Turning on multi-factor authentication was the right call. But the federal agency that writes the guidance is clear that most of what companies deployed can still be walked straight through — and the fix is narrower than the marketing suggests.
If you rolled out multi-factor authentication in the last few years, you did the single most useful security thing available to a mid-market company. Nothing in this article argues otherwise. Keep it on.
But there is a distinction inside the term “MFA” that most organizations never had explained to them, and it decides whether your second factor stops a determined attacker or merely inconveniences one.
The Cybersecurity and Infrastructure Security Agency — CISA, the federal body that publishes this guidance — draws a line between MFA generally and phishing-resistant MFA specifically. In its public guidance, CISA states plainly that the only widely available phishing-resistant authentication is FIDO/WebAuthn.[1] Its fact sheet on the subject identifies two qualifying approaches: FIDO/WebAuthn authenticators, and MFA built on an organization’s PKI — the smart-card model used across federal agencies.[2]
Read that carefully, because of what it leaves out. A six-digit code texted to a phone is not on the list. A rotating code from an authenticator app is not on the list. A push notification you approve by tapping “Yes” is not on the list — and CISA treats number matching, the feature vendors added to harden push, as an interim mitigation rather than a solution.[2]
Almost every mid-market MFA deployment we encounter runs entirely on methods that fall outside CISA’s definition of phishing-resistant.
The attack that defeats them is called adversary-in-the-middle, and it is worth understanding because it explains why “we have MFA” is not the end of the conversation.
The attacker stands up a proxy between your user and the real login page. Your employee receives a convincing link, lands on what looks exactly like the genuine sign-in screen, and enters their password. That password is relayed to the real service. The real service issues a genuine MFA challenge. Your employee, seeing a prompt they expected, approves it. The proxy captures the session cookie that gets issued afterward — and a session cookie is what actually grants access.
Nothing was broken. The code was real, the prompt was real, and the user did what they were trained to do. The attacker simply stood in the middle and kept the result.
Phishing-resistant methods defeat this because the credential is cryptographically bound to the legitimate site’s origin. A proxy on a lookalike domain cannot satisfy that check, so the login fails at the attacker’s server rather than succeeding at yours. As CISA puts it, when a malicious actor tricks a user into logging into a fake website, the FIDO protocol blocks the attempt.[1]
It does not mean your current MFA is worthless. Password-only access remains dramatically worse than any second factor, and the overwhelming majority of opportunistic attacks never get past even weak MFA. If your choice today is between a text-message code and nothing, take the code.
It also does not mean you need to replace everything this quarter. CISA’s own advice is sequenced: start with the services that already support phishing-resistant methods — most hosted mail and single sign-on platforms do — because that is where the valuable data sits and where the vendor support already exists.[2] It further suggests that rolling out to everyone simultaneously is often impractical, and that a sensible first phase covers groups like help desk staff and system administrators.[2]
That is a roadmap, not an emergency.
If you take one thing from this: the next time a vendor or IT partner tells you multi-factor authentication is enabled, ask which methods are permitted, and whether any phishing-resistant option is available on the systems that matter most. “MFA is on” and “we have ruled out adversary-in-the-middle” are very different statements, and only one of them is usually true.
The answer might reasonably be that phishing-resistant methods are not viable across your environment yet. That is a legitimate position. What you want to avoid is nobody having asked.
A note on scope. NETIT is a vendor-neutral technology advisor, not a managed security provider. Nothing here is a compliance determination or a substitute for guidance from your security, legal, or compliance leads. It is a summary of published federal guidance and what we consistently see when we look at real environments.
A technology assessment covers exactly this — what is enabled, what is possible, and what is worth doing first. No cost, no obligation.
Talk With an Advisor →