TL;DR: Legacy MFA is no longer enough against deepfakes and modern phishing, according to Yubico’s commissioned Forrester TEI study, which found a composite 5,000-plus employee organisation achieved 265% ROI, 99.99% lower addressable breach risk costs, and $7.3 million in three-year benefits after moving to YubiKeys. The security model is shifting from checkbox authentication to phishing-resistant identity proofing, because OTP and push-based flows still leave enterprises exposed to account takeover and operational drag.
At a glance
What this is: Yubico’s commissioned TEI study argues that phishing-resistant authentication is replacing legacy MFA as the practical enterprise baseline, with quantified gains in risk reduction, productivity, and IT efficiency.
Why it matters: IAM and PAM teams should treat MFA modernization as an identity resilience decision, because weak authentication still drives account takeover, support load, and trust gaps across human and non-human access paths.
By the numbers:
- The study found a composite organisation achieved a 265% ROI after switching to phishing-resistant YubiKeys with YubiKey as a Service.
- Users authenticated 80% faster with YubiKeys than with legacy MFA in the TEI study.
👉 Read Yubico's analysis of the Forrester TEI study on phishing-resistant MFA
Context
Legacy MFA often improves access hygiene, but it does not remove the core weakness of shared secrets, replayable one-time codes, or user-driven approval fatigue. In an environment shaped by generative AI, deepfakes, and credential theft, enterprise identity programmes need stronger proof of possession than SMS or push approvals can provide.
The primary governance issue is not whether MFA exists, but whether the factor resists modern phishing and social engineering. For IAM teams, that shifts the discussion from convenience versus control to authentication methods that can meaningfully reduce account takeover risk while still supporting scale, legacy systems, and hybrid work.
Key questions
Q: How should organisations modernise MFA without disrupting employee access?
A: Start with the highest-risk sign-in paths, then introduce stronger authenticators alongside a phased rollout and clear recovery routes. Keep legacy methods only where business continuity requires them, and use policy-based enforcement to avoid forcing all users through the same change at once. The goal is controlled migration, not a hard cutover that creates support bottlenecks.
Q: Why do push approvals and OTPs fail against modern MFA attacks?
A: Because both rely on something a user can be tricked into giving away or approving. Attackers use reverse-proxy phishing, MFA fatigue, SIM swaps, and OTP interception to turn the second factor into a liability. Once the factor is replayable or socially engineerable, it no longer provides strong assurance.
Q: How should security teams measure whether authentication controls are actually working?
A: Measure the full path, not just successful login. Teams should track completion rates, latency, recovery effort, suspicious attempts, and downstream fraud or support load. For NHIs, add provisioning, rotation, revocation, and offboarding completion. If the metric does not change a control decision, it is not yet useful for governance.
Q: What should identity teams prioritise after deploying MFA?
A: Prioritise policy quality, session scoping, and exception management. The goal is not just to add a second factor, but to make sure the authentication result actually reflects the risk of the access path and continues to matter after login.
Technical breakdown
Why phishing-resistant authentication changes the control model
Phishing-resistant authentication changes the control model because the verifier is no longer asking the user to repeat or approve a reusable secret. FIDO2-based security keys bind the authentication ceremony to a physical authenticator and the origin being accessed, which sharply reduces replay, relay, and adversary-in-the-middle abuse. That matters because many legacy MFA flows still depend on user judgement at the exact moment attackers are best at manipulating it.
Practical implication: prioritise phishing-resistant factors for high-value users, administrators, and externally exposed applications before tuning legacy MFA policy exceptions.
Why legacy MFA creates hidden operational cost
Legacy MFA creates hidden operational cost because each lost phone, expired app token, or failed push enrolment becomes a help desk event. Those tickets compound across large environments, and the cost is not only support labour. Delays in authentication also slow business processes, interrupt sessions, and increase the likelihood of insecure workarounds that weaken identity governance over time.
Practical implication: measure authentication friction as an identity control issue, not just a service desk metric, and track it alongside account takeover attempts.
How physical keys fit broader zero trust architecture
Physical keys fit broader zero trust architecture because they strengthen the user authentication layer without relying on network location or device trust alone. In practice, they can anchor access across browsers, older infrastructure, and cloud services when paired with appropriate federation and policy controls. The architectural value is consistency: a stronger proof standard across diverse access paths reduces the number of exception-handling patterns attackers exploit.
Practical implication: align key-based authentication with zero trust policy design so that strong auth becomes the default across both modern SaaS and legacy access paths.
Threat narrative
Attacker objective: The attacker’s objective is to obtain durable authenticated access that can be reused for account takeover, lateral movement, or fraudulent activity.
- Entry begins when attackers use phishing, deepfake-assisted impersonation, or credential replay to target authentication flows that still rely on OTPs or push approvals.
- Escalation occurs when the attacker obtains authenticated access, then reuses that session or account trust to reach applications, support workflows, or privileged functions.
- Impact follows as account takeover, fraudulent access, or credential-based intrusion that bypasses weak MFA despite the presence of a second factor.
Breaches seen in the wild
- Shai Hulud npm malware campaign — Shai Hulud campaign: npm malware exposed secrets on GitHub.
- Reviewdog GitHub Action supply chain attack — reviewdog/action-setup GitHub Action supply chain attack exposed secrets.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Phishing-resistant MFA is now an identity governance requirement, not a premium option. Deepfake-enabled phishing changes the economics of authentication abuse because the weakest point is often the human response loop, not the cryptography itself. Organisations that still rely on OTPs and push approval are accepting a control that can be socially engineered at scale. The practical conclusion is that authentication assurance has become part of core identity risk management, not an edge-case hardening exercise.
Legacy MFA creates security debt in the form of both attack exposure and operational drag. The TEI findings point to a dual cost model: breach risk remains addressable by attackers, while support tickets and user friction keep accumulating. That combination is exactly why checkbox compliance fails as a governance strategy. Practitioners should treat authentication modernisation as a programme to reduce identity debt across the full access lifecycle.
Zero trust only holds when the factor resists replay and coercion. If the second factor can be forwarded, approved, or socially manipulated, the access decision is weaker than the architecture assumes. That breaks the premise that strong identity proofing can be enforced consistently across cloud, legacy, and remote access. The implication is that zero trust programmes need a stronger baseline factor before they can credibly claim continuous verification.
Phishing resistance should be measured as a trust boundary, not a product feature. The study’s business outcomes matter because they tie authentication design to measurable outcomes such as risk reduction, ticket deflection, and faster user access. That makes phishing resistance part of identity programme governance, with clear ownership across IAM, security architecture, and service desk operations. Teams should use that lens to prioritise the populations and applications where assurance gaps are most costly.
From our research:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
- That governance gap is why the Ultimate Guide to NHIs , Key Challenges and Risks remains relevant for teams trying to govern modern non-human access patterns.
What this signals
Phishing-resistant authentication is becoming the dividing line between acceptable and fragile identity assurance. As deepfakes and credential theft improve, weak MFA increasingly shifts risk into the human decision layer, where attackers are strongest. Teams that still treat OTP and push approvals as “good enough” will keep inheriting avoidable account takeover exposure.
Authentication modernisation should be managed as programme risk, not just login convenience. When support tickets, enrolment failures, and user workarounds remain high, the identity control is producing debt elsewhere in the programme. That makes lifecycle governance, federation policy, and privileged access design part of the same decision, not separate workstreams.
For practitioners
- Reclassify legacy MFA as a compensating control Inventory where SMS OTP, voice, and push approval still protect high-value accounts, then rank those flows by exposure to phishing, deepfake impersonation, and account takeover. Replace the highest-risk populations first, starting with administrators, finance, and externally exposed users.
- Measure authentication friction as a governance metric Track help desk tickets, failed logins, enrolment drop-off, and session interruptions alongside security outcomes. The goal is to understand where weak MFA is creating hidden cost, then use that evidence to justify stronger factors for the right user groups.
- Standardise phishing-resistant factors for critical access paths Use FIDO2-capable keys or equivalent phishing-resistant methods for privileged users and high-risk workflows, then align federation, conditional access, and break-glass procedures so exceptions remain tightly governed.
- Update zero trust policy to require stronger proof of possession Map where your current access policy still trusts user approval rather than cryptographic proof. Strengthen the authentication baseline before expanding reliance on AI-enabled workflows, remote access, or sensitive SaaS applications.
Key takeaways
- Legacy MFA is no longer a reliable endpoint for enterprise identity because modern phishing methods can still defeat human-dependent approval flows.
- The business case for phishing-resistant authentication is broader than risk reduction alone, with lower support cost and faster access contributing materially to the outcome.
- IAM teams should treat strong factors as a zero trust prerequisite and govern them by user risk, application criticality, and operational friction.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article centres on authenticator strength and phishing-resistant authentication. |
| NIST CSF 2.0 | PR.AC-7 | Authentication strength and access assurance are central to this identity topic. |
| NIST Zero Trust (SP 800-207) | 5.1 | Zero trust requires stronger identity verification at the access decision point. |
| NIST SP 800-53 Rev 5 | IA-2 | Identification and authentication control selection is directly relevant here. |
Align phishing-resistant MFA with zero trust access decisions and reduce trust in user approval flows.
Key terms
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Legacy MFA: Older multi-factor authentication methods that add a second check but still depend on human response or reusable codes. In practice, SMS, voice, and push-based flows can reduce casual compromise while leaving room for phishing, fatigue attacks, and adversary-in-the-middle interception.
- Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
- Zero Trust: A security model that assumes no identity — human or non-human — should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
What's in the full report
Yubico's full report covers the operational detail this post intentionally leaves for the source:
- The full TEI methodology and assumptions behind the 265% ROI calculation
- Per-user productivity and support cost breakdowns for a 5,000-employee composite organisation
- Deployment and enrolment considerations for scaling phishing-resistant authentication across a global workforce
- Interviews and qualitative findings from organisations that replaced legacy MFA with security keys
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org