Phishing-resistant MFA is now the real control boundary for CJIS access. The policy shift makes the quality of the authenticator more important than the presence of a second factor. That changes the governance question from "is MFA enabled?" to "can this authentication method withstand phishing and credential replay?" Practitioners should treat authentication strength as the compliance variable, not a feature toggle.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: What is the difference between strong MFA and phishing-resistant MFA?
A: Strong MFA means more than one factor is used, while phishing-resistant MFA means the factor cannot be easily captured and replayed by an attacker. A code sent by text may count as MFA, but it is not resistant enough for high-risk accounts because the secret can be stolen outside the application itself. Resistance is the higher standard.
👉 Read our full editorial: CJIS phishing-resistant MFA raises the bar for identity assurance