Data Security (Inc. Data Loss Prevention), Cyber Security, Privacy, Website Security, Email Security, Malware/Viruses, Open Source Intelligence, Cyber Security/Product Training
Most of us think of two-factor authentication (2FA), or multi-factor authentication (MFA), as a relatively recent security innovation that has become widespread over the past five years. In reality, the concept has existed for decades.

RSA introduced its well-known SecurID token in 1987, although these devices were rarely seen outside specialist environments until the early 2000s. At the time, they were used primarily to secure corporate VPN connections. The idea was simple but highly effective: a dedicated hardware device generated a code that was completely separate from the computer being used. Unless the token was physically stolen, it offered a very strong layer of security. Unlike today's authentication methods, these early devices typically lacked PIN or biometric protection.

Fast forward to 2026, and organisations have a wide range of authentication options available. These include physical devices, SMS and email-based codes, authenticator apps, push notifications, security keys, and passkeys. As adoption has increased, costs have generally fallen, making stronger authentication available to organisations of all sizes.

However, increased usage does not automatically mean better security. To understand why, it helps to consider a security triangle based on three competing factors: cost, usability, and security.

A low-cost authentication solution is often easier for employees to use and can significantly improve security compared to passwords alone. However, lower-cost options are not necessarily the most resilient against modern attacks. Conversely, the most secure solutions can be more expensive and less convenient to deploy and manage.

Let's examine the most commonly used authentication methods in 2026.

SMS One-Time Passwords (OTP)
An authentication code is sent via a standard SMS message over the mobile phone network.
Cost: Low. Although each message typically incurs a charge.
Usability: Good. Provided there is basic mobile phone coverage. A data connection is not required.
Security: Low. Vulnerable to SIM-swapping attacks, malware on mobile devices, message interception, and phishing attempts.

WhatsApp OTP
A one-time password is delivered through WhatsApp rather than SMS.
Cost: Very low. Messages can cost significantly less than SMS, sometimes as little as $0.005 per message.
Usability: Low to medium. Requires either a mobile data connection or Wi-Fi.
Security: Moderate. While WhatsApp benefits from strong encryption, risks remain from SIM-swapping, device malware, and phishing attacks. Enabling WhatsApp's PIN protection can help reduce some of these risks.

Email OTP
A one-time password is delivered via email instead of SMS or a messaging application.
Cost: Extremely low. Ranging from virtually free to a small cost per email.
Usability: Good. Assuming internet access is available on a laptop, desktop, tablet, or smartphone.
Security: Low. Vulnerable to malware, phishing attacks, email compromise, and the possibility that the authentication code is being received on the same device used for logging in.

TOTP (Time-Based One-Time Password) Applications
These are the familiar six-digit codes generated by applications such as Microsoft Authenticator, Google Authenticator, or Duo Mobile that refresh every 30 seconds.
Cost: Low. Often included at no additional cost or available for a small per-user subscription fee.
Usability: Good. Most authenticator apps continue to function without an internet connection.
Security: Moderate. More secure than SMS or email but still susceptible to malware and phishing attacks. Security may also be weakened when codes are stored within a password manager on the same device being used for authentication.

Push Notifications
After entering a username and password, the user receives a notification on their mobile device and simply approves or denies the sign-in request.
Cost: Low. Often included with Microsoft 365 or available through providers such as Duo at minimal cost.
Usability: Very good. Users generally only need to approve the request and, where configured, enter a PIN or biometric factor.
Security: Moderate. While more user-friendly than OTPs, push notifications can still be targeted by phishing attacks and compromised devices.

Security Keys
Security keys resemble USB drives but contain no storage. Instead, they are dedicated security devices, typically protected by a button press, PIN, or biometric verification.
Cost: High. Generally between £20 and £50 per key.
Usability: Relatively low. Users must carry the device with them, and compatibility issues can arise. For example, USB-A keys may require adapters for modern devices, although NFC-enabled models address some of these challenges.
Security: Excellent. Security keys are considered one of the most secure authentication methods available. They are separate from the device being used, highly resistant to phishing attacks, and protected by PINs or biometrics. Organisations are often advised to issue two or more keys per user for resilience, which increases both cost and administrative overhead.

Hardware-Bound Passkeys
A passkey is a modern credential that can be stored either in software or on dedicated hardware. In this model, the passkey is stored on a compatible security key.
Cost: High. Typically between £25 and £50 per device.
Usability: Relatively low. Similar to security keys, users must carry the device and may occasionally face compatibility challenges.
Security: Excellent. Hardware-bound passkeys provide the same advantages as security keys, including strong phishing resistance, device separation, and offline protection.

Final Thoughts
In my view, security keys and hardware-bound passkeys represent the gold standard for authentication today. Once deployed, they are straightforward to use, operate independently of the device or service being accessed, and are highly resistant to phishing and credential theft. An attacker would generally need physical possession of the device, along with any associated PIN or biometric factor, to gain access.

These solutions are also highly durable, with many devices being waterproof and crush-resistant. While they are among the most expensive options available, they provide the strongest practical level of security. For that reason, many organisations reserve them for users with elevated privileges, executive leadership, or individuals handling particularly sensitive information.
© Copyright 2012-2026 DataSecurityExpert.co.uk

Sorry, this website uses features that your browser doesn't support. Upgrade to a newer version of Firefox, Chrome, Safari, or Edge and you'll be all set.