Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Phishing-resistant MFA and identity lifecycle: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Phishing, ransomware, and weak credentials remain the dominant failure modes in identity security, and Yubico’s interview argues that password-era authentication and legacy MFA no longer match the threat environment. The editorial takeaway is that phishing-resistant hardware-bound authentication, paired with lifecycle discipline, is now a baseline control for human IAM and adjacent NHI governance.

NHIMG editorial — based on content published by Yubico: an interview on phishing-resistant authentication, identity lifecycle, and cyber resilience

By the numbers:

Questions worth separating out

Q: How should organisations modernise MFA without disrupting employee access?

A: Start with the highest-risk sign-in paths, then introduce stronger authenticators alongside a phased rollout and clear recovery routes.

Q: When does hardware-bound authentication matter more than convenience?

A: It matters most when the cost of account takeover is high, when auditors need proof of user presence, or when phishing resistance is a control expectation rather than a nice-to-have.

Q: What do organisations get wrong about strong authentication programmes?

A: They often treat authentication as a one-time rollout instead of part of a lifecycle.

Practitioner guidance

  • Replace replayable MFA on high-risk access paths Move administrators, developers, and regulated users to phishing-resistant authentication methods that require possession of a hardware-bound device and user presence.
  • Tighten joiner-mover-leaver controls around authentication rollout Make sure new hires receive strong authentication on day one and departing users lose access immediately at offboarding.
  • Retire legacy MFA exceptions for regulated workflows Inventory the places where push approvals, software tokens, or shared devices remain in use and assign deadlines for removal.

What's in the full article

Yubico's full interview covers the operational detail this post intentionally leaves for the source:

  • How Volocopter rolled out YubiKeys across employees without relying on private devices for authenticator apps
  • Operational lessons from using hardware keys for clean-room access, SSH, and commit signing
  • Practical implementation considerations for regulated environments that need defensible identity evidence
  • Why user education and cross-functional rollout planning matter when replacing legacy MFA

👉 Read Yubico's interview on phishing-resistant authentication and identity resilience →

Phishing-resistant MFA and identity lifecycle: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Passwords and software MFA fail because they preserve a remotely exploitable trust path. The problem is not that these methods are obsolete in theory, but that they still let an attacker target the human and the shared recovery channel. That makes credential phishing, MFA fatigue, and session replay persistent governance failures. Practitioners should treat phishing resistance as a control requirement, not a preference.

A few things that frame the scale:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to The 2026 Infrastructure Identity Survey.
  • NHIMG research also shows 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.

A question worth separating out:

Q: How should security teams implement phishing-resistant MFA in existing IAM environments?

A: Start with the most exposed and highest-value access paths, then phase in device-bound methods such as passkeys, FIDO2 keys, or smart cards. Keep the rollout tied to use case, user population, and assurance needs so you can replace replayable secrets without breaking operations or creating unmanaged exceptions.

👉 Read our full editorial: Phishing-resistant MFA and identity lifecycle are now basic controls



   
ReplyQuote
Share: