TL;DR: The DoW CIO’s new “Brilliant at the Basics” guidance ranks phishing-resistant MFA as the top IT cybersecurity practice for small, mid-sized, and non-traditional Defense Industrial Base suppliers, signalling that SMS codes and push-based MFA no longer meet the modern trust bar, according to Yubico. Legacy MFA assumes attackers cannot intercept or socially engineer the second factor, but that assumption breaks under phishing, SIM-swapping, and MFA fatigue.
NHIMG editorial — based on content published by Yubico: the DoW’s “Brilliant at the Basics” guidance for Defense Industrial Base suppliers
By the numbers:
- The DoW guidance includes 10 IT cybersecurity practices and 10 OT cybersecurity practices for suppliers to prioritise.
Questions worth separating out
Q: How should organisations phase out legacy MFA for sensitive access?
A: Start with privileged users, supplier access, and systems tied to regulated or sensitive data.
Q: Why do SMS codes and push notifications create identity risk?
A: Because they can be phished, intercepted, or coerced through social engineering and MFA fatigue.
Q: What do security teams get wrong about MFA in supplier environments?
A: They often assume MFA quality is interchangeable across methods.
Practitioner guidance
- Replace legacy MFA on sensitive access paths Prioritise user, privileged, and supplier accounts that still rely on SMS or push approvals, then move them to phishing-resistant methods such as FIDO2/WebAuthn or PIV/CAC.
- Separate IT and OT authentication policy Apply the same phishing-resistant standard across corporate and operational environments instead of allowing OT to inherit weaker identity assumptions from IT.
- Reclassify MFA method quality in access reviews Stop treating all MFA as equivalent during recertification.
What's in the full article
Yubico's full article covers the operational detail this post intentionally leaves for the source:
- The article breaks down the DoW CIO’s ranked Top 10 IT and OT practices so you can see where phishing-resistant MFA sits in the broader control stack.
- It explains why SMS, push approvals, and similar legacy methods are treated as insufficient under the guidance.
- It outlines the practical difference between FIDO2/WebAuthn passkeys and weaker MFA methods for DIB suppliers.
- It connects the guidance to federal expectations for small and mid-sized contractors working with sensitive DoW information.
👉 Read Yubico’s analysis of DoW’s phishing-resistant MFA guidance for DIB suppliers →
Phishing-resistant MFA for the DIB: is your access model ready?
Explore further
Phishing-resistant MFA is now a supply-chain trust requirement, not a user convenience choice. The DoW ranking reflects a broader identity security shift: authentication is being treated as the first line of defence for third-party access. In defence-adjacent environments, a second factor that can be phished is functionally a weak control, even if it passes audit language. Practitioners should read this as a policy signal that authentication quality is becoming part of supplier assurance.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 38% have no or low visibility and 47% have only partial visibility into those connected vendors, which means access assurance often stops at the edge of the provider relationship.
A question worth separating out:
Q: How do you know if phishing-resistant MFA is actually working?
A: Look for enrolment coverage by user group, renewal discipline, exception rates, and the absence of weak fallback methods. A working programme does not just issue stronger authenticators. It can prove who is enrolled, which credentials are current, and where the rollout still depends on exceptions or untracked recovery paths.
👉 Read our full editorial: Phishing-resistant MFA is now the DIB baseline, not a nice-to-have