Two-Factor Authentication
Bringing enhanced security features to the masses. Eversource facilitates the ability for millions of customers across New England to go about their daily lives and business operations with access to various forms of power. With the handling of sensitive data comes the responsibility of protecting the information customers entrust in their applications.

Upon signing into their online account, customers will be prompted to enable Two-Step authentication. The design language was aimed at creating a sense of urgency, without feeling forced, as this is an optional feature.

Whereas more advanced methods such as push notifications via security applications are a standard, the team conducted research to better understand the level of familiarity our customer base had with two-step authentication. It was decided that for MVP, we'd roll out with email and SMS (text), and then fast follow with voice calls as to not exclude customers who don't have the ability to text or utilize email.

The intention with the design solution was to enable as effortless and friction-less an experience as possible, with enlarged UI elements to encourage focus.

When appropriate, recommendations were made to leverage native functions, such as serving up the code via the messages app on mobile. In an effort to reduce unnecessary clicks, the recommendation was made ( a best practice) to allow the interface to process the 6-digit code upon entry without the need of selecting a 'submit' button.

Clear and concise error messaging allows for customers to better understand the consequences of their actions and mistakes. In an effort to mitigate issues, clearly labeled language describes to length of time the code is valid, as well as a countdown for when a resend can be triggered.

Upon successfully completing the addition of a factor, customers are reminded their settings can be adjusts on their profile page, as well as reiterating the detail of receiving a code — such as a mobile number for SMS verification. Customers also have the option to set up an additional factor for greater security measures and protections on their account(s).
This was a high effort feature that included collaboration and insight from development partners, content strategy, analytics, security stakeholders and business SMEs. A huge thank you to those involved in getting this shipped for future iteration and improvement.