TL;DR: Legacy MFA is no longer enough against deepfakes and modern phishing, according to Yubico’s commissioned Forrester TEI study, which found a composite 5,000-plus employee organisation achieved 265% ROI, 99.99% lower addressable breach risk costs, and $7.3 million in three-year benefits after moving to YubiKeys. The security model is shifting from checkbox authentication to phishing-resistant identity proofing, because OTP and push-based flows still leave enterprises exposed to account takeover and operational drag.
NHIMG editorial — based on content published by Yubico: the Forrester TEI study on YubiKeys and phishing-resistant MFA
By the numbers:
- The study found a composite organisation achieved a 265% ROI after switching to phishing-resistant YubiKeys with YubiKey as a Service.
- Users authenticated 80% faster with YubiKeys than with legacy MFA in the TEI study.
Questions worth separating out
Q: How should organisations modernise MFA without disrupting employee access?
A: Start with the highest-risk sign-in paths, then introduce stronger authenticators alongside a phased rollout and clear recovery routes.
Q: Why do push approvals and OTPs fail against modern MFA attacks?
A: Because both rely on something a user can be tricked into giving away or approving.
Q: How should security teams measure whether authentication controls are actually working?
A: Measure the full path, not just successful login.
Practitioner guidance
- Reclassify legacy MFA as a compensating control Inventory where SMS OTP, voice, and push approval still protect high-value accounts, then rank those flows by exposure to phishing, deepfake impersonation, and account takeover.
- Measure authentication friction as a governance metric Track help desk tickets, failed logins, enrolment drop-off, and session interruptions alongside security outcomes.
- Standardise phishing-resistant factors for critical access paths Use FIDO2-capable keys or equivalent phishing-resistant methods for privileged users and high-risk workflows, then align federation, conditional access, and break-glass procedures so exceptions remain tightly governed.
What's in the full report
Yubico's full report covers the operational detail this post intentionally leaves for the source:
- The full TEI methodology and assumptions behind the 265% ROI calculation
- Per-user productivity and support cost breakdowns for a 5,000-employee composite organisation
- Deployment and enrolment considerations for scaling phishing-resistant authentication across a global workforce
- Interviews and qualitative findings from organisations that replaced legacy MFA with security keys
👉 Read Yubico's analysis of the Forrester TEI study on phishing-resistant MFA →
Legacy MFA is now a liability for enterprise identity teams?
Explore further
Phishing-resistant MFA is now an identity governance requirement, not a premium option. Deepfake-enabled phishing changes the economics of authentication abuse because the weakest point is often the human response loop, not the cryptography itself. Organisations that still rely on OTPs and push approval are accepting a control that can be socially engineered at scale. The practical conclusion is that authentication assurance has become part of core identity risk management, not an edge-case hardening exercise.
Phishing-resistant authentication is becoming the dividing line between acceptable and fragile identity assurance. As deepfakes and credential theft improve, weak MFA increasingly shifts risk into the human decision layer, where attackers are strongest. Teams that still treat OTP and push approvals as “good enough” will keep inheriting avoidable account takeover exposure.
A question worth separating out:
Q: What should identity teams prioritise after deploying MFA?
A: Prioritise policy quality, session scoping, and exception management. The goal is not just to add a second factor, but to make sure the authentication result actually reflects the risk of the access path and continues to matter after login.
👉 Read our full editorial: Phishing-resistant MFA is becoming the baseline for enterprise identity