H-ISAC Finished Report CISA TLP White: Guidance on Phishing-Resistant and Numbers Matching Multifactor Authentication

On October 31, 2022, the Cybersecurity Infrastructure Security Agency (CISA) released two fact sheets highlighting threats against accounts and systems using certain forms of multifactor authentication (MFA). CISA strongly urges all organizations to implement phishing-resistant MFA to protect against phishing and other known cyber threats. If an organization using mobile push-notification-based MFA is unable to implement phishing-resistant MFA, CISA recommends using number matching to mitigate MFA fatigue. Although number matching is not as strong as phishing-resistant MFA, it is one of the best interim mitigation for organizations that may not immediately be able to implement phishing-resistant MFA.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272