Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: The Case for Hardware Security Keys

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on fake login pages. Cloudflare's employees were tricked too — but attackers still couldn't get in, because Cloudflare required physical security keys.

Why hardware keys work

A security key (or a passkey on a phone or laptop) checks the website's real address before it works. On a fake site, it simply doesn't respond. There's nothing for the employee to type and nothing for the attacker to steal.

The business case

  • Stops credential phishing for the users who have them.
  • Low cost compared with the impact of a breach — keys cost a modest amount each.
  • Insurance and compliance: phishing-resistant MFA is increasingly expected for privileged users.
  • Passkeys on phones extend the same protection without hardware for many users.

Questions to ask your team

  • Which employees would cause the most damage if their accounts were phished?
  • Do they have phishing-resistant sign-in today?
  • What would it cost to issue keys or enable passkeys for them?
  • What's our process if someone loses a key?

What good looks like

Phishing-resistant MFA for administrators, executives, finance and IT support now, with passkeys extending protection to everyone over time.

The decision

Approve a security key budget for your highest-risk users. Cloudflare's experience is one of the clearest examples of a modest investment preventing a serious breach.

0ktapus impact0ktapus / Twilio2022

More on this story