Skip to main content
DTI

GOVERNMENT ACCESS SECURITY

Security Keys for Government Agencies: Phishing-Resistant MFA for Digital Public Services

Protect civil servant accounts, system administrators, and e-government applications from phishing and credential theft with FIDO2 and PIV hardware security keys. DTI guides your agency from assessment and piloting through rollout and device governance.

FIDO2 / WebAuthnFIPS 140-2 Validated (FIPS series)PIV / Smart Card — NIST SP 800-73Aligned with GR 71/2019, PR 95/2018 (SPBE) & PDP Law

Discuss your deployment

Free initial consultation — we'll map your needs, integration, and compliance.

Are you inquiring for an organization or yourself?*

✓ Official 1-year Yubico warranty — claims handled by DTI in Indonesia

Reply within 1 business day · Your data is protected (UU PDP)

Demand for security keys in government agencies is rising alongside the acceleration of public-sector digital transformation. Under Indonesia's Electronic-Based Government System (SPBE) framework established by Presidential Regulation 95/2018, ever more services, citizen data, and internal processes run on digital accounts — and every one of those accounts is now a target. National cybersecurity monitoring reports consistently place credential theft and phishing among the dominant initial attack vectors against the government sector.

The problem is that most commonly used authentication mechanisms — passwords, SMS OTP, even codes from authenticator apps — can still be stolen through fake login pages and real-time proxy (adversary-in-the-middle) attacks. Even well-trained users can be deceived by a lookalike of their agency's official portal. As long as the authentication factor is a code that can be typed or copied, it can be handed to an attacker.

Hardware security keys using the FIDO2/WebAuthn protocol close this gap by design: cryptographic credentials are bound to the legitimate service domain and never leave the device, so there is no secret to phish. This approach aligns with the direction of Indonesia's national cybersecurity policy — the reliability and security obligations for electronic systems in Government Regulation 71/2019, the protection of vital information infrastructure under Presidential Regulation 82/2022, and the data-security obligations of the Personal Data Protection Law (Law 27/2022) — and reflects international best practice for government, with NIST SP 800-63B placing hardware authenticators at the highest assurance level.

Why Conventional Authentication No Longer Suffices for Government Agencies

Phishing targets civil servant and official accounts

A fake login page imitating an HR portal, official email, or e-government application is enough to steal a password together with its OTP code. One compromised account can become the entry point into an agency's entire network.

SMS OTP and authenticator apps can still be phished

Adversary-in-the-middle attacks relay a victim's OTP to the real site in real time, so code-based MFA does not stop modern phishing. SMS OTP is additionally exposed to SIM swapping and interception.

Administrator accounts are a single point of failure

Stolen credentials for servers, citizen databases, or an agency's email tenant hand an attacker full control. Privileged accounts are often protected no better than ordinary ones.

Audit and compliance expectations keep rising

SPBE security evaluations, information-security maturity assessments, and the safeguarding obligations of GR 71/2019 and the PDP Law all demand evidence of strong access controls. Passwords and OTP are increasingly hard to defend as adequate controls for critical systems.

Hardware Security Keys: Phishing-Resistant Access Control for Government Systems

Phishing-resistant MFA built on FIDO2/WebAuthn

The private cryptographic key stays inside the device and responds only to the registered service domain, so a fake page gets nothing. There is no code an attacker can steal, copy, or relay.

PIV smart card for login and digital certificates

Support for the PIV standard (NIST SP 800-73) lets a single device handle certificate-based Windows/macOS login, signing, and encryption. Well suited to agencies that have adopted — or plan to adopt — public key infrastructure.

FIPS models for high-assurance requirements

A dedicated series is available with FIPS 140-2 validation, an internationally recognized cryptographic standard for government environments. Appropriate for systems classified as vital information infrastructure or handling classified data.

Dedicated protection for privileged and admin accounts

Enforcing security keys on domain admin, server, cloud tenant, and core-system accounts cuts off the escalation path attackers exploit most. Integrates with conditional access policies and privileged access management solutions.

Field-reliable, with no battery and no network

Security keys work without power, without cellular signal, and withstand physical conditions — dependable for regional offices, branch units, and mobile personnel. Authentication keeps working when SMS does not arrive.

We have guided this approach into production at regulated-sector organizations across Indonesia that demand high standards for access security.

How DTI Guides Implementation at Your Agency

1

Assessment and mapping of critical accounts

We map your highest-risk systems: the identity provider in use (such as Microsoft Entra ID or Google Workspace), administrator accounts, e-government applications, and the readiness of FIDO2/WebAuthn and PIV support in your environment. The result is a protection priority list and the right device model choices, including whether the FIPS series is warranted.

2

Pilot with priority user groups

Rollout begins with the highest-impact group — system administrators and holders of privileged access. We assist with device registration, authentication policy configuration in your identity provider, and standard operating procedures before expanding further.

3

Phased rollout and policy enforcement

Expansion to other units proceeds in stages, with staff awareness materials, phishing-resistant MFA enforcement policies per risk group, and controlled fallback mechanisms during the transition so services are not disrupted.

4

Device lifecycle governance

We help establish procedures for issuance, backup keys, replacement upon loss, revocation on transfer or retirement, and reporting for internal audit and SPBE security evaluations. Security endures because governance keeps running — not merely because the devices exist.

Frequently Asked Questions

How is a security key different from SMS OTP or an authenticator app?

An OTP is a code that can be read and typed, which means it can be phished on a fake page and relayed to the real site in real time. A security key performs cryptographic authentication bound to the service's legitimate domain — on a fake page, the key simply will not respond. This is why standards such as NIST SP 800-63B classify it as a phishing-resistant authenticator.

Are government agencies required to use security keys?

No Indonesian regulation explicitly mandates a specific device. However, GR 71/2019 requires electronic system operators to keep their systems reliable and secure, Presidential Regulation 82/2022 requires protection of vital information infrastructure, and the PDP Law mandates technical measures to secure personal data. Security keys are one of the most measurable ways to meet those obligations at the access-control layer.

Will they work with the systems our agency already uses?

Security keys work with any service that supports FIDO2/WebAuthn — including Microsoft Entra ID/Microsoft 365, Google Workspace, and web applications implementing WebAuthn — and support PIV for certificate-based login on Windows and macOS. During the initial assessment we verify readiness across your environment and define an integration path for internal applications.

When does an agency need the FIPS models?

The FIPS series uses cryptographic modules validated to FIPS 140-2, a standard commonly required in government environments for high-assurance systems. It is worth considering for systems classified as vital information infrastructure, those handling large volumes of sensitive data, or where internal policy requires validated cryptography. For general use, the standard series with FIDO2 and PIV is usually sufficient.

What happens if an employee loses their security key?

Standard practice is for every user to have a registered backup key, so losing one device never halts work. The lost device is promptly revoked in the identity provider — and because keys are PIN-protected and store no readable data, a lost key cannot simply be used by someone else to log in. We formalize these procedures with your team during the governance phase.

Where should an agency start?

Start with the accounts that matter most: system administrators, identity provider operators, and holders of access to critical data — a small group with the largest impact. Piloting there delivers fast, demonstrable value before wider rollout. DTI can assist from assessment through procurement to day-to-day operations.

GOVERNMENT ACCESS SECURITY

Start with Your Agency's Most Critical Accounts

Discuss your agency's security key requirements with the DTI team — from priority account mapping and model selection (including the FIPS series) to a managed pilot and rollout. Contact us to begin.

Chat via WhatsApp