The Defense Industrial Base Has a New #1 Cybersecurity Priority: Phishing-Resistant MFA

The Department of War’s (DoW) Chief Information Officer recently published a new resource for the Defense Industrial Base (DIB) Sector, and it’s refreshingly clear and simple. “Brilliant at the Basics” isn’t a mandate or a memo; It’s a ranked list of the ten IT cybersecurity practices and ten OT cybersecurity practices DoW wants its small, mid-sized and non-traditional suppliers to get right, in the order that matters most.

Ten items in, there’s one detail that stands out. It’s not encryption, patching, or backups. The list contains sound advice but the #1 IT best practice, ahead of everything else on the list, is phishing-resistant multi-factor authentication (MFA). Let’s break down what this means and why it matters for the DIB Sector and those working with the U.S. government.

What is “Brilliant at the Basics”?

The DoW’s CIO built this initiative for the part of the DIB that doesn’t have a large security team on staff. The stated goal is to “help small, mid-sized, and non-traditional companies confidently secure their networks, protect sensitive DoW information, and deliver peace through technical strength.” Two downloadable lists do the work: a Top 10 for IT cybersecurity and a separate Top 10 for OT (operational technology) cybersecurity, covering everything from asset inventory to backup architecture to workforce readiness.

No compliance deadline is attached yet, but when a department names its #1 priority in writing, that’s a signal worth reading closely – especially for anyone who sells into the defense supply chain.

Why does MFA top the list?

Here’s the DoW CIO’s own guidance on IT best practice #1: “Upgrade your authentication mechanisms to require strong phishing-resistant MFA methods for user accounts. Moving away from legacy MFA methods such as SMS text messages or push notifications forms the foundation of a modern security stack.”

The message is clear: not all MFA is created equal. SMS codes and push notifications can still be phished, intercepted, or exploited through SIM-swapping, MFA fatigue, and social engineering.

DoW is drawing a clear distinction between MFA that checks a compliance box and MFA that stops modern attacks. Phishing-resistant authentication – such as hardware-backed passkeys like a YubiKey, platform passkeys based on FIDO2/WebAuthn, or PIV/CAC credentials – keeps private keys on the device, preventing credential theft through phishing.

It’s also one of the easiest security controls to deploy. FIDO passkeys are supported by all major cloud and identity providers, and FIPS-validated security keys are readily available to meet government requirements.

It’s not just an IT problem: OT gets the same message

The OT list echoes the same priority in different words. Its #1 practice is “Identity and Access Control,” requiring multi-factor authentication for sensitive systems and instructing organizations to “enforce a ‘never trust, always verify’ mindset.” For contractors running both IT and OT environments (common across manufacturing and logistics in the DIB), that’s two separate Top 10 lists agreeing on the same starting point before anything else is addressed.

What does this mean for me if I’m a DIB contractor?

This reinforces a trend we’ve seen across federal guidance – from M-22-09 for civilian agencies to the NDAA and CISA’s Cybersecurity Performance Goals 2.0: legacy MFA is no longer enough. Authentication must be phishing-resistant by design, not dependent on user vigilance. “Brilliant at the Basics” extends that same principle to the Defense Industrial Base.

If you’re a small or mid-sized DIB contractor, here are four practical next steps:

  • Assess your current MFA. SMS codes and push notifications are now considered legacy under this guidance.
  • Adopt phishing-resistant authentication. FIDO2/WebAuthn security keys and PIV/CAC credentials meet DoW’s recommended standard.
  • Secure IT and OT separately. Operational technology requires its own identity and access controls, not just protection through the corporate IT environment.
  • Act before it’s mandated. While this guidance doesn’t set a deadline, previous federal recommendations have evolved into requirements. YubiKey FIPS Series security keys support both DoD PKI certificates and passkeys, helping contractors strengthen security today and prepare for future compliance.

Getting the basics right, brilliantly

DoW picked an apt name for this initiative; The basics aren’t glamorous, but getting them right – starting with the credential that decides who gets in – is what actually keeps a network defensible. When the department writing the list ranks phishing-resistant authentication above everything else, that’s not a suggestion to note for later; It’s the foundation the rest of the list is built on.

For more on moving your organization to phishing-resistant authentication that satisfies federal and DIB guidance out of the box, see here.

Talk to our team

Share this article: