TL;DR: Phishing still drives ransomware paths, yet many MFA methods remain vulnerable, and CISA says 84% of employees interacted with a phishing email, highlighting why certificate-based authentication and Zero Trust-aligned verification are gaining attention, according to Axiad and CISA. Identity programmes that stop at MFA labels miss the underlying trust model problem.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Fresh Take: A Brief Reflection on the National Cybersecurity Strategy”.
By the numbers:
- 84% of employees interacted with a phishing email, according to CISA data cited by Axiad.
Key questions
Q: What breaks when MFA is configured with weak, phishable factors?
A: Weak factors such as SMS codes, OTP apps, or push-based approvals can satisfy a policy checkbox while still leaving the environment open to phishing, man-in-the-middle, and push bombing attacks.
A: Certificate-based authentication reduces phishing risk because authentication is tied to possession of a private key and trusted certificate rather than a reusable password.
Q: How should IAM teams decide when phishing-resistant authentication is needed?
A: Use phishing-resistant methods wherever account compromise would create material business or operational impact, especially for remote access, privileged users, and high-value applications.
Practitioner guidance
- Define phishing resistance as a requirement Set an explicit standard for which authentication methods count as phishing-resistant in your environment, then exclude methods that still depend on shared secrets or user approvals vulnerable to proxy attacks.
- Prioritise certificate-backed authentication for high-risk access Use certificate-based authentication for employee, admin, and remote access paths where identity compromise would create outsized blast radius, especially in hybrid work scenarios.
- Review certificate lifecycle controls Check issuance, storage, renewal, and revocation processes so certificates do not become long-lived trust artefacts that outlive device or user assurance.
Bottom line: Phishing-resistant authentication matters because many common MFA methods still allow attackers to intercept or replay the second factor.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing resistance is now an identity architecture issue, not just an awareness issue. The article correctly separates authentication strength from the marketing language around MFA. When SMS, OTP, and push approvals remain phishable, the control objective is not simply second-factor presence but resistance to interception, replay, and social engineering. Practitioners should evaluate authentication based on the attacker’s ability to reuse what the user just proved.
A question worth separating out:
Q: How do certificate-based controls fit into Zero Trust programmes?
A: They fit by improving continuous verification. Zero Trust depends on stronger evidence about the user, device, and session, and certificate-backed authentication gives practitioners a more reliable proof mechanism than prompts that a phisher can replay or manipulate.
👉 Read our full editorial: Phishing resistance and certificate authentication reduce identity attack surface