For many small and mid-sized businesses, turning on MFA once felt like the finish line for identity security. SMS codes and push notifications improved protection, and many insurers treated any MFA as a milestone. That baseline has shifted. Attackers now use phishing kits that proxy login sessions in real time and exploit push fatigue to gain approvals. As a result, regulators and insurers increasingly expect phishing-resistant MFA, with FIDO2 passkeys as a core control.

By