logo

CISA Strongly Recommends Phishing-Resistant MFA

ID: 6a565b68-396e-5b32-a03e-671fd231f3e2

STIX ID: report--6a565b68-396e-5b32-a03e-671fd231f3e2

Feed Name: KnowBe4 Blog

Date Published: 2024-11-27

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

This blog post advocates for phishing-resistant MFA, highlighting that many common MFA methods (e.g., SMS, OTP, push) can be easily phished or bypassed and endorsing stronger options in line with recommendations from CISA, NIST, and major vendors. It recounts KnowBe4’s long-standing campaign—sparked by a 2018 Kevin Mitnick demo—to educate on MFA weaknesses, provides resources (webinars, tools, articles, and a book), and argues for prioritizing phishing-resistant MFA wherever possible while acknowledging continued risks and offering mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.