Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do organisations keep relying on passwords and…
Governance, Ownership & Risk

Why do organisations keep relying on passwords and SMS-based 2FA even when stronger options exist?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Governance, Ownership & Risk

Organisations often delay stronger authentication because they focus on perceived implementation cost, migration effort, and user friction. That short-term view ignores the much larger cost of breaches, helpdesk resets, and recurring exposure from phishing. When executives compare total risk and operating cost, weak authentication usually looks cheaper only until an incident forces the real calculation.

Why weak authentication stays in place longer than it should

Password and SMS-based 2FA often survive because they are already embedded in legacy applications, helpdesk workflows, and account recovery paths. Changing them is rarely just a login-page update, it can touch SSO, onboarding, break-glass access, shared services, and user support processes, so organisations default to the option that appears least disruptive.

The other reason is organisational: the cost of weaker authentication is spread across future incidents, while the cost of stronger authentication is immediate and visible. That makes passwords and SMS feel like “good enough” until phishing, SIM swap, or credential theft shows that the apparent simplicity is really deferred risk. NHI Mgmt Group’s Ultimate Guide to Non-Human Identities shows how exposure compounds when authentication and secret handling remain weak at scale.

What stronger options change in practice

Stronger authentication is not just about improving the factor itself, it changes the failure mode. Phishing-resistant methods such as hardware-backed authenticators or passkeys reduce reliance on secrets that users can type, reuse, forward, or expose through social engineering. That lowers the probability that a single phish or helpdesk interaction becomes a full account compromise.

SMS-based 2FA is weaker because it still depends on the mobile number, the telecom path, and recovery processes that can be socially engineered or redirected. Organisations often underestimate how much of the real attack surface sits outside the login screen, including identity recovery, number porting, and support desk escalation. The practical shift is from “can the user receive a code?” to “can the attacker replay, intercept, or reset the authentication path?”

  • Passwords remain attractive because they are universal, cheap to deploy, and familiar to users, but they create a durable phishing target.
  • SMS 2FA raises the bar slightly, but it still permits interception, fatigue, and recovery abuse.
  • Phishing-resistant methods reduce both user-error exposure and large-scale replay value for attackers.

Risk and Threat Considerations

Weak authentication persists because many organisations optimise for short-term convenience, but that choice preserves a high-value attack path for credential stuffing, phishing, session takeover, and helpdesk social engineering. The real danger is not only initial compromise, it is the downstream access that follows when one account unlocks internal systems, sensitive data, or privileged workflows.

Failure mechanism: Attackers harvest passwords through phishing or reuse, then defeat SMS-based 2FA by intercepting codes, forcing resets, or abusing support processes that still trust the phone number as proof of identity.

Impact: Account takeover becomes easier to scale, recovery processes become part of the attack surface, and a single compromised login can cascade into broader enterprise access, fraud, or secrets exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63AAL — Authenticator Assurance LevelsAuthenticator strength and phishing resistance directly shape the authentication risk in this question.
FIDO — Phishing-Resistant AuthenticationPhishing resistance is the core control difference between weak factors and stronger options.
Recommendation — Adopt higher-assurance authenticators for sensitive access and reduce reliance on SMS as a primary factor. Prefer phishing-resistant authenticators for workforce and privileged accounts.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlAuthentication choice directly affects how access is established and controlled across the enterprise.
Recommendation — Strengthen authentication requirements for high-risk access paths and align them to account criticality.
CIS Controls v86 — Access Control ManagementThis question is fundamentally about reducing weak access paths and managing authentication exposure.
5 — Account ManagementPassword and SMS dependencies often persist through lifecycle and recovery processes.
Recommendation — Remove weak authentication methods and enforce stronger access controls for critical accounts. Govern account enrollment, recovery, and deprovisioning so weak fallbacks cannot persist indefinitely.
NIST Zero Trust (SP 800-207)3 — Secure Authz on Each RequestStronger authentication supports per-request trust decisions and reduced implicit trust after login.
Recommendation — Use stronger authentication to support continuous, low-trust access decisions for sensitive resources.

Practitioner Guidance

What to prioritise: Start with the accounts that have the highest blast radius, especially admin, finance, support, and remote-access paths. If a weak method is still allowed there, the organisation is tolerating its most expensive failure mode first.

What to verify: Check whether the migration plan actually removes SMS as a fallback, because many programmes keep the old factor alive through recovery exceptions. Also verify that support staff cannot override stronger authentication with weak manual identity proofing unless the exception is tightly bounded and recorded.

Practitioner takeaway: Stronger authentication succeeds when organisations treat recovery, exception handling, and support workflows as part of the control, not as side issues that preserve the old risk.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org