CISA on phishing-resistant MFA and Secure Our World
CISA's authentication guidance is blunt: not all MFA is equal. FIDO2/WebAuthn and PKI-based MFA resist phishing; SMS and push do not. Plus the four everyday habits behind the Secure Our World campaign.
CISA publishes guidance for two very different audiences at once: security teams choosing authentication technology, and the general public. Its position on multi-factor authentication is the same for both — turn it on — but for organizations it adds an important caveat about which kind.
Not all MFA is equal
In its fact sheet on implementing phishing-resistant MFA, CISA ranks authentication methods by how well they hold up against a real attacker. At the top sit FIDO2/WebAuthn authenticators and PKI-based methods (such as PIV/CAC smart cards), because the credential is bound to the legitimate website's origin and cannot be relayed to a fake one. App-based one-time codes and push notifications are better than nothing but remain phishable — a convincing fake site or a push-fatigue attack can capture or trigger them. SMS codes are the weakest, also exposed to SIM-swap and interception.
Move high-value accounts to phishing-resistant MFA
Treat FIDO2/passkeys or PKI-based MFA as the target for administrators, privileged accounts, and anything internet-facing. Keep app-based codes as a fallback and retire SMS where you can. This is also what OMB M-22-09 requires of federal agencies under zero trust.
Secure Our World: the four habits
For the public, CISA's Secure Our World program boils cybersecurity down to four actions anyone can take. They are unglamorous on purpose — this is the 90% that prevents the most common compromises.
- **Use strong, unique passwords** — and a password manager to keep them all.
- **Turn on multi-factor authentication** everywhere it is offered.
- **Recognize and report phishing** — stop and check before you click or reply.
- **Update your software** promptly, ideally with automatic updates on.