Phishing-Resistant Authentication: A Strategic Imperative for CISOs episode artwork

EPISODE · Sep 4, 2025 · 25 MIN

Phishing-Resistant Authentication: A Strategic Imperative for CISOs

from The Security Strategist

Passwords remain one of the weakest links in enterprise security. Despite advances in multi-factor authentication (MFA), recent data breaches show that attackers continue to bypass traditional protections. In this episode of The Security Strategist, host Trisha Pillay speaks with Nic Sarginson, senior solutions engineer at Yubico.Together, they explore the vulnerabilities of passwords and conventional MFA, and why phishing-resistant authentication is no longer optional; it’s a strategic imperative for chief information security officers (CISOs)."Passwords alone just don’t cut it," says Sarginson. Hackers can launch sophisticated attacks in minutes, and traditional MFA often isn’t enough to stop them. Organisations should turn to device-bound passkeys and physical security keys not just as tools, but as a way to rethink enterprise security, stay ahead of compliance pressures, and embrace a passwordless future."Attackers can now launch sophisticated campaigns quickly and cheaply using publicly available data. That’s why breaches today are far more dangerous, and why weak MFA or social engineering is often involved." — Nic Sarginson, Yubico,Why This Matters for CISOsCybersecurity leaders face growing pressure to defend against phishing attacks, navigate evolving compliance demands, and deliver secure experiences for users. Sarginson shares practical strategies, expert insights, and real-world examples to help CISOs and IT leaders build a stronger, passwordless future.TakeawaysPasswords are fundamentally broken and pose a major vulnerability.Recent breaches highlight the inadequacy of traditional MFA.Device-bound passkeys offer stronger protection against phishing.Integration of new security methods is a significant challenge for enterprises.Real-world case studies show measurable improvements with security keys.Regulatory frameworks are increasingly mandating strong MFA.Phishing resistance must become the default in security strategies.The technology for passwordless solutions is now prevalent.Security leaders must advocate for proactive security measures.User education is crucial for the adoption of new security technologies.Chapters00:00 Introduction to Authentication Challenges02:15 The Impact of Recent Data Breaches05:30 The Entrenchment of Passwords and MFA08:22 Exploring Device Bound Passkeys11:20 Integrating Physical Security Keys14:34 Real-World Case Studies and Metrics17:24 Regulatory Pressures and Future Trends20:27 The Path to Passwordless SecurityAbout Nic SarginsonNic Sarginson is a senior solutions engineer for UKI and RSA at Yubico. An industry veteran, he has held a range of roles in cybersecurity and enterprise solutions, helping organisations adopt strong authentication methods and enhance their phishing resistance strategies.

Episode metadata supplied by the publisher feed · Published Sep 4, 2025

Embed this episode

Ready to play

Phishing-Resistant Authentication: A Strategic Imperative for CISOs

0:00 25:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Security Strategist?

This episode is 25 minutes long.

When was this The Security Strategist episode published?

This episode was published on September 4, 2025.

Can I download this The Security Strategist episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!