Sign in

Duo Security

@duosec.bsky.social
131 followers 5 following 282 posts

📱 | Duo.com 🔑 | Duo is now a part of @Cisco.com 💚 | Human-Centered Security Solutions

PostsRepliesMedia
Duo Security @duosec.bsky.social · 3h
People who change roles accumulate access like frequent flyer miles. When you leave a company, your access gets shut off. But when you switch teams or roles, old access often just… stays. This Cybersecurity Awareness Month, help your IT team keep your access current: cs.co/63320BG7rXq
Identity lifecycle management needs more than tools
000
Duo Security @duosec.bsky.social · 23h
Striking the right balance between UX & security is a challenge for many companies. Lean too far either way and you frustrate users or create risk. Room & Board found that balance, giving design associates secure, flexible access without slowing customers down: cs.co/63329BGfl6l
022
Duo Security @duosec.bsky.social · 06/10/2026
Spend less time logging in and more time doing. Duo Passport reduces authentication prompts by securely passing trust between applications. Log in once and work with no interruptions. Learn more 👇 cs.co/63326BGF1fI
021
Duo Security @duosec.bsky.social · 05/10/2026
Would you click it? 👀 Attackers frequently target MFA enrollment. If they trick you into registering their device, they get ongoing access to your account, even after you change your password. Spot something suspicious? Report it.
032
Duo Security @duosec.bsky.social · 02/10/2026
Since its rollout across the Cisco workforce, Duo Passport and Risk-Based Authentication (RBA) have helped cut user authentication prompts by 3.5 million per week, letting IT adjust verification requirements in real time. #FunFactFriday
Duo Passport and Risk-Based Authentication (RBA) have helped cut user authentication prompts by 3.5 million per week
010
Duo Security @duosec.bsky.social · 01/10/2026
It's Cybersecurity Awareness Month! AI didn't invent phishing. It just made the previously obvious phish look real. The clues we learned to spot are mostly gone. Defense can't rely on catching them anymore. It has to verify what the eye can't. Next week: a challenge
Happy Cybersecurity Awareness Month from Duo
020
Duo Security @duosec.bsky.social · 30/09/2026
Access policies are only as smart as the data behind them. Custom Attributes in Duo Identity Lifecycle Management take you beyond one-size-fits-all rules to context-aware access. See the 10-minute demo inside the Duo Admin Panel: cs.co/63328BGsKWI
001
Duo Security @duosec.bsky.social · 29/09/2026
It’s not often you hear someone choose to pay for a product over the free default. But when Trident Technical College evaluated its MFA options, it became clear that the built-in solution was no match for Duo. Find out why: cs.co/63324BGqSMi
Trident Technical College + Cisco Duo | Case Study
000
Duo Security @duosec.bsky.social · 28/09/2026
Security functionality should be foundational, not an expensive add-on. Duo's security-first approach tackles the toughest identity security problems and defends against advanced attacks — at no additional cost, without adding friction for admins or users. cs.co/63324BGqMBK
021
Duo Security @duosec.bsky.social · 25/09/2026
Fact or Fiction? The biggest risks in agentic AI don't require an attacker. Fact. Agents are often given too many tools, too much access, and too little oversight. Risk starts at deployment. Every agent has an identity, access, and the ability to act. Protect it from day one.
011
Duo Security @duosec.bsky.social · 24/09/2026
Australia's cybersecurity agency confirms that 42% of reported breaches trace back to compromised credentials. The agency’s guidance is direct: enable MFA everywhere, and when possible, move to phishing-resistance methods like passkeys over SMS codes. Learn more: cs.co/63322BGiwQ4
Phishing Resistance Methods like Passkeys over SMS codes
011
Duo Security @duosec.bsky.social · 22/09/2026
Somewhere in your environment right now, an AI agent is likely running without an identity, an owner, or meaningful access controls. Read why agentic AI breaks traditional identity management, and what Duo Agentic Identity does about it: cs.co/63327BGdwSf
Somewhere in your environment right now, an AI agent is likely running without an identity, an owner, or meaningful access controls.
000
Duo Security @duosec.bsky.social · 18/09/2026
There's a new Duo in town. While one Duo flips open, our Duo flips the script on identity with security-first IAM that attackers hate and users love. You know our MFA. Meet our IAM. The New Duo: Security-First IAM.
021
Duo Security @duosec.bsky.social · 17/09/2026
At the University of Wisconsin-La Crosse, ease of use mattered as much as security strategy. Students, faculty, and staff needed authentication simple enough to adopt and strong enough to meet compliance requirements. See how they did it cs.co/63326BGVMGI #HigherEd #MFA
011
Duo Security @duosec.bsky.social · 15/09/2026
Duo Federal Edition, a FedRAMP Class D (IL4) offering, is now generally available: - Phishing-resistant MFA with FIDO2, PIV/CAC - Device health check at access - Adaptive policies that support implementing NIST SP 800-171 and CMMC cs.co/63326BGrVUa
Duo Federal Edition, a FedRAMP Class D (IL4)
022
Duo Security @duosec.bsky.social · 14/09/2026
Passwords are a liability: forgotten, reused - a common target for phishing & credential stuffing. Passwordless authentication reduces friction, cuts help desk volume & speeds up access - giving teams more time for what matters. 5 passwordless benefits you shouldn’t ignore 👇
022
Duo Security @duosec.bsky.social · 10/09/2026
With the rise of Adversary-in-the-Middle (AiTM) attacks and sophisticated session hijacking, organizations need to go beyond basic MFA. In this Cisco Spotlight, Chad Skipper, Global Security Technologist, walks through Duo's end-to-end phishing resistance.
011
Duo Security @duosec.bsky.social · 09/09/2026
A phishing attack at a sister company changed everything for AmeriGas. MFA went from a handful of privileged users to 9,500 employees and contractors—company devices and BYOD alike. Here's how they pulled it off: cs.co/63321BGJbdN
011
Duo Security @duosec.bsky.social · 08/09/2026
Human-designed credentials were never built for machines that act on their own. Cisco and Teleport bring short-lived cryptographic identity to agentic infrastructure access. cs.co/63325BGHmaX
Cisco and Teleport Partnership
011
Duo Security @duosec.bsky.social · 03/09/2026
In today's fast-paced retail landscape, protecting your business, customers, & employees is more critical than ever. Identity security solutions can support your retail org from emerging cyber threats while enabling seamless access across all apps, devices, & environments. cs.co/63320B1f4uw
In today's fast-paced retail landscape, protecting your business, customers, & employees is more critical than ever. In today's fast-paced retail landscape, protecting your business, customers, & employees is more critical than ever. In today's fast-paced retail landscape, protecting your business, customers, & employees is more critical than ever.
022
Duo Security @duosec.bsky.social · 01/09/2026
There's a moment every security team hits: the tools that got you here won't get you there. For Inductive Automation, that was managing identities across AD and Duo. Consolidating into Duo Directory reduced risk and overhead with less effort than expected. Click the link below to see how 👇
There's a moment every security team hits: the tools that got you here won't get you there.
011
Duo Security @duosec.bsky.social · 31/08/2026
Top identity security gaps: - Fragmented visibility - Inconsistent enforcement - Static access decisions One login shouldn't mean trust forever. The fix? Continuous, context-aware identity security for every account and session. See how: cs.co/63320B1f4Oo
Top identity security gaps
000
Duo Security @duosec.bsky.social · 28/08/2026
Detecting a phishing-driven breach takes an average of 192 days. Containing it adds another 62. That's nearly 8.5 months where an attacker could be sitting inside your environment. The best defense isn't just resistance at login. It's resistance at every stage: cs.co/63327B1Fucb
011
Duo Security @duosec.bsky.social · 27/08/2026
A critical gap in AI agent deployment: can this agent invoke this tool, on this server, within this user's permissions? That's where enterprise agents stall. Arcade dev sends every call through Duo first, where your policies already live, and acts only on what Duo authorizes.
011
Duo Security @duosec.bsky.social · 26/08/2026
Most identity infra was built for: One building One network Manual provisioning Today's reality: Distributed teams, multiple SaaS apps, and machine identities outnumbering people. The fix: Separate auth from the apps. Here's how: cs.co/63326B1xDSk
Today's reality: Distributed teams, multiple SaaS apps, and machine identities outnumbering people.
021
Duo Security @duosec.bsky.social · 25/08/2026
Most agentic AI conversations focus on capability, not identity: who these agents are, and how they're governed. This CSO Online piece proposes a six-stage maturity model to help close that gap, and a case for tracking human and agent governance separately: cs.co/63327B1sow5
Most agentic AI conversations focus on capability, not identity: who these agents are, and how they're governed.
010
Duo Security @duosec.bsky.social · 24/08/2026
Security tools often force a tradeoff: strong protection or a smooth user experience, rarely both. Emil Blondal, CDO at an IT company, found that wasn't the case with Duo—easy enough to implement in two days, robust enough to earn a perfect score. cs.co/63320B1S46C
cs.co
CDO Gives Cisco Duo Top Rating | PeerSpot Review
#CiscoDuo #IdentitySecurity #MultiFactorAuthentication Emil Blondal, a CDO with an IT company, shares his 10-out-10 experience with Cisco Duo in this PeerSpot review. What is Emil’s favorite aspect of Duo for enabling remote access? How easy the whole experience is. “You connect it to the email address, to the phone number, and you are able to push everything to the client,” Emil says. That ease spans its maintenance and scalability. While his company briefly considered a competitor product, Emil reported that the team found Duo easier to implement, connecting it to Active Directory and deploying in just two days. Duo flips the script on identity with security-first identity and access management (IAM) that attackers hate and users love. 🔗 Learn more about why teams trust Duo, then try it free → https://cs.co/63328B1S46A #MFA #ZeroTrustAccess #IdentityManagement #Cybersecurity
010
Duo Security @duosec.bsky.social · 21/08/2026
Fact. Overprivileged agents are one of the biggest risks in agentic deployments. Duo Agentic Identity enforces least privilege at every action - evaluating each tool call before it reaches your systems. cs.co/63329B1dLoU
011
Duo Security @duosec.bsky.social · 20/08/2026
80% of breaches use Active Directory for privilege escalation and lateral movement. That's not a flaw - it's a function of AD's central role. Here's how security teams are strengthening it without ripping it out: cs.co/63323B1dLmx
80% of breaches use Active Directory for privilege escalation and lateral movement. That's not a flaw - it's a function of AD's central role
000
Duo Security @duosec.bsky.social · 19/08/2026
The UK's National Cyber Security Centre has made the call: passwords are "no longer resilient enough for the contemporary world." For teams still relying solely on passwords, it’s time to consider that passwordless is no longer an option but the next step in security. cs.co/63326B1dLw4
The UK's National Cyber Security Centre has made the call: passwords are "no longer resilient enough for the contemporary world."
011
Duo Security @duosec.bsky.social · 18/08/2026
The hardest part of scaling security isn't the technology. It's knowing when your current solution stops being enough. Bluebeam recognized that crossroad, consolidated disparate tools into Duo early, and gained full visibility into suspicious logins. See how: cs.co/63328B1dxyq
032
Duo Security @duosec.bsky.social · 17/08/2026
IAM compliance isn't just a checkbox. It's your first line of defense. Weak passwords, orphaned accounts, and excessive access quietly put businesses at risk. Learn what IAM compliance really means and how to stay secure and audit-ready: cs.co/63329B1bGuP
IAM compliance
011
Duo Security @duosec.bsky.social · 13/08/2026
We’re proud to share that Cisco Systems was named a Customers’ Choice in the 2026 Gartner Peer Insights™ Access Management Voice of the Customer. Thank you to our customers for taking the time to share your experience! cs.co/63323B1uZJZ
Cisco Systems was named a Customers’ Choice in the 2026 Gartner Peer Insights™ Access Management Voice of the Customer.
011
Duo Security @duosec.bsky.social · 12/08/2026
SMS and phone callbacks were once reliable MFA. Now SIM swapping, phishing, and message interception make them a liability. NIST recommends phishing resistant auth, & insurers are starting to require it. Duo Push, security keys, & biometrics are the shift: cs.co/63321B1OI3h
SMS and phone callbacks were once reliable MFA. Now SIM swapping, phishing, and message interception make them a liability.
000
Duo Security @duosec.bsky.social · 12/08/2026
Full article: www.itbrew.com/stories/what...
itbrew.com
What is device token phishing?
Maybe you’re trying to sign into Netflix on your Airbnb TV and you’re tired of typing your super-secure 25-character password with the remote. That’s when a device code—a six- to 12-digit password tha...
000
Duo Security @duosec.bsky.social · 11/08/2026
Would your team fall for a phishing attack that uses Microsoft's own login system against them? Device code phishing takes advantage of the built-in authentication flow which means traditional MFA isn’t enough to stop it. Full article in comments 👇
122
Duo Security @duosec.bsky.social · 10/08/2026
A successful passwordless rollout rarely starts with technology. It starts with people, roles, and risk levels. Our guide walks you through evaluating readiness, choosing the right methods, and rolling out passwordless in a way that builds trust. Learn more: cs.co/63325B1K13l
Passwordless authentication with Duo
000
Duo Security @duosec.bsky.social · 07/08/2026
The average enterprise uses 1,400 different cloud services. That's 1,400 potential login prompts, password resets, and "forgot my password" moments. Passwordless authentication doesn't just improve security, it also gives people their time back. cs.co/63327B1EmUx #FunFactFriday
011
Duo Security @duosec.bsky.social · 06/08/2026
Identiverse 2026 made it clear: identity security has moved from "access" to "actions." Governing AI agents demands delegation, real-time decisions, and infrastructure that legacy IAM wasn't built for. Forrester breaks it down: cs.co/63327B18tHZ
Identiverse 2026
130
Duo Security @duosec.bsky.social · 05/08/2026
60% of leaders lack confidence former employees' access is revoked on time. Lifecycle, not login, is the real gap. See how 28 CISOs are closing it: cs.co/63328B16S58
60% of leaders lack confidence former employees' access is revoked on time.
032
Duo Security @duosec.bsky.social · 03/08/2026
The least-privilege principle has guided access management for decades. Now it needs to evolve for agents. Autonomous systems work best when their access matches their purpose. Good agentic design isn't about restriction, it's about precision: cs.co/63323BE7R6l
033
Duo Security @duosec.bsky.social · 31/07/2026
Behind every secure login, every seamless MFA prompt, every 2 a.m. fire drill—there's a SysAdmin making sure the business never notices a thing. Today, we notice. Happy SysAdmin Day from Duo Security. We know exactly how hard you work to keep access secure and systems running.
SysAdmin Day
011
Duo Security @duosec.bsky.social · 30/07/2026
50 million rides a month means 50 million reasons to get security right. Lyft needed device visibility, strong access controls, and a path to zero trust. Here's how they consolidated MFA, MDM, and device trust without slowing anyone down: cs.co/63325BEIu2R
50 million rides a month means 50 million reasons to get security right.
022
Duo Security @duosec.bsky.social · 29/07/2026
An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data. Researchers found the weak point wasn't the model — it was overprivileged access and a lack of human oversight. cs.co/63323BEIuLV
An AI agent with access to corporate email was tricked into forwarding AWS credentials and a CRM export containing $1.28M in customer revenue data.
011
Duo Security @duosec.bsky.social · 28/07/2026
Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't? IGA manages digital identities across their full lifecycle, keeping permissions aligned with roles, policies, & compliance requirements. Learn more: cs.co/63326BEIuIQ
Your organization might have thousands of user accounts. Do you know which ones still have access to systems they shouldn't?
032
Duo Security @duosec.bsky.social · 27/07/2026
"How do I get consistent identity controls when my agent infrastructure is all over the place?" Agents operate 24/7 across diverse gateways-without unified authorization, every deployment creates a blind spot. Your policies should travel with you. Learn more: cs.co/63325BEx8e7
"How do I get consistent identity controls when my agent infrastructure is all over the place?"
000
Duo Security @duosec.bsky.social · 24/07/2026
Fact or Fiction? Zero Trust only protects your network perimeter. Fiction: Zero Trust eliminates the idea of a perimeter entirely. Every user, device, and access request is treated as potentially hostile — whether it's coming from the office, home, or a café's Wi-Fi. cs.co/63326BEcXRk
011
Duo Security @duosec.bsky.social · 23/07/2026
We often think of phishing as a problem that happens before authentication. But that's only half the story. Security that stops at the login screen isn't full coverage. It's just the beginning. Here's what protecting the full authentication journey looks like: cs.co/63329BEcXux
We often think of phishing as a problem that happens before authentication.
021
Duo Security @duosec.bsky.social · 22/07/2026
Most identity breaches don't start with a sophisticated attack. They start with an undetected gap that nobody knew existed. Episode 4 of Duo's podcast explores how Cisco Identity Intelligence closes the gaps before they become breaches. cs.co/63323BEcXPN
011
Duo Security @duosec.bsky.social · 21/07/2026
A single breach can follow a student for life. In Texas, some academic and disciplinary records are kept permanently. IDEA Public Schools rethought their security posture to match the sensitivity of the data they protect. See how: cs.co/63320BEcXGK
A single breach can follow a student for life.
011