TL;DR: The DoW CIO’s new “Brilliant at the Basics” guidance ranks phishing-resistant MFA as the top IT cybersecurity practice for small, mid-sized, and non-traditional Defense Industrial Base suppliers, signalling that SMS codes and push-based MFA no longer meet the modern trust bar, according to Yubico. Legacy MFA assumes attackers cannot intercept or socially engineer the second factor, but that assumption breaks under phishing, SIM-swapping, and MFA fatigue.
At a glance
What this is: The DoW’s DIB guidance puts phishing-resistant MFA at the top of its IT security list, making authentication hardening the first control to get right.
Why it matters: For IAM and security teams, this reframes MFA from a compliance checkbox into a trust control that must withstand phishing, interception, and social engineering across both IT and OT.
By the numbers:
- The DoW guidance includes 10 IT cybersecurity practices and 10 OT cybersecurity practices for suppliers to prioritise.
👉 Read Yubico’s analysis of DoW’s phishing-resistant MFA guidance for DIB suppliers
Context
Phishing-resistant MFA is authentication that keeps the second factor bound to a cryptographic device or platform rather than something a user can type, forward, or approve under pressure. In the defense supply chain, that difference matters because the primary risk is not weak policy language, but credentials that can be stolen, replayed, or socially engineered.
The DoW CIO’s ranking matters because it is directed at suppliers that often lack large security teams and need clear prioritisation. For identity programmes, this is a strong signal that access control is being judged by attack resistance, not by whether a checkbox can be ticked during an audit.
The same principle applies across IT and OT environments. If contractors treat plant-floor systems as separate from corporate identity controls, they create a split trust model that attackers can exploit through the easier side first.
Key questions
Q: How should organisations phase out legacy MFA for sensitive access?
A: Start with privileged users, supplier access, and systems tied to regulated or sensitive data. Replace SMS and push-based approval with phishing-resistant methods such as FIDO2/WebAuthn or PIV/CAC, then update access policies so the stronger method becomes the default for high-risk accounts.
Q: Why do SMS codes and push notifications create identity risk?
A: Because they can be phished, intercepted, or coerced through social engineering and MFA fatigue. They prove that a second step happened, but not that the authenticator is resistant to an attacker who can manipulate the user or the session.
Q: What do security teams get wrong about MFA in supplier environments?
A: They often assume MFA quality is interchangeable across methods. In practice, supplier access to sensitive systems needs stronger assurance because third-party users may sit outside the organisation’s normal monitoring and training controls.
Q: How do you know if phishing-resistant MFA is actually working?
A: Look for enrolment coverage by user group, renewal discipline, exception rates, and the absence of weak fallback methods. A working programme does not just issue stronger authenticators. It can prove who is enrolled, which credentials are current, and where the rollout still depends on exceptions or untracked recovery paths.
Technical breakdown
Why legacy MFA fails under phishing and push fatigue
Legacy MFA relies on factors that can still be intercepted, replayed, or approved under pressure. SMS can be diverted through SIM-swap attacks, and push prompts can be exhausted through MFA fatigue or tricked by social engineering. That means the control protects the login flow only when the user is vigilant enough to resist manipulation, which is not a reliable security property. Phishing-resistant methods change the model by binding authentication to a private key that never leaves the device and cannot be copied into a phishing site.
Practical implication: replace legacy MFA on high-risk accounts with phishing-resistant authentication that cannot be replayed through a fake login page.
How FIDO2 and PIV/CAC change the identity trust model
FIDO2/WebAuthn and PIV/CAC shift authentication from shared secrets or human approval to cryptographic proof of possession. The verifier challenges the authenticator, and the response is origin-bound, which blocks credential replay against lookalike domains. For federal and DIB environments, that is important because it reduces dependence on user behaviour and raises the cost of phishing campaigns. Hardware-backed passkeys and validated security keys also fit regulated environments where policy needs to be both practical and defensible.
Practical implication: standardise on origin-bound authenticators for privileged and supplier access rather than treating all MFA methods as interchangeable.
Why IT and OT identity control need to converge
The guidance’s separate IT and OT lists point to the same underlying problem: identity controls often stop at the corporate network edge. OT systems frequently inherit weak access assumptions from legacy environments, but the attack path still begins with identity compromise. When the same organisation operates both domains, inconsistent authentication policy creates a weaker entry point that can undermine both environments. Zero Trust language in OT is only meaningful if the authentication method itself resists phishing and adversary-in-the-middle attacks.
Practical implication: align identity policy across IT and OT so that privileged access requires the same phishing-resistant standard in both domains.
Threat narrative
Attacker objective: The attacker wants authenticated access that can be used to reach sensitive defense supply chain systems without triggering obvious credential alarms.
- Entry begins when an attacker targets user authentication with phishing, credential theft, SIM-swapping, or MFA fatigue rather than trying to bypass the network perimeter directly.
- Escalation occurs when a legacy second factor is approved, intercepted, or replayed, allowing the attacker to satisfy the login flow and reach sensitive systems.
- Impact follows when access is used to move into supplier environments, sensitive DoW information, or operational systems that were assumed to be protected by weaker authentication.
- The objective is to obtain trusted access that looks legitimate to downstream systems and defenders, creating a foothold inside the defense supply chain.
Breaches seen in the wild
- Shai Hulud npm malware campaign — Shai Hulud campaign: npm malware exposed secrets on GitHub.
- Reviewdog GitHub Action supply chain attack — reviewdog/action-setup GitHub Action supply chain attack exposed secrets.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Phishing-resistant MFA is now a supply-chain trust requirement, not a user convenience choice. The DoW ranking reflects a broader identity security shift: authentication is being treated as the first line of defence for third-party access. In defence-adjacent environments, a second factor that can be phished is functionally a weak control, even if it passes audit language. Practitioners should read this as a policy signal that authentication quality is becoming part of supplier assurance.
Legacy MFA is a governance debt, not just a technical limitation. SMS and push-based methods persist because they are easy to roll out, but that ease creates an accumulated risk profile across user populations, privileged accounts, and supplier access. The control failure is not that MFA exists, but that the wrong MFA method keeps standing in for genuine resistance to adversary-in-the-middle attacks. Identity teams need to treat that mismatch as an operational debt item.
OT identity controls can no longer lag behind IT identity controls. The DoW’s separate OT guidance reaches the same conclusion from a different operational context. When plant systems and corporate systems use different authentication standards, the weaker domain becomes the easier path to initial access. For contractors operating both, the governance problem is consistency: the attacker only needs one place where identity assurance is thinner.
Phishing-resistant authentication is becoming the baseline for access to regulated ecosystems. That does not mean every workforce use case needs the same factor mix, but it does mean the minimum acceptable factor for sensitive access is moving upward. Organisations that continue to rely on legacy MFA will increasingly need to justify why their risk model is still compatible with supplier, federal, and zero-trust expectations. The practical conclusion is straightforward: factor quality is now part of access governance.
From our research:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 38% have no or low visibility and 47% have only partial visibility into those connected vendors, which means access assurance often stops at the edge of the provider relationship.
- That visibility gap connects directly to Top 10 NHI Issues, where unmanaged third-party access and over-privilege remain recurring control failures.
What this signals
Phishing-resistant MFA is becoming the minimum viable control for high-risk identity paths. For programmes that still rely on SMS or push approval, the problem is not just user friction. The real issue is that identity assurance remains negotiable under attack. Teams should treat supplier access, admin access, and operational environments as the first places where legacy methods need to be retired.
The next governance question is consistency across domains. If IT is hardened while OT continues to accept weaker methods, the organisation preserves a weak entry point that attackers can exploit without needing to defeat the stronger perimeter first. That split will become harder to defend in supplier reviews, audit conversations, and operational resilience planning.
Credential assurance is now part of third-party risk management: if suppliers cannot meet phishing-resistant authentication standards, their access should be narrowed until they can. The issue is not theoretical; it is a practical control boundary that affects onboarding, recertification, and incident response readiness.
For practitioners
- Replace legacy MFA on sensitive access paths Prioritise user, privileged, and supplier accounts that still rely on SMS or push approvals, then move them to phishing-resistant methods such as FIDO2/WebAuthn or PIV/CAC.
- Separate IT and OT authentication policy Apply the same phishing-resistant standard across corporate and operational environments instead of allowing OT to inherit weaker identity assumptions from IT.
- Reclassify MFA method quality in access reviews Stop treating all MFA as equivalent during recertification. Record whether the method is phishing-resistant, approval-based, or legacy so risk decisions are visible.
- Harden supplier onboarding requirements Make phishing-resistant authentication a condition for third-party access to sensitive DoW-related systems, especially where the supplier lacks a large security team.
Key takeaways
- The DoW guidance makes phishing-resistant MFA the first control to fix for DIB suppliers, which raises the bar above legacy approval-based methods.
- The scale of the problem is structural, because weak authentication remains common in both IT and OT environments and is still accepted as “enough” in many access programmes.
- Security teams should move high-risk accounts, supplier access, and operational systems to origin-bound authentication now, before policy language catches up with attacker behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article is about strong authenticators and phishing resistance. |
| NIST CSF 2.0 | PR.AC-7 | Access control and authentication assurance are central to the guidance. |
| NIST Zero Trust (SP 800-207) | The guidance echoes zero-trust verification for IT and OT access. | |
| NIST SP 800-53 Rev 5 | IA-2 | Authentication control selection is the core governance issue here. |
Apply zero-trust principles so each privileged session requires strong, phishing-resistant authentication.
Key terms
- Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
- Origin-bound authentication: An authentication method that only works for the intended website, application, or relying party. This reduces the value of phishing pages and proxy attacks because the factor cannot be easily replayed against a different destination.
- Supplier Access Assurance: The set of controls used to decide whether a third party should be trusted with access to sensitive systems. It covers identity proofing, authentication strength, entitlement scope, and monitoring, and it becomes especially important when suppliers lack mature internal security teams.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- The article breaks down the DoW CIO’s ranked Top 10 IT and OT practices so you can see where phishing-resistant MFA sits in the broader control stack.
- It explains why SMS, push approvals, and similar legacy methods are treated as insufficient under the guidance.
- It outlines the practical difference between FIDO2/WebAuthn passkeys and weaker MFA methods for DIB suppliers.
- It connects the guidance to federal expectations for small and mid-sized contractors working with sensitive DoW information.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org