References
Abduhari, E. S., Shaik, T. C., Adidul, A. B., Ladja, J. H., Saliddin, E. S., Adin, A. J., ... Tahil, S. K. (2024). Access control mechanisms and their role in preventing unauthorized data access: A comparative analysis of RBAC, MFA, and strong passwords. Natural Sciences Engineering and Technology Journal, 5(1), 418–430. Adams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12), 40–46. https://doi.org/10.1145/322796.322806 Afolalu, O., & Tsoeu, M. S. (2025). Cybersecurity in Higher Education Institutions: A Systematic Review of Emerging Trends, Challenges and Solutions. Future Internet, 17(12), 575. https://doi.org/10.3390/fi17120575 MDPI Alasmary, W., Alhaidari, F., Alharbi, F., & Alzahrani, A. (2019). Cybersecurity challenges in higher education institutions: A systematic review. Journal of Information Security and Applications, 47, 81–91. https://doi.org/10.1016/j.jisa.2019.03.007 Alotaibi, S., & Almagwashi, H. (2018). Multi-factor authentication: A survey. International Journal of Computer Science and Network Security, 18(9), 66–78. Apthorpe, N., Beavers, B., Shvartzshnaider, Y., & Frischmann, B. (2024). Measuring NIST authentication standards compliance by higher education institutions. arXiv. Beautement, A., Sasse, M. A., & Wonham, M. (2016). The compliance budget: Managing security behaviour in organisations. New Security Paradigms Workshop, 47–58. https://doi.org/10.1145/1143120.1143127 Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2012). The quest to replace passwords: A framework for comparative evaluation of web authentication schemes. IEEE Symposium on Security and Privacy, 553–567. https://doi.org/10.1109/SP.2012.44 Cahyanto, I., Madihah, H., Budiarso, I., Sutrisno, A., & Hidayat, T. (2025). Effectiveness of multifactor authentication technology for protecting student privacy: A systematic literature review. Edum Journal, 7(2), 253–269. Das, A., Kim, J., Borisov, N., & Caesar, M. (2018). The effectiveness of multi-factor authentication against real-world attacks. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 82–96. https://doi.org/10.1145/3243734.3243810 Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. arXiv Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. Das, S., Wang, B., Tingle, Z., & Camp, L. J. (2019). Evaluating user perception of multi-factor authentication: A systematic review. arXiv. arXiv E-SPIN Group. (2024). Multifactor authentication: Strength security with benefits, challenges, and best practices. E-SPIN Group EDUCAUSE. (2023). 2023 EDUCAUSE Horizon report: Teaching and learning edition. EDUCAUSE. https://www.educause.edu Florencio, D., & Herley, C. (2007). A large-scale study of web password habits. Proceedings of the 16th International World Wide Web Conference, 657–666. Garfinkel, S., & Rosenberg, B. (2021). Password security in modern computing systems. Addison-Wesley. Gaw, S., Felten, E. W., & Fernandez-Kelly, P. (2006). Secrecy, flagging, and paranoia: Adoption criteria in password selection. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, 591–600. https://doi.org/10.1145/1124772.1124861 Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital Identity Guidelines (NIST SP 800- 63B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63b ISACA. (2025). Industry news: 2025 will MFA redefine cyberdefense in the 21st century. ISACA Jain, A. K., Ross, A., & Nandakumar, K. (2011). Introduction to biometrics. Springer. Kasahara, Y., & Shimayoshi, T. (2025). Our design and implementation of multi-factor authentication deployment for Microsoft 365 in Kyushu University. Kyushu University Pure Portal. Kyushu University Pure Portal Site Meyer, L. A., Romero, S., Bertoli, G., Burt, T., Weinert, A., & Lavista Ferres, J. M. (2023). How effective is multifactor authentication at deterring cyberattacks? Microsoft Research. Nagpal, D. (2024). Breaking down barriers: Overcoming usability challenges in multi-factor authentication systems. Medium. Medium National Institute of Standards and Technology . (2022). Digital identity guidelines (Special Publication 800-63B). NIST. https://doi.org/10.6028/NIST.SP.800-63b National Institute of Standards and Technology. (2017). Digital identity guidelines (NIST SP 800-63-3). U.S. Department of Commerce. Natter, G. (2025). A unified multi-factor authentication strategy: Enhancing security in academic institutions with a case study of TU Wien. Technische Universität Wien. vr.tuwien.ac.at Omega Network Solutions. (2024). 10 surprising limitations of multi-factor authentication . PMC. (2023). BAuth-ZKP—A blockchain-based multi-factor authentication mechanism for securing smart cities. PMC. Renaud, K., Volkamer, M., & Renkema-Padmos, A. (2014). Why doesn’t Jane protect her privacy? Privacy Enhancing Technologies Symposium, 244–262. https://doi.org/10.1007/978-3-319-08506-7_13 Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust architecture (NIST SP 800-207). National Institute of Standards and Technology. Stallings, W. (2020). Cryptography and network security: Principles and practice (8th ed.). Pearson. Tetlay, A., Treharne, H., Ascroft, T., & Moschoyiannis, S. (2020). Lessons learnt from a 2FA roll out within a higher education organisation. arXiv. Verizon. (2024). 2024 data breach investigations report. Verizon Enterprise Solutions. https://www.verizon.com/business/resources/reports/dbir/ Weir, C. S., Douglas, G., Carruthers, M., & Jack, M. (2009). User perceptions of security, convenience and usability for e-banking authentication tokens. Computers & Security, 28(1–2), 47–62. https://doi.org/10.1016/j.cose.2008.09.008 Weir, M., Douglas, S., Carruthers, M., & Jack, M. (2020). User perceptions of security and usability of multi-factor authentication. International Journal of Human-Computer Studies, 135, 102–114. https://doi.org/10.1016/j.ijhcs.2019.102379 Whitman, M. E., & Mattord, H. J. (2021). Principles of information security (7th ed.). Cengage Learning.