TL;DR: CISA’s updated Cross-Sector Cybersecurity Performance Goals push critical infrastructure toward phishing-resistant authentication, unique credentials, and stronger third-party access controls, with Yubico framing hardware-backed passkeys and FIDO/WebAuthn as the highest-assurance option. For identity teams, the practical shift is from password-centric assurance to verifiable, device-bound credential governance that reduces credential reuse, phishing exposure, and MSP-driven blast radius.
NHIMG editorial — based on content published by Yubico: CISA CPG 2.0 and phishing-resistant authentication guidance
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
Questions worth separating out
Q: How should security teams implement phishing-resistant MFA for privileged SaaS access?
A: Start with the identities that can export data or change access, including IdP admins, SaaS admins, and helpdesk staff.
Q: What breaks when organisations keep default or shared credentials?
A: Accountability breaks first.
Q: How do you know if phishing-resistant MFA is actually working?
A: Look for enrolment coverage by user group, renewal discipline, exception rates, and the absence of weak fallback methods.
Practitioner guidance
- Prioritise phishing-resistant MFA for privileged access Require FIDO/WebAuthn or PKI-based authentication first for administrators, remote operators, and third-party support accounts.
- Eliminate default accounts and shared administrative credentials Remove default accounts where possible, and where they must exist, isolate them with separate controls, explicit ownership, and audit review.
- Set partner authentication requirements before access is granted Make FIDO-based or equivalent phishing-resistant authentication a prerequisite for MSP and other third-party privileged access.
What's in the full article
Yubico's full article covers the implementation detail this post intentionally leaves for the source:
- How YubiKey-backed passkeys map to phishing-resistant MFA requirements in CPG 2.0
- Why the article distinguishes hardware-backed private keys from synced passkeys for high-risk use cases
- How the guidance treats MSP and third-party access as a privileged trust boundary
- The practical rationale behind disabling default accounts and separating user and admin credentials
👉 Read Yubico's analysis of CISA CPG 2.0 and phishing-resistant MFA →
CISA CPG 2.0 and phishing-resistant MFA: what should teams change?
Explore further
Phishing resistance is now an identity governance control, not just an authentication upgrade. CISA’s framing reinforces a shift many programmes still resist: the strength of the login method determines downstream access assurance. When the credential is the trust anchor, weaker MFA leaves governance decisions built on an unstable base. Practitioners should treat phishing-resistant MFA as the default for privileged and externally exposed access.
Phishing-resistant authentication is becoming the common denominator across human, delegated, and machine access. As organisations harden login assurance for privileged users, the same logic will be pulled into NHI and agentic AI governance, because attackers do not respect the boundary between human login and machine-issued trust. The programme implication is simple: identity assurance has to be designed as one control plane, not separate policies for separate actor types.
A question worth separating out:
Q: Who is accountable when a third-party operator is compromised?
A: The organisation granting access remains accountable for the trust decision, even if the compromise starts with the partner. Third-party access should be governed as an extension of your privileged access model, with explicit assurance, review, and revocation requirements.
👉 Read our full editorial: CISA CPG 2.0 raises the bar for phishing-resistant identity