---
title: ACT Quickly to Ensure the Safety of Your Data
description: Keeping financial services organizations' data safe may seem daunting, but focusing on the application layer eliminates the majority of data breach risks.
image: https://blog.strongkey.com/hubfs/Stock%20images/business%20documents%20on%20office%20table%20with%20smart%20phone%20and%20laptop%20computer%20and%20graph%20financial%20with%20social%20network%20diagram%20and%20two%20colleagues%20discussing%20data%20in%20the%20background.jpeg
---

[![StrongKey Logo](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

INDUSTRY

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa50e587d1ab_cpu%20(1).svg) 

[Fintech Payments, card capture ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg)](https://www.strongkey.com/solutions/industry/fintech) [Enterprise Fully scalable customization ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg)](https://www.strongkey.com/solutions/industry/enterprise) [Manufacturing IIoT integration, key injection ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg)](https://www.strongkey.com/solutions/industry/manufacturing)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2d4787d1e0_check-square.svg)

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated; low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burden of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

Products

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

SOFTWARE

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa215487d1ca_activity.svg) 

[FIDO2 Passwordless Authentication Reduce password-related costs ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg)](https://www.strongkey.com/products/software/fido-strong-authentication) [Public Key Infrastructure Build new or update existing ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg)](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [Encryption & Tokenization For small and mid-sized applications ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg)](https://www.strongkey.com/products/software/tokenization-and-encryption) [Custom Solutions Work with us to find a solution ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cffdbccd1c7f01ee3fce_cicruit.svg)](https://www.strongkey.com/products/software/custom-solutions)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa92287d205_truck.svg)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Development Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy and future](https://www.strongkey.com/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) Partners and Resellers Who we do business with](https://blog.strongkey.com/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/careers)

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) 

[DEMOS ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa61e187d118_arrow-left.svg)](https://www.strongkey.com/demos)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated for low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burdens of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

INDUSTRY

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg) Fintech Payments, card capture](https://www.strongkey.com/solutions/industry/fintech) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg) Enterprise Fully scalable customization](https://www.strongkey.com/solutions/industry/enterprise) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg) Manufacturing IIoT integration, key injection](https://www.strongkey.com/solutions/industry/manufacturing)

Products

SOFTWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg) FIDO Passwordless Authentication Reduce password-related costs](https://www.strongkey.com/products/software/fido-strong-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg) Public Key Infrastructure Build new or update existing](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg) Encryption & Tokenization For enterprise applications](https://www.strongkey.com/products/software/tokenization-and-encryption)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Collaboration Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy, and future](https://www.strongkey.com/about/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/about/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/about/careers) 

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) [Demos](https://www.strongkey.com/demos)

[Arshad Noor](https://blog.strongkey.com/blog/author/arshad-noor) - Oct 25, 2018

# ACT Quickly to Ensure the Safety of Your Data

- [Tweet](https://twitter.com/share)

[FIDO](https://blog.strongkey.com/blog/tag/fido)  [Payments/E-Commerce](https://blog.strongkey.com/blog/tag/payments-e-commerce)  [Encryption/Tokenization](https://blog.strongkey.com/blog/tag/encryption-tokenization)

Keeping a financial services organization’s data safe can seem like mission impossible, but focusing on the application layer will eliminate the vast majority of data breach risks.

Within this layer, the information received, stored and processed must have the following three properties to ensure security:

- **A**uthenticity
- **C**onfidentiality, where appropriate, and
- **T**rustworthiness

This article provides best practices for banks and other financial institutions to make sure that their data meet these three criteria, also referred to as ACT.

#### What is Authentic Data?

When a power company bills a customer for [power consumption](https://www.globalbankingandfinance.com/extend-battery-life-in-portable-devices-with-new-ultra-low-iq-ldo/), the meter reading must pertain to the specific customer, originate from an authorized meter and be accurate. This makes the information authentic. When data is accepted as being “authentic,” it establishes an initial level of trust in the data. However, an initial level of trust does not necessarily make data trustworthy later, unless the proper controls are in place.

Not all devices that produce data have security components built into them to guarantee data authenticity—the cost is still too high for general-purpose computing. As a result, the world has learned to use proxies to attest to the authenticity of information. The meter-reader is trained to identify customers’ premises, read meters and record data into information systems, all of which are proxies for the data’s authenticity.

The technology used to authenticate humans to information systems is the vulnerability in such a proxy-based system. If an information system can be tricked into accepting a masquerader as the “authentic source” (which most current systems can) then assumptions that data are authentic fall apart.

#### Data Confidentiality

In addition to authenticity, confidentiality is another critical data attribute necessary to preserve stable business ecosystems. Data breaches that destroy confidentiality weaken the foundations of such ecosystems. Some of the largest and best-known financial services organizations in the world have been affected by data breaches, including [Equifax](https://www.theguardian.com/us-news/2017/sep/07/equifax-credit-breach-hack-social-security), [JPMorgan Chase](https://dealbook.nytimes.com/2014/10/02/jpmorgan-discovers-further-cyber-security-issues/?mcubz=3), [Bangladesh Central Bank through the Federal Reserve of New York](https://www.reuters.com/investigates/special-report/cyber-heist-federal/), and [Veridian Credit Union](https://www.manatt.com/Insights/Newsletters/Financial-Services-Law/2017-Year-in-Review-Data-Breaches).

The reason for most data breaches is the incorrect assumption that it is easier to stop “barbarians at the gate” rather than actually protect sensitive data in the application. Financial institutions over-invest in network-based security tools, such as firewalls, anti-virus, malware detection or intrusion prevention, rather than invest in the control mechanism that provides the highest level of data protection: [application-level encryption](https://alesa.website/2015/12/01/what-is-alesa/).

Financial services organizations that use anything other than application-level encryption have a higher probability of getting breached. Data security today requires multiple strategies to deter attackers. Short of eliminating sensitive data from a system, encrypting and decrypting data within authorized applications (combined with a hardware-backed, cryptographic key management system) provides strong data protection control. When combined with FIDO-based strong authentication, risk management becomes formidable.

#### Making Data Trustworthy

Being able to trust the data is the third key to security. However, because of how standard database management systems are designed, it is always possible for a privileged user to modify data-at-rest directly without the knowledge of the application or users who created the record.

This risk is not easily mitigated, even when controls are in place so that the database system tracks changes and stores audit logs offline that privileged users cannot access. This is because even database management systems use usernames and passwords to authenticate users and applications. The probability of an attacker using a legitimate user’s compromised password to modify information in the database is very high—creating a breakdown in data trustworthiness.

Most applications today function on the premise that information stored within their databases is accurate. Even application programmers and system administrators are constrained in protecting the integrity of data for a variety of reasons: lack of knowledge, lack of resources, lack of business imperative, etc. It is possible to implement FIDO-based strong authentication and application-level encryption but still remain vulnerable to integrity attacks on data unless additional security capabilities are designed into the system.

Developing a data security strategy to preserve trustworthiness includes implementing digital signatures for both user transactions and stored database records. Transaction digital signatures using FIDO-based protocols are one of the strongest risk mitigation protection mechanisms to ensure only authorized users are capable of modifying stored data.

Similarly, transactions stored in databases must be secured using digital signatures generated by the applications themselves; the cryptographic key performing application-level signatures must be inaccessible to any human user—privileged or otherwise. Upon reading a database record, the application must verify the signature of the retrieved record before attempting to use it. Only when the signature is verified successfully can the application be sure it is using the same data it stored previously.

#### **ACT Now**

Financial institutions are responsible to both their customers, who are entrusting them with their personal information, and to a variety of data security and privacy regulations. Defending data through strong authentication, encryption and digital signatures provides extraordinarily high levels of security because it assumes an attacker may already be within the network and/or host, and if designed correctly into the application, can still protect data from being compromised.

When designed with appropriate cryptographic key management, authenticity, confidentiality and trustworthiness (ACT) protections create formidable barriers. While they are not infallible, they are the strongest risk mitigation technologies available today. In the past, implementation was a challenge due to the cost and complexity of integrating such technologies into business applications. But with today’s new market offerings, this is no longer true.

Today’s information systems work under an enormous security burden. Attackers from the far corners of the earth are capable of compromising systems as easily as an attacker next door. The above guidelines create powerful mechanisms to protect financial information, users and investments. Following them will ensure the authenticity, confidentiality and trustworthiness of your data.

#### About the author:

Arshad Noor is the CTO of StrongKey, a Silicon Valley-based company focused on securing data through key management, strong authentication, encryption and digital signatures. He has 32 years of experience in the Information Technology sector, of which, more than 17 were devoted to architecting and building key-management infrastructures for dozens of mission-critical environments around the world, including Central Banks. He has been published in periodicals and journals, as well as authored XML-based protocols for two Technical Committees as OASIS. He is a member of the FIDO Alliance, and also a frequent speaker at forums such as RSA, ISACA, OWASP and the ISSE. He can be reached at [arshad.noor@strongkey.com](mailto:arshad.noor@strongkey.com).

**ALSO SEEN IN: [Global Banking & Finance Review](https://www.globalbankingandfinance.com/act-quickly-to-ensure-the-safety-of-your-data/)**

### ALL TOPICS

- [FIDO (45)](https://blog.strongkey.com/blog/tag/fido)
- [Culture/Influence (31)](https://blog.strongkey.com/blog/tag/culture-influence)
- [Cybersecurity ROI (29)](https://blog.strongkey.com/blog/tag/cybersecurity-roi)
- [Breaches (16)](https://blog.strongkey.com/blog/tag/breaches)
- [Encryption/Tokenization (16)](https://blog.strongkey.com/blog/tag/encryption-tokenization)
- [Payments/E-Commerce (15)](https://blog.strongkey.com/blog/tag/payments-e-commerce)
- [Disruptive Defenses (14)](https://blog.strongkey.com/blog/tag/disruptive-defenses)
- [Key Management (11)](https://blog.strongkey.com/blog/tag/key-management)
- [PSD2 (11)](https://blog.strongkey.com/blog/tag/psd2)
- [GDPR and CCPA (8)](https://blog.strongkey.com/blog/tag/gdpr-and-ccpa)
- [SCA (8)](https://blog.strongkey.com/blog/tag/sca)
- [Events (7)](https://blog.strongkey.com/blog/tag/events)
- [Employee Spotlight (6)](https://blog.strongkey.com/blog/tag/employee-spotlight)
- [Ransomware (5)](https://blog.strongkey.com/blog/tag/ransomware)
- [COVID-19 (4)](https://blog.strongkey.com/blog/tag/covid-19)
- [PCI DSS (4)](https://blog.strongkey.com/blog/tag/pci-dss)
- [Products (4)](https://blog.strongkey.com/blog/tag/products)
- [Blockchain (3)](https://blog.strongkey.com/blog/tag/blockchain)
- [Healthcare (3)](https://blog.strongkey.com/blog/tag/healthcare)
- [Hybrid Cloud (RC3) (3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)
- [IoT (3)](https://blog.strongkey.com/blog/tag/iot)
- [PKI (3)](https://blog.strongkey.com/blog/tag/pki)
- [Press Releases (2)](https://blog.strongkey.com/blog/tag/press-releases)
- [Citrix (1)](https://blog.strongkey.com/blog/tag/citrix)
- [Passkeys (1)](https://blog.strongkey.com/blog/tag/passkeys)

### Most Popular

<https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Key Management](https://blog.strongkey.com/blog/tag/key-management) [Passkeys](https://blog.strongkey.com/blog/tag/passkeys)

**[“Would you trust your bank with both keys to your ....](https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box)**

<https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)

**[An In-depth Guide to FIDO Protocols: U2F, UAF, and....](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2)**

<https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how>

[Key Management](https://blog.strongkey.com/blog/tag/key-management) [Cybersecurity ROI](https://blog.strongkey.com/blog/tag/cybersecurity-roi)

**[Key Custodians: Who, What, Where, When, Why, and H....](https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how)**

<https://blog.strongkey.com/blog/fido-101-strong-authentication>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses) [Culture/Influence](https://blog.strongkey.com/blog/tag/culture-influence)

**[FIDO 101: Understanding FIDO Strong Authentication....](https://blog.strongkey.com/blog/fido-101-strong-authentication)**

### Archive

- [March 2026 (1)](https://blog.strongkey.com/newsroom/archive/2026/03)
- [June 2025 (1)](https://blog.strongkey.com/newsroom/archive/2025/06)
- [March 2022 (1)](https://blog.strongkey.com/newsroom/archive/2022/03)
- [December 2021 (1)](https://blog.strongkey.com/newsroom/archive/2021/12)
- [March 2021 (6)](https://blog.strongkey.com/newsroom/archive/2021/03)
- [December 2020 (4)](https://blog.strongkey.com/newsroom/archive/2020/12)
- [November 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/11)
- [October 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/10)
- [September 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/09)
- [August 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/08)
- [June 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/06)
- [April 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/04)
- [February 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/02)
- [January 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/01)
- [December 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/12)
- [September 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/09)
- [August 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/08)
- [July 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/07)
- [June 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/06)
- [May 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/05)
- [April 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/04)
- [March 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/03)
- [February 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/02)
- [January 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/01)
- [December 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/12)
- [November 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/11)
- [October 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/10)
- [September 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/09)
- [August 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/08)
- [July 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/07)
- [April 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/04)
- [January 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/01)
- [October 2017 (1)](https://blog.strongkey.com/newsroom/archive/2017/10)

![Strongkey - Logo](https://blog.strongkey.com/hubfs/Strongkey%20-%20Logo.png "Strongkey - Logo")

StrongKey provides solutions to companies looking to solve for PCI DSS, PSD2 Strong Customer Authentication, passwordless authentication with FIDO, data privacy, public key infrastructure and other security challenges.

Copyright 2022 StrongKey, Inc.

- [Privacy Policy](https://www.strongkey.com/about/privacy-policy)
- [Terms of Use](https://www.strongkey.com/about/terms-of-use)
- [Cookie Policy](https://www.strongkey.com/about/cookie-policy)

#### About

- [Company](https://www.strongkey.com/about/company)
- [Newsroom](https://blog.strongkey.com/newsroom)
- [Events](https://www.strongkey.com/about/events)
- [Careers](https://www.strongkey.com/about/careers)

#### Solutions

- [PCI DSS](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services)
- [FIDO](https://www.strongkey.com/products/software/fido-strong-authentication)
- [PSD2 SCA](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication)
- [CCPA](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)
- [GDPR](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2)
- [NACHA](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection)

#### Resources

- [Library](https://blog.strongkey.com/resources)
- [CONTACT US](https://www.strongkey.com/contact)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526cad36f3a5e723525fba_GitHub_logo_white_10%25.png)](https://github.com/StrongKey) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa071787d2c3_Twitter.png)](https://twitter.com/strongkeyinc) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa775287d2c0_Linkedin.png)](https://www.linkedin.com/company/strongkey)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526bcf0df80d185f961b8d_youtube_white_icon.png)](https://www.youtube.com/channel/UCueU61oRt9G6MILRSHIfimA) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036be2bdf2d65e2d2fc906f_Instagram_5%25.png)](https://www.instagram.com/strongkeyinc/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036bd8ef3da6a4bb2e24382_facebook_10%25.png)](https://www.facebook.com/strongkeyinc/)

#### Subscribe to Our Newsletter

Receive helpful information and the latest news from the world of cybersecurity