New Phish-Resistant Security – FIDO Keys

19 September 2024
Get in touch

Share on social..

The Harsh Reality of Modern Cyber Threats Today

Here’s a sobering statistic: phishing was responsible for 84% of business breaches in the UK last year.

Nearly all of them were down to human error.

Let that sink in for a moment.

Despite our best efforts with extra security measures like complex passwords and Multi-Factor Authentication (MFA), cybercriminals are still finding ways to exploit human error.

As a business owner, this might make you feel vulnerable, and rightfully so. But you’re not alone in this fight.

The Rise and [Anticipated] Fall of MFA: A Brief History

Remember when setting a strong password was all you needed to keep your accounts safe? Those days are long gone. As cybercriminals became more sophisticated, the humble username-password combination proved woefully inadequate.

Enter Multi-Factor Authentication (MFA).

For a while, MFA seemed like the perfect solution. It significantly improved security for many businesses and individuals. However, as with any security measure, determined cybercriminals eventually found ways to overcome it.

The Next Evolution in Cybersecurity: Passkeys and FIDO Security Keys

Imagine a world where you don’t have to worry about your employees falling for a clever phishing email. A world where logging in is as simple as tapping a small device, with no complex and easily forgettable passwords to remember or codes to input.

This isn’t science fiction – it’s the reality of passkeys and FIDO security keys.

What is FIDO?

First, what exactly is FIDO?

FIDO stands for Fast Identity Online.

An alliance was formed in 2013 between the big tech giants like Google, Microsoft and other cybersecurity experts who continue to work together to improve online security and to “help reduce the world’s over-reliance on passwords”.

This coalition is also known as the FIDO alliance.

What Are Passkeys?

Passkeys are a ground-breaking technology that ties your login to a specific device.

Think of it as a unique, digital key that only works with your specific ‘lock’. It’s based on well-established public key infrastructure (PKI) technology.

Here’s how passkeys work:

  1. When you set up a passkey for a website or app, two digital ‘keys’ are created – one public, one private.
  2. The public key is stored on the website or app’s server. The public key is effectively useless without the private key, therefore, is not considered sensitive information, unlike a password.
  3. The private key is stored securely on your device.
  4. When you log in, the website/app checks if your private key matches the public key they have stored.
  5. If they match, you’re in! If not, access denied.

This system offers a much greater level of protection because no secret authentication information is transmitted during this exchange. The website or app you’re logging into is only checking to see if the two ‘digital keys’ match.

Passkeys are built on the global FIDO2 authentication standard, supported by the FIDO alliance.

What Are FIDO Security Keys?

FIDO security keys take this concept a step further. These are physical devices that store your passkeys, offering an extra layer of tangible security. Here’s what you need to know:

  1. FIDO security keys contain passkeys and operate using the same public key infrastructure technology.
  2. The main difference is that the passkeys are tied to a portable, physical security device that needs to connect to your laptop, computer, or tablet to authenticate your credentials.
  3. The current market leader for producing FIDO security keys is Yubico, with their product line called YubiKeys.
  4. Currently, YubiKeys can store a maximum of 25 passkeys, with the potential for increased capacity in the future.

The main advantage of FIDO security keys is that the same key can be used across multiple devices, so users are not restricted to using one device.

However, they do require the user to have the key with them to complete the authentication – both their core advantage and a potential disadvantage if the user leaves their key at home.

Why This Should Matter to You

As a business owner, you might be thinking, “This sounds great, but what does it mean for me?” Here’s why you should care:

  1. Phishing Resistant: Unlike passwords or even MFA codes, passkeys stored on FIDO security keys can’t be stolen or tricked out of you by a crafty phishing email. A hacker using an unauthorised device will not be able to access your data and resources because they need to physical security key to be able to log in.
  2. User-Friendly: No more frustrated employees who can’t remember their complex passwords or have lost their phones with the MFA app. Logging in becomes as simple as inserting the security key and tapping it to authenticate credentials.
  3. Consistent Across Platforms: Major tech companies like Google and Microsoft are all on board with passkeys and FIDO security keys, meaning you’ll be able to use them across various devices and platforms.
  4. Peace of Mind: Imagine being able to focus on growing your business, knowing that your digital assets are protected by cutting-edge technology. That’s the peace of mind that passkeys and FIDO security keys can offer.

What If I Lose My Security Key?

Now, you might be wondering, “What if my employees forget or lose their security keys?” It’s a valid concern, and it’s why we recommend registering multiple keys for each account. Yes, there will be a learning curve, but think of it as an investment in your business’s future security.

Looking Ahead: The Future of Cybersecurity

As we look into the future, the cybersecurity landscape will continue to evolve. There are already discussions about the potential role of AI and deep fakes in future identity theft scenarios. While it’s too early to predict the exact impact, one thing is clear – staying ahead of the curve is crucial.

Your Next Steps

As a small business owner, embracing these changes might seem daunting. But remember, you don’t have to go it alone. At Lumina, we’re committed to guiding small businesses like yours through the ever-changing cybersecurity landscape.

We’re rolling out passkeys, FIDO keys, and other cutting-edge security measures as part of our PRISM Business/Enterprise packages. These comprehensive security solutions are designed to give you peace of mind, allowing you to focus on what you do best – running and growing your business.

Ready to take your cybersecurity to the next level? Let’s have a conversation about how we can secure your digital future together. Your future self (and your data) will thank you.

 

 

What our customers say

Lumina Technologies have taken the time to understand the requirements of our business and work as our strategic IT partner, enabling us to concentrate on delivering a high quality service to our clients and focus on our growth strategy. They have delivered a 100% cloud solution to our business with no underlying infrastructure costs or maintenance, which gives us scalability for our planned growth. It also means our business critical applications and data are securely accessible from virtually all our user devices. Lumina’s professional approach and strategic expertise is highly valued and their management of our IT – based on their in-depth knowledge, leaves us confident that our systems are available 24×7.

Luke Harrison
Keidan Harrison LLP

Lumina have supported us so well through the difficult circumstances of 2020.  They worked extremely hard to ensure we were able to work remotely and continue to operate our business successfully. The support team are very friendly and knowledgeable, and have excellent response times.

The team have also enhanced our cyber security which is so important in the legal sector, and they continue to provide high quality advice to help us move forward with our IT goals.

Robin Illingworth
Managing Partner, Adams & Remers LLP

The quality of IT Support provided by Lumina Technology is of the highest standard and is complemented by effective client liaison with impressive response times. Trap Oil Group plc has no hesitation in recommending Lumina as a dedicated and specialist group of IT professionals.

Martin David
Technical Director, Trap Oil Group plc

Richard and his team are a real inspiration to anyone who meets them and I have watched Lumina’s growth over the last few years with interest and admiration. Richard has been an amazing supporter of the Hospice of St Francis, being a Gold member of the Corporate Partner Network for almost two years. He takes an active interest in the community and is passionate about his company and his town: nothing is too much trouble, he is always willing to help, to give up his time and to provide business advice when asked. Lumina is an inspiration to any company wanting to set up business in Hertfordshire.

Carolyn Addison
Corporate Fundraising Manager, The Hospice of St Francis

Lumina Technologies Prism Hosted Desktop has allowed our business to centralise our global corporate data, allowing much faster access for all our staff – regardless of their location. We have also been able to simplify and reduce our infrastructure and management overhead. With the new Prism Hosted Desktop solution all staff now have simple and secure access to corporate data using any device they choose. Prism Hosted Desktop has increased the productivity of our staff and given us a single, consistent and familiar experience for all users from any device, in any location, 24/7.

Katherine Roe
Chief Executive Officer, Wentworth Resources PLC

The commercially sensitive and regulated nature of Lambert Energy Advisory’s business requires an IT provider able to maintain the highest levels of integrity and confidentiality, Lumina Technologies has consistently been unimpeachable in this regard over the nine years we have employed them.

Patrick Agar
Lambert Energy Advisory

It has been a great pleasure working with Lumina Technologies over the past two years. They have fully committed to being involved in the local community with volunteering and with professional advice and commitment, helping many local charities along the way. As a growing company it proves that being involved in the local community is helping them attract and retain a talented workforce and I look forward to working with them well into the future.

Cindy Withey
Connect Dacorum

Hawkstone Management Services Ltd is a small company for which IT Outsourcing is realistically the only viable option. Lumina Technologies have successfully performed this role for over fifteen years. They also provide innovative solutions to keep pace with technological progress. I would have no hesitation in recommending Lumina to similar sized businesses.

Stephen Pembury
Hawkstone Management Services Ltd

Charles Douglas Solicitors LLP have been using Lumina Technologies for a number of years now and continue to be impressed by the technical know-how and contemporary knowledge of their senior management, who provide a timely, efficient and friendly service. Whether it is a small issue with one computer, or a strategic IT decision, they maintain a current knowledge of available technologies. Lumina are always at the other end of the phone to help resolve issues and minimise business interference. The technical knowledge of Richard and his senior team means that there has not been a problem that they can’t solve to date. I am sure we will continue to use them in the years to come.

Charles Douglas
Managing Partner, Charles Douglas Solicitors LLP

The team at Lumina Technologies have made the Amoun Travel & Tours office IT transition seamless and problem free. The office set-up has been vastly improved and the IT Support services are flawless. No issue goes unresolved, which is extremely reassuring.

Adam Helmy
Amoun Travel & Tours Ltd

Lumina Technologies has been Salamander Energy plc’s IT provider since start-up in 2005 and has supported us in London during our expansion across operational offices in SE Asia. Their professional approach, strategic advice and close co-operation have been essential in making this a success.

John Bell
Group Technical Director, Salamander Energy plc

Richard and his team at Lumina have provided Perrett Laver Limited with high quality strategic and practical IT Services for over ten years. During this period, Perrett Laver has grown from 10+ colleagues based in London to nearly 100 colleagues located in six offices across the Americas, EMEA and Asia-Pacific. Richard and the Lumina team have not just been responsive to our ‘everyday’ IT needs, but have proactively sought to work with us on developing an infrastructure suitable for the type of operation we are today, and are planning to be months and years down the line. I would not hesitate to recommend Richard, especially for small to medium size business with growth in mind.

Clementine McKinley
COO, Perrett Laver Limited

Society Limited has been supported by Lumina Technologies since our earliest start-up phase. From large logistical challenges like an office move, through to smaller fiddly issues like fixing a faulty e-template, we know we can count on their support and advice. They’ve also been able to engage with us strategically on the challenge of scaling-up our infrastructure as the firm continues to grow and evolve. We always feel confident going to Lumina with a problem, since we know they genuinely care about sorting things out and helping us to get on with our core business.

Simon Lucas
Managing Director, Society Limited

The Vita Group HQ staff have worked with Richard McBarnet and Lumina Technologies for over 9 years, with Lumina providing all our PC, server, phone, and software support. The services have included C-level executives based in London, Manchester, the US, as well as supporting home office IT as well. The service provided and intellectual capabilities are outstanding and we would highly recommend Richard and his Lumina team.

Joe Menendez
CEO, The Vita Group

We worked with Lumina on a GDPR Audit. Richard was knowledgeable and professional throughout, and did the best he could to bring a dry topic to life through lots of real life examples and analogies. We were so impressed with the service Lumina provided and the value we got from partnering with them on this project – we couldn’t recommend them enough.

Holly Cottingham, Vintec Laboratories

We’ve been so well supported by Paige and the Lumina team. They’ve been highly professional, very responsive, friendly, supportive. It’s really validated the decision to engage an IT partner, and we’re glad it’s with Lumina. 

Bruce Storey
Chief Operating Officer, Estu Global Ltd

Discuss your business needs today

Get in touch Schedule a call