FIDO for Bank Employees: A Path for Phishing-Resistant Workforce

FIDO for Bank Employees: A Path for Phishing-Resistant Workforce

Summary: Banks have invested heavily in protecting customers from phishing — but the workforce remains the control plane, and it is still largely secured with authentication methods that can be intercepted, replayed, or socially engineered. This article makes the case for extending FIDO-based phishing-resistant MFA across the entire banking workforce, explains the passkey hierarchy that should govern deployment decisions, and outlines the practical path to get there.

The Workforce Gap in Phishing-Resistant MFA

The discussion around phishing-resistant MFA in banking often starts with the customer. That focus is warranted but incomplete.

Attackers target employees with the same level of aggression, and internal users have far greater access privileges than customers. A single compromised workforce credential can open administrative consoles, transaction approval workflows, and core system access. The authentication methods protecting those credentials, namely passwords, OTPs, and push-based MFA, are the same ones that phishing kits, adversary-in-the-middle (AitM) proxies, and push bombing are purpose-built to defeat.

The structural fix is FIDO.

By replacing shared secrets and interceptable codes with device-bound cryptographic keys, FIDO eliminates the replay and interception vectors that make legacy MFA inadequate. Authentication is bound to both the user’s device and the legitimate domain. Phishing sites cannot harvest what cannot be transmitted.

For banks still weighing when to prioritize workforce FIDO adoption, that timeline is a planning constraint, not a distant horizon.

FIDO, Zero Trust, and PAM

Workforce authentication is not an isolated security control. It is the foundation of a Zero Trust architecture.

Zero Trust requires continuous verification of every user and device; FIDO provides the cryptographically strong, device-bound authentication signal that makes that verification meaningful rather than ceremonial. Every login becomes a high-assurance assertion of identity, not a knowledge-based check that an attacker could replicate.

The integration with Privileged Access Management is equally direct. PAM governs the highest-risk operations in a bank: administrative access, transaction approvals, and core system changes. FIDO’s device binding gives PAM policy engines a trustworthy authentication signal to gate privileged session initiation, replacing weaker step-up methods like OTP without adding friction to legitimate workflows.

Choosing the Right Passkey for the Right Role

Not all passkeys offer the same level of assurance.

As Gartner® states:

“Wherever possible, migrate to inherently phishing-resistant MFA, such as public-key tokens. For workforce MFA and SCA, prefer FIDO2 tokens (e.g., WHfB or roaming authenticators with device-bound passkeys). This approach is increasingly being successfully adopted. While multidevice passkeys may not satisfy workforce MFA or SCA needs, they can add value in customer use cases as a strong alternative to passwords, and with better UX.”

– Gartner, Innovation Insight for Many Flavors of Authentication Token, By Ant Allan, James Hoover, Yemi Davies, 13 January 2025.  GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

The following table maps the three deployment options to their appropriate use cases and the delivered assurance level as described in NIST SP 800-63:

Authenticator typeHow it worksBest forAssurance level
Hardware security key (FIDO2 roaming authenticator)Cryptographic operations in a dedicated tamper-resistant element, physically isolated from the host devicePrivileged users, executives, fraud teams, high-value transaction roles,
Any worker for whom the usage of a mobile phone is not possible: mobile free area or air gapped environment, shared workstations, no company mobile phone ...
AAL3
Highest assurance, immune even to fully compromised endpoints
Mobile FIDO (device-bound passkey on smartphone)Private key stored in device secure enclave; unlocked by biometric or PINGeneral workforce, broad deployment baseline, employees equipped with company mobile phoneAAL3 High assurance, strong for standard workforce roles
Synced passkey (multidevice passkey via cloud)Credential synced across devices through the cloud ecosystemLow-assurance, non-sensitive workflows onlyAAL2
Lower assurance, not suitable for workforce MFA use cases

Even if NIST classifies both device-bound passkeys and hardware security keys at the highest assurance level, there are important distinctions between the two when it comes to selection.

The distinction between hardware keys and mobile FIDO is worth stating explicitly.

  • A mobile platform authenticator stores the private key in the device’s secure enclave, which is strong, but shares an attack surface with the operating system.
  • A dedicated FIDO2 security key performs all cryptographic operations in a tamper-resistant hardware element physically isolated from the host. For privileged users and high-value transaction roles, that isolation is the appropriate control for the risk level and not a premium option.

For workforce-wide deployment, hardware keys offer stronger security where roles handle sensitive transactions or high-value access. Mobile FIDO works for general employee authentication but carries inherent risks from device-level vulnerabilities. Organizations should use hardware keys as the baseline for privileged users, and mobile FIDO for standard workforce access only when device security posture is acceptable.

A Practical Path to Workforce-Wide Deployment

The goal is FIDO for all employees. Not the same authenticator for everyone, but phishing-resistant authentication for every role.

To reach this goal, businesses must establish clear execution priorities:

  1. Migrate to phishing-resistant MFA wherever possible
  2. Implement compensating controls where the migration is not feasible
  3. Design enrollment security and account recovery as a prerequisite.

In practice, that means starting with the highest-risk population, such as privileged users, fraud operations, and remote access roles, where the return on deployment investment is most immediate, and the risk of compromise is highest. Hardware security keys should be the standard for these roles.

Mobile FIDO then becomes the deployment vehicle for the broader workforce equipped with a company mobile phone: most employees already carry a compatible device, eliminating hardware logistics and accelerating rollout without sacrificing assurance.

For users where mobile is not an option — restricted areas where phones are prohibited, roles without a company device, shared workstations, or air-gapped environments — a hardware security key is the appropriate default. The key travels with the user and requires no dependency on a corporate mobile fleet.

The final step is integrating FIDO with existing IAM and PAM systems to enable centralized policy enforcement, consistent authentication across applications, and full visibility of authentication events. Legacy MFA methods must be deprecated through that process, not left running as permanent fallback paths that attackers will deliberately target.

Phishing Resistance Starts with the Workforce

Banks have made the customer authentication problem a strategic priority. The workforce deserves the same treatment. Employees are not a secondary consideration. They are the control plane, and the credential-based attacks that succeed against them cause damage that no customer-facing control can contain.

FIDO is the architecture to close the gap with proven technology, clear trajectory, and executable deployment. The remaining question is not whether to extend phishing-resistant MFA to the workforce; it is how quickly banks can make it the standard.

 

IAM Product Marketing Manager at Thales