CIO Brief: The Case for Hardware Security Keys
Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on fake login pages. Cloudflare's employees were tricked too — but attackers still couldn't get in, because Cloudflare required physical security keys.
Why hardware keys work
A security key (or a passkey on a phone or laptop) checks the website's real address before it works. On a fake site, it simply doesn't respond. There's nothing for the employee to type and nothing for the attacker to steal.
The business case
- Stops credential phishing for the users who have them.
- Low cost compared with the impact of a breach — keys cost a modest amount each.
- Insurance and compliance: phishing-resistant MFA is increasingly expected for privileged users.
- Passkeys on phones extend the same protection without hardware for many users.
Questions to ask your team
- Which employees would cause the most damage if their accounts were phished?
- Do they have phishing-resistant sign-in today?
- What would it cost to issue keys or enable passkeys for them?
- What's our process if someone loses a key?
What good looks like
Phishing-resistant MFA for administrators, executives, finance and IT support now, with passkeys extending protection to everyone over time.
The decision
Approve a security key budget for your highest-risk users. Cloudflare's experience is one of the clearest examples of a modest investment preventing a serious breach.
- 0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies Incident Teardowns
- How to Deploy FIDO2 Security Keys for High-Risk Users How-To & Hardening
- Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL Detection & Response