HomeCloud ComputingEmbracing a Passwordless Future: Cisco's Journey to Seamless Authentication with Duo Passwordless

Embracing a Passwordless Future: Cisco’s Journey to Seamless Authentication with Duo Passwordless


ndly approach that may enable its 130,000 customers to securely work wherever, from any machine, with out friction. By leveraging its personal Duo Passwordless, the group was capable of eradicate phishable multi-factor authentication components, enhance usability and productiveness, scale back authentication actions by 93%, and safe its workforce from wherever. 

At Cisco, securing our office for the long run means constantly adapting to technological developments and staying forward of the menace panorama. Leveraging our personal suite of safety merchandise, together with Duo, has been key in serving to us try this.  

When most of our workforce labored remotely throughout the pandemic, we applied Duo Past and moved from a conventional network-based perimeter and VPN mannequin to a zero-trust framework in order that customers might securely work wherever, from any machine, with out friction. 

In the present day, our zero-trust journey continues as we try to fulfill the safety wants of right this moment whereas adapting for what’s subsequent with Duo Passwordless. Identification is now the perimeter— the primary line of protection towards cyber threats. With most knowledge breaches coming from weak or stolen credentials, it’s clear that the long run requires passwordless authentication. 

The issue with passwords

To place it merely, passwords are a simple goal for hackers. As soon as the gold normal for shielding delicate info, passwords are actually outdated and susceptible within the ever-evolving menace panorama. They’re extremely vulnerable to phishing assaults, may be simply forgotten, and infrequently result in consumer frustration that brings an inflow of password-related assist desk tickets to IT groups.  

When tormented by password fatigue, customers are inclined to make use of weak, reused, or solely barely modified passwords throughout totally different accounts. Good password administration is difficult and tough to implement, and previous to utilizing Duo Passwordless, Cisco IT struggled to handle these challenges throughout an enormous workforce spanning greater than 130,000 customers.  

As a big firm and a pacesetter in know-how, a compromise in our safety can have a significant influence on our enterprise and our innovation. If attackers receive delicate info resembling supply code, inside system particulars, buyer knowledge, or mental property, it not solely places our enterprise and staff in danger, however the prospects who depend on our know-how. We would have liked to adapt our method to authentication to mitigate the password associated safety dangers to our enterprise and challenges confronted by our staff and assist groups.

Conventional multi-factor authentication (MFA) is now not enough

Authentication has advanced as cybercrime has turn out to be increasingly more refined. We began with “one thing you understand,” or a username and password. We added MFA, which mixes “one thing you understand” with “one thing you could have” or “are” like a tool or fingerprint. Whereas stronger than a username and password alone, the “one thing you understand” issue of a password remained vulnerable to vulnerabilities.  

The transfer to passwordless: specializing in safety and consumer expertise

We started working carefully with the Duo product group to take a user-friendly, zero belief method that not solely enhanced safety but additionally improved the consumer expertise. To do that, we applied Duo Passwordless. It wasn’t nearly bettering safety, however on the identical time cultivating a seamless expertise that may higher serve our prospects and staff each now and into the long run.

While Duo Passwordless continues to be MFA, it takes it a step additional and combines the expertise into one step, making for a smoother consumer expertise. It depends on cryptographic public-private key pairs, using biometrics (resembling fingerprint or facial recognition) or safety keys like YubiKeys to authenticate customers with out the necessity for passwords.

Enhancing Duo as buyer zero

As “buyer zero” for Duo Passwordless, we had the power to check and enhance the know-how by early pilot packages earlier than launch. Utilizing a multi-phased method, we began with a small group of IT and safety workers, bettering efficiency and performance by suggestions earlier than regularly increasing to the complete workforce over 10 months. The information gained from preliminary pilot teams and insights into how totally different customers can be impacted helped form our method to speaking the modifications with our workforce. 

By cautious collaboration between groups throughout our group, Cisco IT Safety and the Safety and Belief Group (S&TO) started driving the route of our passwordless future. My group inside IT Safety served as the principle drivers behind this effort, with S&TO offering change administration assist, and IT UX, IT Comms, and IT Analysis & Analytics supporting as wanted. Assist@Cisco additionally performed a job as soon as we shifted to necessary passwordless just for key apps, managing the assist course of for our inside customers so service groups might deal with the operation and enchancment of the product.  

Challenges and classes discovered

Whereas the complete rollout has seen excessive ranges of natural workforce enrollment with restricted promotion, there have been some challenges with adoption. Many customers reported preliminary considerations with using biometrics. For instance, Home windows Hi there customers who didn’t log in with biometrics by default, merely didn’t know to set it up. Until particularly instructed, customers on this scenario didn’t notice biometrics have been an choice for them.  

To treatment, we centered on worker schooling round how biometrics are used, the place they’re saved, in addition to the worth of shifting to passwordless authentication. As well as, we supplied options to biometrics. For instance, on Home windows, customers can use a PIN. In the event that they don’t like platform-based authenticators, they’ll use a YubiKey with a PIN or setup a passkey on a cellular machine. 

Additionally necessary to notice, we didn’t initially mandate the transfer to passwordless. Our method to encouraging worker adoption and alter was formed by our dedication to delivering one of the best consumer expertise. We wished to ship companies and know-how that acted as a magnet for adoption relatively than a mandate.  

Now that we’re additional into our journey, we now have began Passwordless Solely enforcement on sure apps. The slower, however at-will transition allowed natural adoption and helped get individuals snug with the brand new know-how prior to creating the apply necessary. 

 The influence: A safer and productive workforce

Because the passwordless resolution was made obtainable to the whole workforce, we’ve seen substantial advantages together with:  

  • Zero password-related safety incidents 
  • A frictionless expertise for over 130,000 staff with zero belief safe entry 
  • Improved usability and productiveness, lowering authentication actions by 93% 
  • Enhanced safety by eliminating phishable MFA components 
  • Substantial discount in IT time and prices resulting from fewer password-related points

The longer term: Continued innovation and growth

Whereas there’s a lengthy highway forward of a full business shift away from passwords fully, this has primarily been about altering the expertise for our workforce right this moment and mitigating potential future threats for our enterprise. Getting ready for a very passwordless future is a journey that we proceed to construct and enhance on, together with: 

  •  Bettering safety and usefulness for our workforce: Our journey started with our implementation of Duo Past and continues with Duo Passwordless, underpinning our present transition to Cisco Safe Entry inside Cisco IT (extra to return!). Identification safety is a basis for zero belief entry, and Duo is rather more than simply MFA.  
  • Strengthening and evolving our zero-trust structure: The profitable rollouts of our Duo options mixed with the newest rollout of Cisco Safe Entry unlocks even stronger zero belief outcomes with an identify-first SSE.  

Be taught extra about Duo Passwordless Authentication, our journey, and the highly effective mixture of Cisco Safe Entry and Duo. For Cisco staff, learn to arrange passwordless in your Cisco machine right here.

 

 

Further Sources:

 

PS:  Attending Cisco Reside in San Diego this June? 

You’ll have a particular alternative to speak dwell with Cisco IT consultants to dive into these success tales and different deployments! Look for Cisco on Cisco in every of the showcases and be sure you search Cisco on Cisco within the session catalog to add our periods to your schedule!

Share:

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments