Practical guideEN052

Passkeys vs. Phishing-Resistant MFA: What Should Your Small Business Implement First?

Deciding between passkeys and phishing-resistant MFA? Learn practical steps, free resources, and expert context to choose the right first step for your small business.

For a small business with limited IT resources, the first step should be to require multifactor authentication (MFA) on all accounts that support it, then move toward phishing-resistant methods as tools allow. Passkeys are a strong and convenient passwordless option, but support is not yet universal. Phishing-resistant MFA, such as security keys or number matching, directly counters credential theft via phishing. Both CISA and NIST provide free, practical guidance tailored for small businesses, including fact sheets and step-by-step guides. Start by enabling MFA on email, financial systems, and any platform holding customer data. Then, evaluate passkeys for the most used applications, but keep MFA as a fallback until passkeys are fully supported. The goal is layered defense: if a password is compromised, a second factor still blocks unauthorized access.

Why MFA Is the Urgent First Step

MFA adds a second verification layer beyond the password, making unauthorized access significantly harder. CISA’s guidance for small businesses identifies MFA as a core practice, alongside phishing avoidance and software updates. Their free printable fact sheets and short online trainings help your team adopt MFA without requiring a security specialist.

For most small businesses, the highest-risk account is email, as compromise can lead to invoice fraud or data theft. Enabling MFA on email is a low-cost, high-impact action. CISA recommends using app-based authenticators over SMS whenever possible, because SMS can be intercepted via SIM-swapping or other techniques.

  • Enable MFA on all email and financial accounts first.
  • Prefer authenticator apps or hardware tokens over SMS.
  • Train staff with CISA’s free fact sheets and videos.
  • Verify MFA support in every critical SaaS tool you use.
Sources and verification date: [1][2]

Understanding Phishing-Resistant MFA

Phishing-resistant MFA refers to methods that cannot be easily tricked by fake websites. Traditional SMS codes or one-time passwords from authenticator apps can be captured by a phishing site that asks the user to enter them. In contrast, phishing-resistant methods like FIDO2 security keys or number matching are tied to the legitimate site’s domain, so a fake site cannot misuse the credentials.

CISA’s guidance on implementing number matching in MFA applications is a practical, low-cost upgrade to existing MFA apps. Number matching requires the user to see a code on their device and type it into the site, which prevents real-time phishing interception. This can be deployed without purchasing new hardware.

  • Phishing-resistant MFA blocks credential reuse on malicious sites.
  • Security keys are hardware tokens that provide high assurance.
  • Number matching is a free feature in many authenticator apps.
  • Choose methods your team will actually use consistently.
Sources and verification date: [1]

Passkeys: A Convenient Passwordless Option

Passkeys are a passwordless alternative that leverages public key cryptography, similar to security keys but built into devices and browsers. When you create a passkey, the service stores only the public key; your device holds the private key, which is unlocked via fingerprint, face scan, or PIN. This eliminates the risk of reused passwords and reduces the burden of remembering credentials.

For small businesses, passkeys simplify login for employees and lower the risk of credential stuffing attacks. However, adoption varies: not every service or device supports passkeys, and legacy systems may still require passwords. NIST’s quick-start guide emphasizes a risk-based approach: identify the most valuable accounts and apply the strongest protection available, which may be passkeys on some platforms and MFA on others.

  • Use passkeys where supported, such as major cloud email providers.
  • Keep an alternative sign-in method in case a device is lost or replaced.
  • Test passkeys across the devices your team uses to ensure compatibility.
  • Do not disable existing MFA until you confirm passkeys work reliably.
Sources and verification date: [2]

Step-by-Step Implementation for a Small Team

Start by creating an inventory of your accounts and data. Identify systems that store sensitive customer, financial, or employee information. CISA recommends developing an incident response plan, but you can build it over time. NIST’s quick-start guide walks you through the core functions: identify, protect, detect, respond, and recover.

Next, enforce MFA on all high-risk accounts. Turn it on for email, cloud storage, payroll, and any platform that can access customer data. Then, for the top three tools your team uses daily, research whether passkeys are offered. Enable passkeys where possible, but keep MFA active as a fallback. Pilot the change with a small group before company-wide rollout to address issues early.

  • List critical accounts and categorize data sensitivity.
  • Enable MFA everywhere first, prioritizing email and finance.
  • Use free CISA training to coach your team on new methods.
  • Pilot passkeys on one system to evaluate user experience.
Sources and verification date: [1][2]

Avoiding Common Pitfalls and Staying Informed

A frequent mistake is investing in advanced security tools before enforcing basic MFA. Start with the free guidance from CISA and NIST, which is sufficient to begin. Also, be wary of vendors using the term “passkeys” loosely-true phishing-resistant passkeys are based on public key cryptography and domain binding. Verify the technology before trusting it.

Cyber threats evolve, so check CISA and NIST websites periodically for updated recommendations. If you operate in a regulated industry, ensure your authentication choices meet applicable compliance standards. Prioritize government sources over vendor claims for baseline expectations, and document your security decisions for audits and reviews.

  • Enforce MFA before exploring premium security hardware.
  • Confirm any passkey solution is genuinely phishing-resistant.
  • Review CISA and NIST updates at least quarterly.
  • Maintain a record of your security decisions for future reference.
Sources and verification date: [1][2]

What to verify

  • Passkey support varies by platform and service; verify that your specific tools support them before implementation.
  • Regulatory or compliance requirements may impose additional security controls beyond general guidance; consult a qualified professional.
  • CISA and NIST resources are US-based; readers in other countries should adapt guidance to local laws and regulations.

Questions and answers

What is the difference between standard MFA and phishing-resistant MFA?

Standard MFA often uses SMS codes or one-time passwords from authenticator apps. These can be intercepted by a phishing site that prompts you to enter the code. Phishing-resistant MFA, such as number matching or hardware security keys, uses cryptographic verification that only works on the legitimate site, so a fake site cannot misuse the credentials. [1]

Are passkeys the same as MFA?

No. Passkeys are a passwordless sign-in method that can serve as a second factor, but they are not a separate MFA system. When used alone, passkeys replace the password. Many services offer passkeys, but you still need MFA for accounts that do not support passkeys yet. [2]

What are the costs of implementing phishing-resistant MFA or passkeys?

Basic MFA via an authenticator app is often free. Upgrading to number matching or hardware security keys may cost between $20 and $80 per key, depending on the model. Government resources like CISA’s fact sheets and NIST’s guide are free to download. For specific pricing, check current vendor offerings. [1][2]

Sources and verification date

  1. Official source: cisa.govcisa.gov · Checked
  2. Official source: csrc.nist.govcsrc.nist.gov · Checked

Related reading