ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The changing face of identity security

For more than a decade, multi-factor authentication (MFA) has been one of cyber-security’s most effective defences. The logic was simple enough: even if an attacker managed to steal a password, they would still need a second factor to gain access to an account. Organisations embraced the approach, regulators encouraged it, and security teams treated MFA deployment as a major milestone in reducing identity-based risk.

 

Yet despite its widespread adoption, account compromise remains one of the most common causes of security incidents. The reason is not that MFA has failed. Rather, attackers have become increasingly adept at working around it.

 

Many of the identity attacks seen today no longer focus on defeating technical controls directly. Instead, they exploit the people using them. MFA fatigue attacks, in which users are bombarded with authentication requests until they eventually approve one, have become a common tactic. At the same time, increasingly sophisticated phishing campaigns are capable of capturing credentials, authentication tokens and active sessions, allowing attackers to bypass security measures that organisations may still regard as robust.

 

These developments are forcing security leaders to reconsider a long-standing assumption: that any form of MFA automatically provides strong protection. In reality, there is a growing recognition that the effectiveness of authentication depends not simply on the number of factors involved but on the resilience of those factors to modern attack techniques.

 

This is one reason why SMS-based authentication is gradually falling out of favour. While text-message verification helped drive MFA adoption, concerns around phishing, SIM-swapping and social engineering have exposed its limitations. The wider industry is already responding. Microsoft recently signalled plans to move users away from SMS-based authentication, reflecting a broader shift towards stronger and more phishing-resistant alternatives.

 

At the centre of that shift are passkeys. Rather than relying on passwords and one-time codes, passkeys use cryptographic credentials tied to a trusted device. Authentication takes place through a fingerprint, facial recognition or device PIN, removing many of the opportunities attackers traditionally rely on to steal or intercept credentials. For users, the experience is often simpler. For organisations, it offers a way of reducing one of the most persistent risks in cyber-security: the human element of authentication.

 

The growing interest in passkeys also reflects a wider change in how organisations approach identity security. For years, the focus was on adding layers of protection to passwords. Increasingly, the goal is to reduce dependence on passwords altogether. According to current MFA best-practice guidance, organisations are placing greater emphasis on phishing-resistant authentication methods, adaptive access controls and risk-based approaches that continuously evaluate trust rather than relying on a single login event.

 

Most organisations are unlikely to abandon traditional MFA overnight. Legacy systems, third-party applications and operational realities mean authenticator apps and one-time passcodes will remain part of the security landscape for some time. What is changing, however, is the benchmark against which authentication is judged.

 

A few years ago, simply enabling MFA was considered evidence of good security practice. Today, organisations are increasingly asking a different question: can their authentication methods withstand the phishing techniques attackers are actually using? As identity becomes the primary battleground in cyber-security, the answer to that question may prove far more important than whether MFA is deployed at all.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543