惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Vercel News
Vercel News
Google DeepMind News
Google DeepMind News
罗磊的独立博客
WordPress大学
WordPress大学
The Cloudflare Blog
GbyAI
GbyAI
The Register - Security
The Register - Security
L
LangChain Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
A
About on SuperTechFans
U
Unit 42
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
Visual Studio Blog
云风的 BLOG
云风的 BLOG
Stack Overflow Blog
Stack Overflow Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
Blog — PlanetScale
Blog — PlanetScale
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
M
MIT News - Artificial intelligence
C
CERT Recently Published Vulnerability Notes
T
The Exploit Database - CXSecurity.com
T
Tor Project blog
A
Arctic Wolf
H
Hacker News: Front Page
NISL@THU
NISL@THU
F
Full Disclosure
雷峰网
雷峰网
L
LINUX DO - 热门话题
Recent Announcements
Recent Announcements
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Apple Machine Learning Research
Apple Machine Learning Research
Google Online Security Blog
Google Online Security Blog
I
InfoQ
Webroot Blog
Webroot Blog
S
Security Affairs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
N
News | PayPal Newsroom
Forbes - Security
Forbes - Security
博客园 - Franky
V
Vulnerabilities – Threatpost
博客园 - 【当耐特】
Latest news
Latest news

Yubico

RIP SMS: Microsoft transitioning to passkeys as default authentication method for Entra ID Beyond the login: Top 3 things developers need to know about YubiKey 5.8 OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members to log into ChatGPT accounts Works with YubiKey Spotlight: Translating YubiKey logistics into enterprise cyber resilience with EgoMind’s Appterix Google Play Services adds support for NFC-enabled FIDO2 security keys: How Yubico makes Android passkey authentication seamless Post-quantum cryptography is now a federal mandate: Here’s what it means and what your agency should do now Salesforce enforces MFA for all employee logins: Here’s what you need to know Secure it Forward Spotlight: Cyber defenders as a force for resilience New Executive Order on AI: Identity as a critical foundation for trusted AI YubiKey 5 FIPS Series and YubiHSM 2 FIPS are now FIPS 140-3 validated: What it means for high assurance security Secure It Forward Spotlight: Securing independent journalism with Radio Free Europe / Radio Liberty The passkey spectrum: Importance of user choice in digital security journeys OpenAI’s Advanced Account Security program: Top 5 things Codex users need to know New to OpenAI’s Advanced Account Security program? Here’s how to add your YubiKey to ChatGPT accounts Leading Yubico forward: Q1 reflections and securing the AI frontier Building a safer AI journey: How to add your YubiKey to ChatGPT accounts OpenAI partners with Yubico: What it means for the future of AI-based workflows and the role of the human Works with YubiKey Spotlight: Securing the AI frontier and high-assurance infrastructure Yubico’s commitment to securing the future of digital identities: Reflecting on RSAC 2026 YubiKey as a Service expands to Ping Identity with pre-configured security keys Securing agentic AI: Why automation still needs human oversight Yubico officially lands in Singapore: Opening our third global headquarters Welcome to YubiNation Partners: Reimagining the Future of Channel Partnership to Secure Identity at Scale Yubico’s Clifton Slater recognized as a CRN 2026 Channel Chief Leading Yubico into the Future: 2025 Reflections and Our 2026 Roadmap Fireside chat: Meet Yubico’s new acting CEO, Jerrod Chong Yubico will introduce secure and privacy capable passkey enabled digital signatures in upcoming 5.8 firmware
The 265% ROI of phishing resistance with Yubico: Why modern enterprises are ditching legacy MFA for YubiKeys
Karin Muskopf · 2026-02-03 · via Yubico

For years, we’ve been told that “any MFA is better than no MFA.” While this still holds true, generative AI and sophisticated deepfakes are rapidly evolving the threat landscape, making it even more important than ever for enterprises to modernize their approach to security. Today, legacy multi-factor authentication (MFA) – like one-time password (OTP) SMS codes and mobile push apps – isn’t just a friction point for employees; it’s a growing liability.

We recently commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) of Yubico YubiKeys study to look at the real-world math behind this shift. We wanted to know: What happens when a global enterprise with 5,000+ employees stops “checking the box” on security and starts building actual cyber resilience with YubiKeys?

The results were eye-opening. The study found that a composite organization based on interviewed customers achieved a 265% ROI and a 99.99% reduction in addressable breach risk costs, $5.3 Net Present Value and $7.3 million in total benefits over three years by switching to phishing-resistant YubiKeys with YubiKey as a Service.

The high cost of “good enough” security

The “old way” of doing security, using One-Time Passwords (OTPs) and other forms of basic MFA, comes with a hidden tax that most companies don’t realize they’re paying until they see the data. According to the Forrester findings, the “after” story of switching to YubiKeys isn’t just about stopping hackers; it’s about reclaiming resources:

  • Goodbye, Password Reset Tickets: The study found $476,000 in savings just by eliminating the help desk tickets that pile up when employees lose access to mobile apps or forget their passwords.
  • Faster Workdays: We often think of security as a speed bump. However, the TEI study showed that users authenticated 80% faster with YubiKeys than with legacy MFA. For the composite organization of 5,000 employees, that added up to $2.2 million in productivity value.
  • Operational Peace of Mind: By removing the “human error” variable from phishing, organizations saved $912,000 in labor by avoiding the investigation of addressable credential-based attacks.

Beyond the spreadsheet: The Zero Trust journey and scaling YubiKey deployments without stress

Along with the millions in savings, the qualitative feedback from the study’s participants tells an even more compelling story. As one Principal Identity Engineer in the technology industry put it: “Our CEO stated that we are going to be 100% phishing resistant and passwordless… The only solution that fit the bill was YubiKeys.”

We believe this highlights a critical shift. YubiKeys aren’t just another hardware peripheral; they are the “anchor” for a Zero Trust architecture. Because they support multiple protocols (FIDO2, Smart Card/PIV, and OTP), they allow companies to secure everything from a 20-year-old legacy server to the latest cloud-based AI tools with a single touch.

We know that the biggest hurdle for large enterprises isn’t the why – it’s the how.

That’s why we’ve built the YubiKey as a Service model. We’ve turned the complex logistics of shipping and enrolling keys for a global, distributed workforce into a self-service experience. It shifts your security spend from a lumpy capital expense (CapEx) to a predictable, scalable operating expense (OpEx).

Security shouldn’t be a cost center. When done right, it should be a business accelerator that protects your brand, saves your IT team’s sanity, and actually pays for itself.

And don’t just take our word for it! See below for what interviewed companies are saying about working with Yubico and the impact of YubiKeys on their business.

“Yubico is easy to work with. They had the ability to deliver at the scale and velocity we needed.” Senior manager, cybersecurity, telecom services

“Account takeovers have not happened since we rolled everybody over to YubiKeys.” – General director of information assurance, transportation

“After acquiring YubiKeys to deploy to all our employees, we sought to have it so that their first login would be through a pre-enrolled YubiKey. FIDO Pre-reg satisfied the phishing-resistant requirement and satisfied the goal to be 100% passwordless all in one.” – Principal identity engineer, technology

“Not only do YubiKeys make us more secure, but they also make it easier for our staff and they are cost-effective. We are going to be 99.99% phishing resistant.” – Director of information technology and cybersecurity, government

“If we protect these identities and restrict their usage to FIDO2, it really reduces the attack surface. It is affordable for your partners. You can build it into your contracts and offset that cost. Yubico ships globally and they will handle logistics. No partner wants to be the reason that your customer data got out.” – Senior manager, cybersecurity, telecom services

“Our CEO stated that we are going to be 100% phishing resistant and passwordless. We had to look for what could help us achieve passwordless for the full employee lifecycle and what was 100% phishing resistant. The only solution that fit the bill was YubiKeys.”Principal identity engineer, technology

“YubiKeys are phishing-resistant. They provide the strongest layer of authentication we can offer our clients.”Director of client authentication, financial services

“YubiKeys are a fiscally responsible way to increase your cybersecurity posture.”Director of information technology and cybersecurity, government

“With cybersecurity incidents rising and the climate getting worse, we needed to do everything we could to protect our customer information and data.”Senior manager, cybersecurity, telecom services

Ready to see the full breakdown? Download the complete Forrester Total Economic Impact™ of Yubico YubiKeys study here to dive into the methodology and see how your organization can achieve similar results.

Check out our Webinar with Forrester here to hear a breakdown of the Forrester TEI survey and what this means for organizations exploring and deploying YubiKeys in their organization.