How To Adopt Phishing-Resistant MFA
Security Boulevard, Wednesday, March 6th, 2024
In a recent blog post, we discussed what phishing-resistant multi-factor authentication (MFA) is and why it matters. In this post, we discuss how organizations should go about adopting unphishable authentication.
According to Axiad's 2023 State of Authentication Survey, 49% of respondents said phishing is the most likely attack to happen. In addition, the headlines are full of data breaches based on phishing attacks, so it is easy to see why phishing is such a big problem. This is why organizations like the Cybersecurity and Infrastructure Security Agency (CISA), the National Institute of Standards and Technology (NIST), and The U.S. White House Office of Management and Budget (OMB) have all recommended that organizations try to stamp out phishing by adopting phishing-resistant MFA.
We know that phishing is a major security problem. But why aren't organizations doing something about it? According to the Axiad survey mentioned above, 64% of respondents said 'fear of change' is the top reason for holding onto passwords and non-phishing-resistant MFA. Fears of cost and the time of implementation were also named as key factors.