BANKING AUTHENTICATION SECURITY
Phishing-Resistant MFA for Banking: Protect Critical Access with FIDO2 Security Keys
SMS OTPs and authenticator codes can still be stolen through real-time phishing, SIM swaps, and adversary-in-the-middle attacks. FIDO2 security keys deliver authentication that is phishing-resistant by design — aligned with the risk-based IT governance approach of POJK 11/2022.
Phishing attacks against Indonesia's financial sector have grown far more sophisticated. Attackers no longer rely on crude fake emails; they deploy modern phishing kits that replicate login pages pixel-perfectly and relay the victim's credentials and OTP codes to the real system in real time. In these adversary-in-the-middle (AiTM) schemes, code-based MFA — SMS OTP, email codes, even authenticator apps — can be bypassed because the code the victim types is used by the attacker before it expires. This is why phishing-resistant MFA for banking matters: authentication that stays secure even when the user is deceived.
POJK No. 11/POJK.03/2022 on Information Technology Implementation by Commercial Banks places responsibility for IT risk management — including cybersecurity and access controls — on the bank, using a risk-based approach. The regulation does not mandate any single authentication technology; banks are expected to select controls proportional to their risk profile. For high-risk access — system administrators, treasury officers, staff with customer-data access, privileged core banking accounts — authentication controls that are demonstrably phishing-resistant are far easier to defend before auditors and regulators.
The FIDO2/WebAuthn standard, implemented in hardware security keys such as YubiKey, uses public-key cryptography bound to the service's domain (origin binding). Credentials never leave the device, there is no code to retype on a fake site, and no shared secret to leak from a server. NIST SP 800-63B classifies such authenticators as phishing-resistant — a level of assurance SMS-based OTP cannot reach. This page explains why that difference matters for your bank, and how to roll it out in phases without disrupting operations.
Why Code-Based MFA Is No Longer Enough for Banking
Real-time phishing defeats OTP
Modern AiTM kits relay the victim's credentials and OTP codes to the genuine system within seconds. A one-time code remains valid in the attacker's hands for as long as its time window lasts.
SIM swaps and SMS interception
SMS OTP depends on cellular networks outside the bank's control. Number takeover via SIM swap or SS7-path interception makes the channel fragile — NIST SP 800-63B itself classifies OTP over PSTN/SMS as a restricted authenticator.
Privileged accounts are the prime target
A single compromised core banking administrator or customer-data account can cause far more damage than thousands of ordinary ones. Authentication for this access should be the strongest available, not identical to what regular users get.
The burden of proof in audits and incidents
When an incident occurs, a bank must show that its access controls were proportional to the risk under the POJK 11/2022 framework. MFA that is known to be phishable is increasingly hard to defend as an adequate control for critical systems.
FIDO2 Security Keys: Phishing-Resistant by Design
Origin binding — the key only answers the real domain
FIDO2 credentials are cryptographically bound to the domain that registered them. On a phishing site with a different domain, authentication simply will not proceed — there is nothing a deceived user can hand over that an attacker can reuse.
No shared secrets on the server
The server stores only a public key; the private key never leaves the hardware. A database breach yields no reusable credentials, unlike OTP seeds or passwords.
Proof of physical user presence
Every authentication requires a physical touch on the key, so malware on the workstation cannot silently trigger logins. Combined with a PIN, it provides possession and knowledge factors at once.
One key for many systems — including smart card/PIV
Beyond FIDO2/WebAuthn, YubiKey supports PIV (smart card), OpenPGP, and legacy OTP, so a single device can secure Windows/AD login, VPN, IAM platforms (Entra ID, Okta, and others), and SSH. Migration can proceed in stages without replacing every system at once.
FIPS variants for higher-assurance requirements
For environments requiring validated cryptographic modules, the YubiKey FIPS Series is validated to FIPS 140-2/140-3. This simplifies control justification for systems with the highest risk classification.
DTI has supported financial institutions and other regulated organizations in Indonesia through hardware security key procurement and implementation, from pilot to organization-wide rollout.
Phased Rollout: From Risk Assessment to Full Scale
Risk assessment and access mapping
Working with your team, DTI maps systems and roles by risk level under the POJK 11/2022 IT risk framework: privileged accounts, core banking access, treasury, down to branch users. The output is a prioritized list of who needs phishing-resistant MFA first.
Integration testing on your identity stack
Security keys are tested against the directory and IAM you already run — Active Directory, Entra ID, Okta, or other SAML/OIDC identity providers — including smart card/PIV scenarios for workstation login. This validates compatibility without touching production.
Pilot with high-risk groups
Rollout begins with IT administrators and privileged users: a small population with the largest security impact. Operational procedures are established here — key enrollment, backup keys, loss handling, and access revocation for departing employees.
Gradual expansion and reporting
Once the pilot is stable, coverage expands group by group on a realistic timeline. DTI helps document policies and implementation evidence so the control is ready to present in internal audits and regulatory examinations.
Frequently Asked Questions
Does POJK 11/2022 require banks to use FIDO2 security keys?
No. POJK 11/2022 takes a risk-based approach: banks must manage IT risk and apply safeguards proportional to it, without mandating specific technologies. FIDO2 security keys are one of the strongest ways to meet that expectation for high-risk access — an option, not a regulatory obligation.
What makes FIDO2 more phishing-resistant than SMS OTP or authenticator apps?
An OTP code can be retyped on a fake site and relayed by the attacker to the real one in real time. FIDO2 credentials are bound to the genuine domain and never produce a stealable code, so phishing and adversary-in-the-middle schemes obtain nothing they can reuse.
What happens if an employee loses their security key?
Standard practice is enrolling at least two keys per user — one primary, one backup kept securely. A lost key is simply revoked in the identity system and becomes immediately unusable, and a controlled recovery procedure is part of the policy set we help draft during implementation.
Can security keys integrate with the systems our bank already runs?
Generally yes. FIDO2/WebAuthn is natively supported by modern browsers and major identity platforms such as Entra ID, Okta, and SAML/OIDC-based IdPs, while PIV/smart card mode covers Windows and Active Directory login. Internal applications without WebAuthn support are typically bridged through the IdP with no application changes.
Where should rollout start to avoid disrupting operations?
Start with the small population carrying the greatest risk: system administrators, core banking access, and other privileged accounts. This phased approach delivers maximum security impact from day one and gives you time to mature procedures before expanding to branches and general users.
When should a bank consider the YubiKey FIPS variant?
The FIPS Series is relevant when internal policy, contracts, or system classification require cryptographic modules validated to FIPS 140-2/140-3. For most banking use cases, the standard YubiKey 5 Series provides the same phishing resistance; the difference lies in the formal validation of the cryptographic module.
BANKING AUTHENTICATION SECURITY
Discuss a Phishing-Resistant MFA Roadmap for Your Bank
DTI's team is ready to help with access risk assessment, integration testing, procurement, and phased security key rollout. Contact us for a no-cost consultation and demo.
