











The Department of War’s (DoW) Chief Information Officer recently published a new resource for the Defense Industrial Base (DIB) Sector, and it’s refreshingly clear and simple. “Brilliant at the Basics” isn’t a mandate or a memo; It’s a ranked list of the ten IT cybersecurity practices and ten OT cybersecurity practices DoW wants its small, mid-sized and non-traditional suppliers to get right, in the order that matters most.
Ten items in, there’s one detail that stands out. It’s not encryption, patching, or backups. The list contains sound advice but the #1 IT best practice, ahead of everything else on the list, is phishing-resistant multi-factor authentication (MFA). Let’s break down what this means and why it matters for the DIB Sector and those working with the U.S. government.
The DoW’s CIO built this initiative for the part of the DIB that doesn’t have a large security team on staff. The stated goal is to “help small, mid-sized, and non-traditional companies confidently secure their networks, protect sensitive DoW information, and deliver peace through technical strength.” Two downloadable lists do the work: a Top 10 for IT cybersecurity and a separate Top 10 for OT (operational technology) cybersecurity, covering everything from asset inventory to backup architecture to workforce readiness.
No compliance deadline is attached yet, but when a department names its #1 priority in writing, that’s a signal worth reading closely – especially for anyone who sells into the defense supply chain.
Here’s the DoW CIO’s own guidance on IT best practice #1: “Upgrade your authentication mechanisms to require strong phishing-resistant MFA methods for user accounts. Moving away from legacy MFA methods such as SMS text messages or push notifications forms the foundation of a modern security stack.”
The message is clear: not all MFA is created equal. SMS codes and push notifications can still be phished, intercepted, or exploited through SIM-swapping, MFA fatigue, and social engineering.
DoW is drawing a clear distinction between MFA that checks a compliance box and MFA that stops modern attacks. Phishing-resistant authentication – such as hardware-backed passkeys like a YubiKey, platform passkeys based on FIDO2/WebAuthn, or PIV/CAC credentials – keeps private keys on the device, preventing credential theft through phishing.
It’s also one of the easiest security controls to deploy. FIDO passkeys are supported by all major cloud and identity providers, and FIPS-validated security keys are readily available to meet government requirements.
The OT list echoes the same priority in different words. Its #1 practice is “Identity and Access Control,” requiring multi-factor authentication for sensitive systems and instructing organizations to “enforce a ‘never trust, always verify’ mindset.” For contractors running both IT and OT environments (common across manufacturing and logistics in the DIB), that’s two separate Top 10 lists agreeing on the same starting point before anything else is addressed.
This reinforces a trend we’ve seen across federal guidance – from M-22-09 for civilian agencies to the NDAA and CISA’s Cybersecurity Performance Goals 2.0: legacy MFA is no longer enough. Authentication must be phishing-resistant by design, not dependent on user vigilance. “Brilliant at the Basics” extends that same principle to the Defense Industrial Base.
If you’re a small or mid-sized DIB contractor, here are four practical next steps:
DoW picked an apt name for this initiative; The basics aren’t glamorous, but getting them right – starting with the credential that decides who gets in – is what actually keeps a network defensible. When the department writing the list ranks phishing-resistant authentication above everything else, that’s not a suggestion to note for later; It’s the foundation the rest of the list is built on.
For more on moving your organization to phishing-resistant authentication that satisfies federal and DIB guidance out of the box, see here.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。