New report shows data breaches, phishing and regulations driving rapid adoption of strong authentication
By FF Newsroom · 23 January 2019

As data breaches and increasingly sophisticated phishing attacks continue to drive online account compromise and financial loss, organisations are finally stepping up and investing in stronger, phishing-resistant forms of authentication, Javelin Strategy & Research’s new “The State of Strong Authentication 2019” report has found.
The report, sponsored by the FIDO Alliance, analyses the state of customer and enterprise (employee) authentication amongst U.S. businesses and draws conclusions on the role strong authentication is playing in protecting accounts and securing access to valuable data and critical systems.
The 30-page report is available for free download at https://fidoalliance.org/2019- strong-authentication-report/.
In the report, Javelin’s key findings and recommendations show:
- Strong authentication implementations have grown dramatically since 2017. The number of organisations using cryptographically-backed strong authentication, where one of multiple authentication factors uses public key cryptography, has tripled since 2017 for consumer authentication and increased by nearly 50 percent for enterprise authentication in the same period. This form of authentication is not susceptible to phishing, man-in-the-middle and/or other attacks targeting credentials -- which are known vulnerabilities with passwords and one-time passwords (OTPs)
- Regulation is accelerating strong authentication adoption. Nearly 70 percent of businesses agree they face strong regulatory pressure to provide strong authentication for their customers. This is attributed to the introduction of PSD2, along with data protection regulations in the EU and U.S. states such as California
- Strong authentication holdouts are underestimating risks to their businesses and customers. Two-thirds of businesses that use only passwords to authenticate their employees do so because they believe passwords are “good enough” for the type of information they are protecting, despite cybercriminals’ continuing to target a wide variety of consumer and business information
- Not all strong authentication is created equal. According to Javelin, adopting strong authentication solutions that are based on standards and employ cryptographic security (like FIDO Authentication) can help organisations lower the cost of keeping up with regulation, customer expectations and increasingly sophisticated fraud schemes
- It’s time to sunset OTPs. With cyber criminals using social engineering, phone porting and malware to compromise OTP authenticators, Javelin recommends moving away from them and adopting cryptographically-backed strong authentication