Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do weak MFA methods fail NYDFS Part…
Authentication, Authorisation & Trust

Why do weak MFA methods fail NYDFS Part 500 expectations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Authentication, Authorisation & Trust

They can be relayed, intercepted, or bypassed through fatigue and social engineering, which means they do not materially reduce risk in the way the regulation expects. In practice, the issue is not the presence of a second step, but whether the method is resistant to modern phishing and interception techniques.

Why weak MFA methods do not satisfy the regulatory bar

nydfs part 500 is not satisfied by any second factor in the abstract. The control has to materially reduce account-takeover risk against current attack techniques. Weak methods such as SMS codes, reusable OTPs, and push approvals are vulnerable to relay, interception, SIM swap, and fatigue-based abuse, so they often add friction without adding much assurance.

That distinction matters because the regulation is about risk reduction, not checkbox completion. A method can be “multi-factor” and still fail the practical test if an attacker can obtain or replay the factor during the same session or social-engineer the user into approving access.

How weak MFA is defeated in practice

Weak MFA usually fails in one of three ways: the code is stolen in transit, the user is tricked into revealing or approving it, or the second step is bypassed after the session is already trusted. SMS OTP is exposed to SIM swap and message interception, reusable OTPs can be relayed in real time, and push-based approvals are often defeated by repeated prompts or help-desk manipulation.

What makes these methods weak is not that they never work, but that they do not reliably resist the most common adversary paths. If the factor can be captured, forwarded, replayed, or socially engineered at scale, it does not meaningfully narrow the attacker’s options.

That is why phishing-resistant methods such as NIST SP 800-63 Digital Identity Guidelines place so much emphasis on authenticator strength, verifier binding, and resistance to replay and phishing.

What NYDFS expects instead of checkbox MFA

The practical expectation is that MFA should be hard to phish, hard to relay, and hard to coerce through routine user interaction. In other words, the method should still hold up when the attacker has the password, a convincing login page, or the ability to pressure the user in real time.

That is why MFA Guide, Passwordless and Passkeys Guide, and Workforce Identity Security Guide all point practitioners toward phishing-resistant MFA, passkeys, and stronger recovery controls rather than relying on SMS or approval fatigue defenses.

In regulated environments, the real question is whether the factor materially changes the attacker’s effort and success rate. If the answer is no, the method may satisfy a literal “second step” but still miss the control objective behind the rule.

Risk and Threat Considerations

Weak MFA increases the chance that a stolen password, leaked session, or social-engineering campaign becomes a successful login. It also creates a false sense of protection, which can delay stronger controls such as phishing-resistant authenticators, recovery hardening, and session protection.

Failure mechanism: Attackers relay OTPs in real time, intercept SMS through telecom abuse, or trigger MFA fatigue until the user approves access. Once they obtain a valid session, they can move laterally or abuse trusted access paths without needing to defeat MFA again.

Impact: The organisation may still suffer account takeover, unauthorized access, data exposure, and downstream privilege abuse even though “MFA” is enabled. In a regulated setting, that means the control may fail both operationally and in supervisory review because it does not deliver durable resistance to current attack methods.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesPhishing-resistant authenticators and assurance levels directly address weak MFA adequacy.
Recommendation — Use phishing-resistant authenticators and assurance levels that withstand replay and real-time phishing.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Weak MFA concerns how organizational users are authenticated and protected from takeover.
IA-5 — Authenticator ManagementMFA weakness often comes from lifecycle, reset, and authenticator handling weaknesses.
IA-9 — Identification and Authentication (Non-Organizational Users)Weak MFA controls for external users and customer-facing access also hinge on authenticators.
Recommendation — Require stronger user authentication methods that resist interception and social engineering. Manage authenticators to prevent reuse, interception, and insecure recovery paths. Apply stronger authentication to external access paths that can be phished or relayed.
ISO/IEC 27001:2022A.5.17 — Authentication informationWeak MFA methods relate directly to the handling and robustness of authentication information.
Recommendation — Protect authentication information with methods that are resistant to capture and replay.
OWASP ASVSV6 — AuthenticationThe issue is whether authentication methods withstand phishing, relay, and MFA fatigue attacks.
Recommendation — Select authentication mechanisms that resist phishing, replay, and approval abuse.

Practitioner Guidance

What to verify: Treat “MFA enabled” as insufficient unless you can show the method is phishing-resistant or at least resistant to relay and real-time interception. Verify how enrollment, recovery, and help-desk reset flows are protected, because weak recovery often negates the value of a strong factor.

Decision rule: If the factor can be approved, relayed, or intercepted during the login transaction, treat it as a transitional control, not a durable compliance answer. Prioritise passkeys, hardware-backed authenticators, or equivalent phishing-resistant methods for users with meaningful access.

Common mistake: Many teams focus on the presence of MFA and ignore whether the second factor survives modern phishing kits, adversary-in-the-middle attacks, and social-engineering pressure. That is the gap regulators and attackers both care about.

Practitioner takeaway: For NYDFS Part 500, the standard is not “did a second step exist?”, it is “did the method materially reduce takeover risk under realistic attack conditions?”

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org