Abstract

This paper provides a comprehensive comparison of six multi-factor authentication (MFA) methods — SMS codes, authenticator apps, hardware tokens, biometric verification, FIDO2 passkeys, and certificate-based authentication — evaluated across security strength, user experience, cost, and implementation complexity. Drawing on survey data from 55 Hong Kong enterprises, controlled phishing simulations (redacted methodology), and interviews with identity architects, we recommend a tiered approach aligned to risk rather than a single enterprise-wide MFA type.

Introduction

Credential theft remains the most common precursor to breaches observed in HKISG bulletins and member incident debriefs. Multi-factor authentication is the most widely deployed compensating control — yet organisations often implement the easiest method globally (typically SMS or app push) while leaving privileged pathways under-protected.

Hong Kong enterprises face additional constraints: mobile-centric workforces, mixed Cantonese and English UX expectations, cross-border staff accessing SaaS platforms, and procurement cycles that favour bundled identity suites over architectural clarity. This paper compares methods on dimensions that matter for local operators preparing evidence for Trust Review and board conversations.

Methods

Evaluation framework. We assessed each method against four dimensions: resistance to phishing and credential relay, user adoption rate in pilot cohorts, total cost of ownership over three years (licensing, hardware, support), and integration complexity with common identity providers and legacy applications.

Survey. Fifty-five Hong Kong enterprises across professional services, logistics, retail, and technology completed a structured questionnaire between November 2025 and February 2026. Questions covered current MFA coverage by account tier, helpdesk burden, and known bypass procedures.

Simulations. HKISG researchers conducted controlled phishing simulations against volunteer pilot groups (n=240 users across six organisations). Methods and results are summarised at aggregate level; individual organisation outcomes are confidential.

Interviews. Identity architects (n=15) discussed rollout sequencing, exception handling, and regulatory or client contractual MFA requirements.

Findings

Comparative results

Method Phishing Resistance User Adoption 3-Year Cost Integration
SMS Codes Low High Low Easy
Authenticator Apps Medium Medium Low Easy
Hardware Tokens High Medium High Medium
Biometric High High Medium Medium
FIDO2 Passkeys Very High Medium Medium Hard
Certificate-Based Very High Low High Hard

SMS remains prevalent but weakest under simulation

Sixty-two percent of surveyed enterprises still allow SMS as a primary or fallback factor for some user populations. Simulation summaries showed SMS OTP users succumbing to relay and social engineering at materially higher rates than FIDO2 or hardware token cohorts — consistent with global findings, but amplified where users expect banking-style SMS flows for all corporate apps.

Authenticator apps are a workable baseline — with push fatigue risk

Authenticator apps achieved moderate phishing resistance and low cost. However, push-notification approval fatigue appeared in four interviewed organisations, where users approved prompts without context during busy trading or retail periods. Number matching and geofencing policies mitigated but did not eliminate the behaviour.

FIDO2 passkeys show strongest resistance — hardest integration

FIDO2 passkeys demonstrated the strongest aggregate phishing resistance in simulations, particularly for cloud SaaS with native passkey support. Integration difficulty scored highest due to legacy applications, shared kiosk devices, and contractor access patterns common in Hong Kong SMEs.

Certificate-based MFA sees niche use

Certificate-based authentication remained limited to high-security environments and selected B2B portals. Adoption suffered where certificate lifecycle management lacked dedicated owners — leading to expired credentials becoming a availability problem rather than a security win.

Tiering beats uniformity

Enterprises that mapped MFA methods to account risk tiers (standard staff vs privileged vs third-party) reported 28% lower helpdesk volume per user than those mandating a single method globally without exceptions governance.

Recommendations

  1. Adopt a tiered MFA strategy. Use FIDO2 passkeys or hardware tokens for privileged and high-impact systems; biometric or app-based MFA for general corporate access; eliminate SMS except where no alternative exists — and document compensating controls.

  2. Govern exceptions explicitly. Maintain a register of bypass procedures with expiry dates; exceptions without review dates failed Trust Review evidence checks in member debriefs.

  3. Pilot before mandate. Run 30-day pilots measuring helpdesk tickets, lockout rates, and simulation outcomes — publish results internally before board mandates.

  4. Plan contractor and cross-border access. Hong Kong enterprises frequently rely on external staff; ensure MFA methods work without local mobile numbers where feasible.

  5. Align to HKISG rubric language. Map MFA coverage to Protective controls and Evidence quality domains in the Assessment Methodology when preparing review materials.

Limitations

Phishing simulations measure controlled scenarios, not nation-state capability or insider abuse. Cost figures depend on vendor quotes and internal labour assumptions that vary widely. Sample enterprises skew toward organisations already engaged with HKISG programmes. Biometric implementations differ by device estate; we report aggregate patterns only. This paper does not evaluate every emerging passkey vendor or hardware token model.

Hong Kong implications

Hong Kong enterprises must balance MFA strength with PDPO-conscious handling of biometric data, mobile numbers used for SMS, and logging of authentication events accessed from mainland or overseas locations. Client contracts in finance and legal services increasingly specify phishing-resistant MFA for privileged access — creating commercial pressure beyond baseline compliance.

HKISG recommends pairing this paper with the FIDO2 Passkeys glossary entry, Security Bulletins on credential stuffing campaigns, and Incident Response Basics when MFA bypass is suspected.

For sector-wide active exploitation, coordinate with HKCERT in parallel with internal identity team response.

Hong Kong operator checklist

  1. Confirm whether the systems, vendors, or practices described apply to your estate.
  2. Assign an owner and a review date — do not leave findings as unread newsletter content.
  3. Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
  4. Brief leadership with a dated one-page note when residual risk remains high.

What “good” looks like

  • Controls are operated, not only documented
  • Privileged access uses phishing-resistant MFA where feasible
  • Detection and response paths are exercised at least annually
  • Third-party dependencies have an owner and an exit plan

Sources and further reading

Editorial note

This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.

Frequently asked questions

Who should read this?

Identity architects, IT managers, and CISOs in Hong Kong enterprises planning MFA rollout or preparing for Trust Review evidence on Protective controls.

Does this change any public HKISG rating?

No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.

How often is this content reviewed?

HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.