Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

CISA CPG 2.0 and phishing-resistant MFA: what should teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: CISA’s updated Cross-Sector Cybersecurity Performance Goals push critical infrastructure toward phishing-resistant authentication, unique credentials, and stronger third-party access controls, with Yubico framing hardware-backed passkeys and FIDO/WebAuthn as the highest-assurance option. For identity teams, the practical shift is from password-centric assurance to verifiable, device-bound credential governance that reduces credential reuse, phishing exposure, and MSP-driven blast radius.

NHIMG editorial — based on content published by Yubico: CISA CPG 2.0 and phishing-resistant authentication guidance

By the numbers:

Questions worth separating out

Q: How should security teams implement phishing-resistant MFA for privileged SaaS access?

A: Start with the identities that can export data or change access, including IdP admins, SaaS admins, and helpdesk staff.

Q: What breaks when organisations keep default or shared credentials?

A: Accountability breaks first.

Q: How do you know if phishing-resistant MFA is actually working?

A: Look for enrolment coverage by user group, renewal discipline, exception rates, and the absence of weak fallback methods.

Practitioner guidance

What's in the full article

Yubico's full article covers the implementation detail this post intentionally leaves for the source:

  • How YubiKey-backed passkeys map to phishing-resistant MFA requirements in CPG 2.0
  • Why the article distinguishes hardware-backed private keys from synced passkeys for high-risk use cases
  • How the guidance treats MSP and third-party access as a privileged trust boundary
  • The practical rationale behind disabling default accounts and separating user and admin credentials

👉 Read Yubico's analysis of CISA CPG 2.0 and phishing-resistant MFA →

CISA CPG 2.0 and phishing-resistant MFA: what should teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Phishing resistance is now an identity governance control, not just an authentication upgrade. CISA’s framing reinforces a shift many programmes still resist: the strength of the login method determines downstream access assurance. When the credential is the trust anchor, weaker MFA leaves governance decisions built on an unstable base. Practitioners should treat phishing-resistant MFA as the default for privileged and externally exposed access.

Phishing-resistant authentication is becoming the common denominator across human, delegated, and machine access. As organisations harden login assurance for privileged users, the same logic will be pulled into NHI and agentic AI governance, because attackers do not respect the boundary between human login and machine-issued trust. The programme implication is simple: identity assurance has to be designed as one control plane, not separate policies for separate actor types.

A question worth separating out:

Q: Who is accountable when a third-party operator is compromised?

A: The organisation granting access remains accountable for the trust decision, even if the compromise starts with the partner. Third-party access should be governed as an extension of your privileged access model, with explicit assurance, review, and revocation requirements.

👉 Read our full editorial: CISA CPG 2.0 raises the bar for phishing-resistant identity



   
ReplyQuote
Share: