When you picture the future of cybersecurity, you might imagine layers of sophisticated digital defences. I’m sure complex algorithms, real-time threat detection and AI-driven firewalls spring to mind. But what if I told you that the future of cybersecurity is far more likely to lie in locks and keys, rather than lines of code?
Despite billions of pounds being invested in the latest tech, one factor continues to undermine even the strongest systems; people. It’s no secret that human error is the number one cybersecurity risk, in fact 95% of all data breaches are caused by human error. And as cyberattacks become more sophisticated in the age of AI, the margin for error only widens.
Phishing remains the most effective entry point for attackers exploiting human trust rather than technical flaws. As a result, businesses are going back to basics, returning to a more tangible form of defence that takes human error out the equation entirely; phishing resistant authentication.
Why traditional MFA isn’t enough on its own
Multi-factor authentication (MFA) has long been a cornerstone of cybersecurity practice. It raises the security baseline and adds an extra layer of protection beyond passwords. But traditional MFA methods like SMS codes or push notifications are susceptible to being socially engineered. After all, attackers don’t need to hack a system when they can simply trick a person.
Beyond trickery though, practical barriers still remain. For some industries, MFA can create more obstacles than remove them. Take hotel chains for instance, receptions often used shared PCs which can make authentication tricky and drawn out. Cleanroom environments where mobile devices are banned is another example, making the process time-consuming and unproductive.
User training is obviously a good solution to that problem – especially as phishing attempts become more sophisticated. It helps people recognise fraudulent emails, spot red flags and maintain strong password hygiene. More than that though, it helps them understand just how easy it is for credentials to be compromised.
Practical exercises, like cyber-attack simulations, can help people visualise and experience these risks in controlled environments. For instance, during Kick ICT’s annual tech event, a cyber-attack simulation was used to demonstrate how quickly and easily an attack can unfold and how effective early recognition can be in limiting its impact.
But while training is important, keeping that knowledge current is an uphill battle. As deception techniques evolve at speed, human error remains one of the biggest risks.
That’s why phishing resistant MFA has become essential. While it’s not a silver-bullet, it’s currently the most effective defence against phishing attacks. Using password-less tools like FIDO2 security keys, biometric checks or blue-tooth based proximity authentication requires proof of presence.
In other words, they bring the concept of a ‘lock and key’ back to the digital world. That’s something attackers can’t replicate, regardless of how sophisticated their tools get.
By requiring users to physically prove their identity, it dramatically reduces the risk of compromise – even if credentials are stolen. With proof of presence, attackers can’t simply send a convincing email; they would need to physically possess the key or device, which raises the bar for entry exponentially.
How to get there without breaking the bank
While this new generation of MFA might sound complex or costly, the reality is far more manageable. Most organisations don’t need to rip and replace their entire security stack. In fact, many of the basic MFA capabilities are already built into everyday tools like Google or online banking.
And while that is the baseline, stronger protection can be built in gradually. Incremental upgrades focusing on high-risk areas first can deliver meaningful improvements without breaking budgets.
Start with your most exposed systems, such as shared workstations, remote access points or high-privilege accounts, and expand from there. After all, doing something is better than doing nothing.
Recommended reading
- One in Three UK SMEs Dismiss Cyber Insurance Despite High Risk
- Report: Cyber Breaches Are Tanking Share Prices
- Cyber-crime Costs to Hit $1.2tn in 2025, New Report Warns
Phishing-resistant MFA can also work alongside existing controls, allowing businesses to evolve their defences step by step. Each addition strengthens resilience, proving that modern security doesn’t always mean more complexity, sometimes the simplest form of protection – like a key in the right hands – is the strongest.
However, as attackers continue to innovate, organisations must evolve in kind. Phishing-resistant MFA represents the next iteration of security, but the story doesn’t end there. Organisations will need to be flexible, constantly integrating emerging tools and adapting to new methods of attack.
But by starting small and investing where it matters most, businesses can build lasting resilience. In doing so, cybersecurity’s future may feel surprisingly familiar: less about invisible code and more about tangible, physical keys to keep the doors locked tight.





