---
title: "Spoiler Alert: Game of Thrones Guards Secrets with IAM Strategy"
description: Game of Thrones execs were smart insisting show's stars adopt two-factor authorization on their emails; IAM strategies are key for protecting top-secret info.
image: https://resources.workstate.com/hubfs/Logo_Game_of_Thrones.png
---

[![Workstate](https://resources.workstate.com/hubfs/Workstate-Nov2016/Image/Logo.png "Workstate")](http://workstate.com/)

- Practices 
    - [Technology Team Rental](http://workstate.com/teamrental)
    - [Big Data](http://workstate.com/bigdata)
    - [Cloud Shift](http://workstate.com/cloud-shift)
    - [QA and Testing](http://workstate.com/qa)
    - [Identity and Access Management](http://workstate.com/iam)
    - [Application Security](http://workstate.com/appsecurity)
- [Blog](http://web.workstate.com/blog)
- [Careers](https://workstate.workable.com/)

# Workstate Insights Blog

# Spoiler Alert: Game of Thrones Guards Secrets with IAM Strategy

 May 11, 2017

by [Christian Duvall, Group Vice President, Enterprise Services](https://resources.workstate.com/blog/author/christian-duvall-group-vice-president-enterprise-services)

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Spoiler%20Alert%3A%20Game%20of%20Thrones%20Guards%20Secrets%20with%20IAM%20Strategy) [![Share on Email](https://static.hubspot.com/final/img/common/icons/social/email-24x24.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fgame-of-thrones-guards-secrets-with-iam-strategy%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Logo_Game_of_Thrones.png](https://resources.workstate.com/hs-fs/hubfs/blog-images/iam/Logo_Game_of_Thrones.png?width=640&name=Logo_Game_of_Thrones.png)By Cyanide Studio - Cyanide Studio, [CC BY-SA 3.0](http://creativecommons.org/licenses/by-sa/3.0), [Link](https://commons.wikimedia.org/w/index.php?curid=18777543)

I have to admit — it makes me a little excited to see one of my favorite television shows collide with one of my favorite topics. It’s a rare event, so you can imagine how happy I was to see [The Verge](https://www.theverge.com/) article entitled “[Game of Thrones makes its stars two-factor their emails now](https://www.theverge.com/tldr/2017/5/5/15556388/game-of-thrones-script-security-season-7-2fa).”

No, I’m not very fun at parties.

As the series is now at a point where it is beyond the original novels, secrecy – and security – are crucial to guarding the plot of what is yet-to-be released. Studios go to great lengths, doing everything from [punitive non-disclosure agreements](https://www.instagram.com/p/BQoRjokA8tn/) all the way to filming multiple endings to prevent even the actors from knowing the outcomes. It’s no wonder that keeping the bad guys out is a critical factor in keeping the silence. 

![GoT_IAM_badguy.png](https://resources.workstate.com/hs-fs/hubfs/blog-images/iam/GoT_IAM_badguy.png?width=320&name=GoT_IAM_badguy.png "GoT_IAM_badguy.png")

Sorry - it had to be done. 

As we learned in [Verizon’s 2016 Data Breach Investigations Report](http://www.verizonenterprise.com/verizon-insights-lab/dbir/), over 63% of all confirmed [data breaches come from compromised credentials](https://resources.workstate.com/blog/the-principle-of-least-privilege). It should then come as no surprise that adding additional security in the face of keylogged, phished, or otherwise stolen credentials is a great idea. By adding another step to the authentication journey, we gain a great deal of additional assurance that the identity of the person accessing the account is valid and genuine.

A word of caution – when choosing a multifactor approach, consider the following:

- How will this affect the user’s experience during authentication?
- How easily can the additional factor be compromised?
- What is the cost of adding complexity to authentication vs the risk of the stolen credentials?

These considerations can be weighed against your needs to [identify the best MFA solution](https://resources.workstate.com/blog/iam-weak-passwords-orphan-accounts-and-inappropriate-access-oh-my).

**Digression**: In my opinion, the “question/answer” is the *absolute worst* form of MFA.

I’m looking at you, banks.

If you provide a standard list of questions, like “mother’s maiden name” or “street you grew up on,” you’re basically adding all of the inconvenience of additional authentication steps – with none of the benefits. Thanks to social media, genealogical/historical websites (ancestry.com), and stalker apps … I mean, “personal information aggregators,” you can find these answers pretty much at will. If you force the user to select the question, they’re going to either use the same one for every site or forget it entirely, since it’s hard to push to a password manager. Just don’t do it, there are at least a dozen better ways.

I’m very happy to see some media talking about IAM strategy, especially using a phrase like “two-factor authentication” in the title. However, I was disappointed that the article didn’t have any details about the actual multi-factor approach being used.

Beggars can’t be choosers.

Interested in learning more about the fundamentals of Identity and Access Management?

[![Get IAM Primed Now!](https://no-cache.hubspot.com/cta/default/2258296/3543afec-f439-45d5-afbe-3ea824a116c1.png)](https://cta-redirect.hubspot.com/cta/redirect/2258296/3543afec-f439-45d5-afbe-3ea824a116c1)

### Subscribe to Email Updates

### Recent Posts

### Posts by Topic

- [Cloud Shift (17)](https://resources.workstate.com/blog/topic/cloud-shift)
- [IAM (16)](https://resources.workstate.com/blog/topic/iam)
- [Cloud Computing Best Practices (11)](https://resources.workstate.com/blog/topic/cloud-computing-best-practices)
- [Enterprise Identity (10)](https://resources.workstate.com/blog/topic/enterprise-identity)
- [Identity and Access Management (10)](https://resources.workstate.com/blog/topic/identity-and-access-management)
- [Cloud Migration (8)](https://resources.workstate.com/blog/topic/cloud-migration)
- [Technology Team Rental (8)](https://resources.workstate.com/blog/topic/technology-team-rental)
- [Cloud Shift Best Practices (6)](https://resources.workstate.com/blog/topic/cloud-shift-best-practices)
- [Identity (5)](https://resources.workstate.com/blog/topic/identity)
- [Workstate Codes (5)](https://resources.workstate.com/blog/topic/workstate-codes)
- [AWS (4)](https://resources.workstate.com/blog/topic/aws)
- [Application cloud migration (4)](https://resources.workstate.com/blog/topic/application-cloud-migration)
- [Big Data (4)](https://resources.workstate.com/blog/topic/big-data)
- [For Developers (4)](https://resources.workstate.com/blog/topic/for-developers)
- [Indentity and Access Management Best Practices (4)](https://resources.workstate.com/blog/topic/indentity-and-access-management-best-practices)
- [Lift and Shift (4)](https://resources.workstate.com/blog/topic/lift-and-shift)
- [Workstate (4)](https://resources.workstate.com/blog/topic/workstate)
- [Best practices (3)](https://resources.workstate.com/blog/topic/best-practices)
- [Cloud Innovation (3)](https://resources.workstate.com/blog/topic/cloud-innovation)
- [big data insights (3)](https://resources.workstate.com/blog/topic/big-data-insights)
- [Application Security (2)](https://resources.workstate.com/blog/topic/application-security)
- [Google Cloud (2)](https://resources.workstate.com/blog/topic/google-cloud)
- [IdentityServer3 (2)](https://resources.workstate.com/blog/topic/identityserver3)
- [Insider (2)](https://resources.workstate.com/blog/topic/insider)
- [Microsoft Azure (2)](https://resources.workstate.com/blog/topic/microsoft-azure)
- [data intelligence (2)](https://resources.workstate.com/blog/topic/data-intelligence)
- [hadoop (2)](https://resources.workstate.com/blog/topic/hadoop)
- [Azure Active Directory Best Practices (1)](https://resources.workstate.com/blog/topic/azure-active-directory-best-practices)
- [Design Patterns (1)](https://resources.workstate.com/blog/topic/design-patterns)
- [Development teams (1)](https://resources.workstate.com/blog/topic/development-teams)
- [IdentityModel (1)](https://resources.workstate.com/blog/topic/identitymodel)
- [Programmer Productivity (1)](https://resources.workstate.com/blog/topic/programmer-productivity)
- [QA & Testing (1)](https://resources.workstate.com/blog/topic/qa-testing)
- [Technology mentorship (1)](https://resources.workstate.com/blog/topic/technology-mentorship)
- [identity and access management best practices (1)](https://resources.workstate.com/blog/topic/identity-and-access-management-best-practices)

see all

![Round Workstate Logo](https://resources.workstate.com/hs-fs/hubfs/Workstate-Nov2016/Image/Footer%20Logo.png?width=350&name=Footer%20Logo.png "Round Workstate Logo")

Columbus  
Los Angeles  
Pittsburgh  
San Francisco  
Seattle

**OUR PRACTICES**

[Technology Team Rental](http://workstate.com/teamrental)  
[Big Data](http://workstate.com/bigdata)  
[Cloud Shift](http://workstate.com/cloud-shift)  
[Identity and Access Management](http://workstate.com/iam)  
[QA and Testing](http://workstate.com/qa)  
[Application Security](http://workstate.com/appsecurity)

**CONTACT**

  (614) 559-3904  
  [hello@workstate.com](mailto:hello@workstate.com)

30 Spruce St. Suite 300  
Columbus, OH 43215

<https://twitter.com/workstate> <https://www.linkedin.com/company/workstate> <https://facebook.com/workstate>