Only 28% of Financial Workforce MFA Is Phishing‑Resistant, Leaving Institutions Exposed to Credential Theft
What Happened — A Secret Double Octopus report finds that just 28% of multi‑factor authentication (MFA) used by financial‑sector employees is phishing‑resistant. The majority of MFA relies on passwords plus OTP or magic‑link flows that can be harvested by phishing attacks, especially on legacy systems.
Why It Matters for Compliance & Audit Readiness —
- SOC 2 CC6.1 (Logical Access) requires controls that prevent credential theft; phishing‑resistant MFA directly satisfies this criterion.
- Continuous evidence of MFA coverage across SaaS and legacy environments is essential for a defensible audit trail.
- The gap highlights a control weakness that can be addressed with Verisq’s SOC 2 Access‑Controls capability, providing automated monitoring and audit‑ready evidence.
Who Is Affected — Banks, credit unions, investment firms, and other financial‑services organizations that manage employee access to critical systems.
Recommended Actions —
- Inventory all workforce authentication flows and classify them by phishing‑resistance.
- Deploy cryptographic, phishing‑resistant MFA (e.g., FIDO2, WebAuthn) for high‑risk applications, including legacy systems.
- Update SOC 2 access‑control policies and capture continuous compliance evidence for audit readiness. Source: Help Net Security
Technical Notes — The report cites password‑plus‑OTP and magic‑link methods as the most common non‑phishing‑resistant techniques; no specific CVEs are involved. The primary risk vector is credential harvesting via phishing. Source: Help Net Security