
Why do users still get hacked? In the past, it was often because of weak passwords or the absence of multi-factor authentication (MFA), and for a long time, authentication was treated mainly as a security control that sat quietly in the background of digital systems. Today, however, the real threat lies in authentication itself, which has become ground zero for attackers.
“This shift matters because authentication now plays a much bigger role in how people trust digital systems,” noted Rodney Tan, Director, Cybersecurity Engineering Centre, Cyber Security Agency of Singapore (CSA), during his keynote at the inaugural FIDO Authenticate APAC conference in Singapore.
Whether the digital system is a government service, banking platform, enterprise application, or consumer service, authentication has effectively become the front door to the digital economy, Tan observed.
“If that front door becomes weaker, confidence in the broader digital ecosystem is affected as well,” he added.
Tan then outlined three major issues affecting authentication today: first, authentication has become the primary point of attack; second, shifting the strategy towards resilience will strengthen authentication; and third, scaling stronger authentication requires local ecosystem alignment.
Authentication as the primary point of attack
Attackers have moved beyond stealing passwords or one-time passwords (OTPs) and are now directly intercepting live sessions, hijacking authenticated tokens, and manipulating users in real time. Thanks to AI, doing this at scale has become easier, Tan said.
Phishing campaigns are becoming more convincing, more personalised, and easier to scale across different languages and regions, Tan warned.
The barrier to conducting sophisticated social engineering attacks is dropping rapidly, he added.
This creates a challenge for defenders because many authentication approaches still rely heavily on user judgement at the point of authentication.
“Did the user click the correct link? Did the user approve the correct prompt? Did the user notice subtle signs of session interception?” Tan asked.
The problem, Tan stressed, goes beyond consumers.
“Enterprises, critical sectors, and even governments are facing the same challenge. Even highly trained users can still be manipulated under the right conditions,” he pointed out.
Tan urged industry stakeholders to shift the authentication conversation away from simply adding more steps, because “more friction does not always mean more security.”
Instead, he argued that additional authentication steps can create more opportunities for users to make mistakes, while attackers continue adapting to those controls.
The shift to structural resilience
In Singapore, both the government and private sector have worked to raise the baseline security of digital access, whether for government systems or the broader ecosystem. Alongside expanding MFA adoption, the country has strengthened its national digital identity infrastructure and reduced reliance on weaker authentication mechanisms such as SMS OTPs.
With AI significantly complicating the security landscape, Tan argued that stronger authentication is no longer simply about adding more layers to existing models, but reducing structural exposure to credential theft and phishing-based attacks from the outset.

Approaches such as passkeys and device-bound credentials represent an important evolution in authentication, he said. Unlike traditional credential models that rely heavily on information users manually enter or approve, these approaches use cryptographic credentials tied to trusted devices and verified domains.
“These are origin-bound tokens that fundamentally cannot be phished or replayed,” Tan explained.
As a result, they can improve resilience against phishing, replay attacks, and adversary-in-the-middle techniques.
However, technology alone is not enough. Stronger authentication must also work operationally, particularly for large organisations operating across legacy systems, mixed device environments, different user groups, and varying levels of digital maturity.
“So while the technology direction is becoming clearer, implementation realities remain complicated. There is no single deployment model that works for every organisation immediately,” Tan said.
The transition towards phishing-resistant authentication is therefore likely to happen gradually, with sectors moving at different speeds, organisations facing different operational constraints, and user groups requiring different onboarding approaches, he noted.
“The future of authentication will need to rely less on credentials that can be phished or replayed, and more on approaches that are resilient by design,” Tan added.
Why local ecosystem alignment matters
Tan admitted that technology alone is insufficient to achieve stronger authentication. The real challenge, he said, is scaling adoption consistently across the ecosystem.
Authentication operates across multiple interconnected layers, from platforms and devices that provide the underlying capabilities, to identity and service providers that build authentication experiences for users. At the same time, operating systems, browsers, applications, and enterprise environments all need to work reliably with one another.
As a result, coordination across the ecosystem becomes increasingly important, particularly as users expect authentication to work consistently across different services and platforms.
Tan warned that if implementation approaches diverge significantly across platforms and services, organisations will face uncertainty. Users may encounter inconsistent experiences, recovery models could become fragmented, cross-platform interoperability may become more difficult, and adoption could slow.
In Asia-Pacific, different markets are operating at different stages of digital maturity, while organisations face varying regulatory environments and operational constraints. Although difficult, Tan believes aligning stakeholders across the region is not impossible.
Governments can provide strategic direction and encourage adoption, while industry is responsible for implementation and operational deployment at scale, he said. Standards bodies also play a role by improving interoperability and ecosystem consistency over time.
“None of these groups can solve the problem independently. And I think that is an important mindset shift for authentication moving forward,” Tan concluded.













