PUBLIC SECTOR & SOE ACCESS SECURITY
Phishing-Resistant MFA for Government Agencies and State-Owned Enterprises
Employee credentials are attackers' favorite way into government and state-owned enterprise systems. DTI helps you deploy phishing-resistant MFA built on YubiKey hardware security keys—from privileged accounts to the entire organization—with a realistic, phased rollout plan.
For Indonesian government agencies and state-owned enterprises (SOEs), MFA is no longer a discussion topic but a direct consequence of the threat landscape. These organizations operate strategic systems—digital public services, financial platforms, population data, and vital information infrastructure—that make them high-value targets. Incidents affecting Indonesia's public sector in recent years show a recurring pattern: the initial foothold is rarely a sophisticated technical exploit, but an employee credential stolen through phishing.
Indonesia's regulatory framework already demands serious safeguards. Government Regulation (PP) 71/2019 on Electronic Systems and Transactions obliges electronic system operators to keep their systems secure and reliable. Presidential Regulation 82/2022 governs the protection of Vital Information Infrastructure, while Law No. 27 of 2022 on Personal Data Protection requires technical measures to prevent unauthorized access to personal data. BSSN, Indonesia's national cyber and crypto agency, consistently emphasizes access control and strong authentication in its guidance for government cybersecurity and the electronic-based government system (SPBE, Presidential Regulation 95/2018).
The problem is that not all MFA is equal. SMS one-time codes and authenticator-app codes can still be stolen in real time through proxy phishing pages—a technique now available to attackers as an off-the-shelf service. International standards such as NIST SP 800-63B place phishing-resistant hardware authenticators at the highest assurance level (AAL3). This page explains how agencies and SOEs can move to phishing-resistant FIDO2 MFA with YubiKey: the problems it solves, how it works, and how to plan a phased rollout that does not disrupt operations.
Why Conventional MFA Falls Short for Strategic Systems
SMS OTP and authenticator apps can be phished
One-time codes can be harvested in real time by adversary-in-the-middle phishing sites, letting attackers in even with MFA enabled. Any factor a user can type can be tricked out of them.
Privileged accounts are a single point of failure
One compromised administrator, treasury, or system-operator credential can expose data and services with broad public impact. Yet these accounts are often protected no better than ordinary staff accounts.
Shared credentials and weak password practices persist
In large organizations, shared accounts, reused passwords, and undisciplined rotation are hard to eliminate through written policy alone. Without a hardware factor, compliance depends entirely on individual behavior.
Compliance obligations without an implementation roadmap
PP 71/2019, the Personal Data Protection Law, and BSSN security guidance demand accountable access controls, but many organizations lack a concrete path to phishing-resistant authentication. Audits surface the same gaps year after year.
Phishing-Resistant MFA with YubiKey: DTI's End-to-End Approach
FIDO2/WebAuthn authentication bound to the genuine domain
FIDO2 public-key cryptography ensures the security key only responds to the legitimate service domain, so a look-alike phishing page gets nothing. There is no code to type, share, or steal.
One key for many systems and protocols
YubiKey supports FIDO2/WebAuthn, FIDO U2F, smart card (PIV), and OTP in a single device, securing modern cloud applications alongside older internal systems. Employees carry one tool, not several.
No battery, no network, field-ready
Security keys work without batteries or cellular connectivity—relevant for branch offices, operational units, and low-signal locations. USB-A, USB-C, and NFC form factors match the devices you already have.
FIPS-certified variants for high-assurance needs
For systems with the strictest assurance requirements, the YubiKey FIPS series is FIPS 140-2 validated, aligning with NIST SP 800-63B AAL3. You can standardize assurance levels per system classification.
Phased rollout guided by DTI's local team
DTI supports you from system and identity-provider assessment, through a privileged-account pilot, to organization-wide expansion—complete with enrollment procedures, lost-key handling, and training. You are buying an adoption program, not just hardware.
DTI has guided this phased rollout approach at public sector and enterprise organizations in Indonesia, starting with privileged accounts before expanding to the entire workforce.
How a Phishing-Resistant MFA Rollout Works
System assessment and access-risk mapping
DTI maps your strategic systems, identity providers (Microsoft Entra ID, Google Workspace, Okta, or on-premise directories), and privileged accounts. The output is a priority classification: who must be protected first and which systems are FIDO2-ready.
Pilot with critical accounts
The rollout starts with administrators, finance officers, and operators of strategic systems—a small group where protection has the greatest impact. Enrollment, backup keys, and recovery scenarios are tested and refined at this stage.
Gradual expansion by business unit
Once the pilot is proven, adoption expands per directorate or unit on an agreed schedule, with communication materials and helpdesk support. Access policies tighten progressively: weak MFA methods are disabled after security keys are enrolled.
Operations and continuous audit readiness
DTI helps establish key-lifecycle SOPs—issuance, replacement after loss, deactivation on staff transfer—plus reporting ready for internal auditors and sector supervisors. Access security becomes a routine process, not a one-off project.
Frequently Asked Questions
Do regulations require agencies and SOEs to use hardware security keys?
No regulation explicitly mandates a specific brand or form of authenticator. However, PP 71/2019, the Personal Data Protection Law, Presidential Regulation 82/2022 on Vital Information Infrastructure, and BSSN security guidance all require adequate system security and access controls—and phishing-resistant MFA is the internationally recognized best practice (NIST SP 800-63B) for meeting them on high-risk systems.
How is a security key different from SMS OTP or an authenticator app?
An OTP is a typeable code, so it can be phished and relayed by an attacker in real time through a fake site. A FIDO2 security key performs cryptographic authentication bound to the service's genuine domain, so there is no secret to hand over to a fake site—even by an employee who has been fooled.
What happens if an employee loses their security key?
Standard practice is to enroll at least two keys per user (primary and backup) and establish an identity-verified recovery procedure. A lost key is simply revoked from the system; without its PIN and associated accounts, it cannot be misused by whoever finds it.
Can it integrate with legacy and on-premise systems?
Yes, through several paths: modern applications via FIDO2/WebAuthn at the identity provider, Windows and VPN via PIV smart card, and certain systems via device-generated OTP. DTI's initial assessment maps the integration path per system before procurement, so no hardware sits unused.
What is the rollout strategy for an organization with thousands of employees?
Start with the highest-impact group—administrators and operators of strategic systems—then expand unit by unit with a schedule, communication plan, and helpdesk support. Legacy MFA methods are disabled progressively after security keys are enrolled, so there is never an unprotected transition period or sudden operational disruption.
Does a YubiKey need a battery, a special app, or an internet connection?
No. A YubiKey is a passive, battery-free device that works over USB or NFC, with authentication handled directly by the browser or operating system through open standards. For the highest assurance requirements, FIPS 140-2 validated variants are available.
PUBLIC SECTOR & SOE ACCESS SECURITY
Plan Phishing-Resistant MFA for Your Organization
Talk to DTI about an MFA readiness assessment for your agency or state-owned enterprise—from mapping strategic systems to a phased rollout plan you can defend to auditors and sector supervisors.
