Join our Newsletter — 33% off our NHI Course

Phishing-resistant authentication for people, machines, and email

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: The SANS 2022 Managing Human Risk report puts people at the centre of the current attack frontier, with phishing, business email compromise, and ransomware all driven by credential theft or weak passwords, according to Axiad’s analysis. Passwordless, phishing-resistant MFA is now a baseline control, but it still needs to be paired with ongoing user training and coverage across people, machines, and interactions.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Top Attack Frontier is People – Need for Phishing-Resistant Authentication”.

Key questions

Q: How should security teams implement phishing-resistant MFA in existing IAM environments?

A: Start with the most exposed and highest-value access paths, then phase in device-bound methods such as passkeys, FIDO2 keys, or smart cards.

Q: Why do email attacks remain effective even when organisations use MFA?

A: MFA protects the login step, but many email attacks exploit the trust placed in a compromised or impersonated mailbox after authentication.

Q: What breaks when authentication is not phishing-resistant?

A: The trust boundary between the user and the system becomes easy to impersonate.

Practitioner guidance

  • Implement phishing-resistant MFA for privileged users Start with administrators, help desk accounts and other high-impact users who are prime targets for phishing and BEC.
  • Extend authentication governance to workloads and devices Treat machine certificates and PKI as part of identity architecture, not a separate infrastructure task.
  • Remove shared-secret dependencies from login flows Identify places where shared secrets, OTP codes or fallback methods still travel through channels that attackers can intercept.

Bottom line: People-centric attacks remain effective because they exploit the weakest identity assurance point, which is often still password-based or phishable authentication.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

People-centric attack exposure is now an identity governance problem, not just a security awareness problem. The article correctly frames phishing, BEC and ransomware as part of the same credential-driven attack economy. That means authentication design, not just user education, sits at the centre of risk reduction. For IAM teams, the issue is whether the authentication stack still assumes users can reliably distinguish legitimate from malicious requests.

A few things that frame the scale:

  • Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.

A question worth separating out:

Q: What is the difference between strong MFA and phishing-resistant MFA?

A: Strong MFA means more than one factor is used, while phishing-resistant MFA means the factor cannot be easily captured and replayed by an attacker. A code sent by text may count as MFA, but it is not resistant enough for high-risk accounts because the secret can be stolen outside the application itself. Resistance is the higher standard.

👉 Read our full editorial: People-centric attacks and phishing-resistant MFA for IAM teams


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.