Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
HISTORICAL ARCHIVE · Originally published August 19, 2021
Archive

Multi-factor Authentication in Government Sector

Why government identity programmes are adopting multi-factor authentication, how MFA holds up against phishing and credential theft, and where hardware-rooted authenticators sit in the stack.

This is an earlier piece from the AmbiSecure engineering archive. Where the field has moved on, the link above points to current coverage of the same topic.

State and local government entities — city councils, agencies, public utilities — remain disproportionately attractive targets for credential-based attacks. Multi-factor authentication is the most-discussed mitigation, but the implementation choices decide whether MFA actually changes the threat model or just adds friction.

Why Government Sectors are being targeted?

The amount of information stored by government agencies is immense. Most of it is classified data concerning their citizens. Massive disruption can occur if this data is compromised. Government sector employees are working constantly round the clock and can fall prey to phishing. Cybersecurity readiness is still lacking in most government sectors.

It is surprising that even with a significant rise of cyberattacks in the government sector, many officials are still hesitant in implementing cybersecurity measures.

Defining Cyber Threats

Cyber attackers rely on phishing and ransomware — old methods that remain effective. An overworked employee is likely to cause an error, and threats actors are always ready to abuse those errors. One simple error of logging into an illegitimate phishing website can result in huge financial losses.

Government sectors face MFA-resistant phishing attacks. Threat actors have managed to dodge SMS- and OTP-based MFA, which can now be intercepted.

Cyberattacks extend to election meddling and manipulation. Foreign governments have been accused of prying into election campaigns to create fear, uncertainty, and doubt.

Improve Cybersecurity Readiness

Minimizing the Attack Surface

With remote work, minimizing the attack surface is harder. Many government organizations are shifting toward zero-trust architecture. A "no trust always verifies" policy can significantly reduce the attack surface.

Training

Training is essential. Cyber awareness programs should teach staff about phishing, ransomware, MITM attacks, and malware. A strong email filtering system also helps.

Strong MFA Solution

Government organizations should implement strong MFA — biometrics that cannot be easily compromised, plus hardware security keys and cards. Such mechanisms can prevent cyberattacks in the government sector.

Improve Government Security with AmbiSecure

FIDO2 simplifies and secures user authentication using public-key cryptography. The OnePass USB Key and OnePass Card offer hardware-based authentication that defends against phishing attacks and reduces account-takeover risk. AmbiSecure helps organizations accelerate to a password-less future. The key/card requires no battery or network connectivity.

About Ambimat Electronics

Close to 4 decades of design experience. Solutions include AmbiPay, AmbiPower, AmbiCon, AmbiSecure, AmbiSense, AmbiAutomation across smartwatches, smart homes, medical, robotics, retail, security.

Frequently asked questions

Why are government bodies disproportionately targeted?

The volume of information they hold is immense, and state and local entities — councils, agencies, public utilities — are attractive targets for credential-based attacks.

What is the phishing-resistant MFA baseline for government today?

OMB M-22-09 and NIST SP 800-63-4 have made phishing-resistant MFA the federal baseline. PIV remains in place and FIDO2 is accepted alongside it.

What form factors are available for embedded government identity?

Embedded secure-element PIV applets ship in nano-card and MFF2 form factors for OEM and embedded identity programmes, in addition to conventional cards.

What makes government data such a concentrated target?

The volume and sensitivity of what agencies hold. A single credential can reach citizen records, benefits systems or infrastructure controls, so the return on one stolen login is disproportionately high.

Does adopting FIDO2 mean replacing an existing PIV programme?

No. PIV remains in place and FIDO2 is accepted alongside it, which lets agencies add phishing-resistant authentication on surfaces PIV never covered without retiring the credential estate they already run.

Browse more historical AmbiSecure writing.

The full archive lists everything we have published, with the modern-equivalent counterpart linked wherever one exists.

Open archive