CASE STUDIES · Banking / Financial Services
Phishing-resistant MFA for privileged banking access
A bank hardened privileged-access authentication with YubiKey — a phishing-resistant physical key — within its POJK 11/2022 risk-management framework, without hurting productivity.
Industry
Banking / Financial Services
Client
A bank in Indonesia (anonymized)
DTI Product
YubiKey — hardware security key (FIDO2 / FIPS / U2F)
Challenge
The bank faced rising phishing and account-takeover attacks targeting employee and administrator access to critical systems. SMS OTP remained vulnerable to real-time phishing and SIM-swap. Within its POJK 11/2022 risk-management framework, the bank needed stronger authentication for privileged access without hurting productivity.
Solution
- FIDO2 / WebAuthn for phishing-resistant login on admin and core-system access.
- Privileged-access protection — a physical key that cannot be remotely phished.
- Integration with the SSO/identity provider (e.g., Microsoft Entra ID), rolled out in phases starting with the highest-risk user groups.
- A risk-based approach: security keys on the most critical access, aligned with the spirit of POJK 11/2022 — not a claim that other methods are prohibited.
Results
- Removed SMS-OTP dependency for the most critical access.
- Closed the real-time phishing & SIM-swap vector for priority user groups.
- Faster administrator login (a physical tap vs. wait-and-type OTP).
- Strengthened authentication risk-management posture.
Compliance Anchors
POJK 11/2022 (risk management — risk-based approach) · FIDO2 / WebAuthn · FIPS 140 · U2F
Need phishing-resistant MFA for your organization's critical access? Learn about YubiKey by DTI.
NEXT STEP
Discuss your institution’s needs
The DTI team can help map use cases, integration, and compliance for your context.
