---
title: "Capital One: Chronicle of a Data Breach Foretold"
description: The Capital One data breach provides important lessons. The steps outlined in this article can help companies become resilient to continual cyber-attacks.
image: https://blog.strongkey.com/hubfs/Capital%20One%20Breach%20Blog%20Post%20(2).png
---

[![StrongKey Logo](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

INDUSTRY

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa50e587d1ab_cpu%20(1).svg) 

[Fintech Payments, card capture ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg)](https://www.strongkey.com/solutions/industry/fintech) [Enterprise Fully scalable customization ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg)](https://www.strongkey.com/solutions/industry/enterprise) [Manufacturing IIoT integration, key injection ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg)](https://www.strongkey.com/solutions/industry/manufacturing)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2d4787d1e0_check-square.svg)

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated; low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burden of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

Products

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

SOFTWARE

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa215487d1ca_activity.svg) 

[FIDO2 Passwordless Authentication Reduce password-related costs ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg)](https://www.strongkey.com/products/software/fido-strong-authentication) [Public Key Infrastructure Build new or update existing ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg)](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [Encryption & Tokenization For small and mid-sized applications ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg)](https://www.strongkey.com/products/software/tokenization-and-encryption) [Custom Solutions Work with us to find a solution ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cffdbccd1c7f01ee3fce_cicruit.svg)](https://www.strongkey.com/products/software/custom-solutions)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa92287d205_truck.svg)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Development Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy and future](https://www.strongkey.com/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) Partners and Resellers Who we do business with](https://blog.strongkey.com/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/careers)

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) 

[DEMOS ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa61e187d118_arrow-left.svg)](https://www.strongkey.com/demos)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated for low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burdens of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

INDUSTRY

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg) Fintech Payments, card capture](https://www.strongkey.com/solutions/industry/fintech) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg) Enterprise Fully scalable customization](https://www.strongkey.com/solutions/industry/enterprise) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg) Manufacturing IIoT integration, key injection](https://www.strongkey.com/solutions/industry/manufacturing)

Products

SOFTWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg) FIDO Passwordless Authentication Reduce password-related costs](https://www.strongkey.com/products/software/fido-strong-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg) Public Key Infrastructure Build new or update existing](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg) Encryption & Tokenization For enterprise applications](https://www.strongkey.com/products/software/tokenization-and-encryption)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Collaboration Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy, and future](https://www.strongkey.com/about/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/about/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/about/careers) 

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) [Demos](https://www.strongkey.com/demos)

[Arshad Noor](https://blog.strongkey.com/blog/author/arshad-noor) - Oct 24, 2019

# Capital One: Chronicle of a Data Breach Foretold

- [Tweet](https://twitter.com/share)

[FIDO](https://blog.strongkey.com/blog/tag/fido)  [Breaches](https://blog.strongkey.com/blog/tag/breaches)  [Payments/E-Commerce](https://blog.strongkey.com/blog/tag/payments-e-commerce)  [Hybrid Cloud (RC3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)  [Key Management](https://blog.strongkey.com/blog/tag/key-management)  [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)  [Encryption/Tokenization](https://blog.strongkey.com/blog/tag/encryption-tokenization)

The “data breach of the year” involved more than 100M files containing sensitive information of consumer credit card applications at Capital One. The story hit headlines for months, and with much reason—after all, it’s not every day that the social security numbers, bank account numbers, credit scores, and plenty more other sensitive information of millions get exposed.

As 2019 comes to an end, it’s important to reflect on other companies’ successes and, in this case, failures to prevent similar catastrophes from happening again. In this article, we discuss how the Capital One breach happened, why we believe these breaches will continue, and the steps companies and public agencies can take to prevent a similar incident from occurring with your data.

#### **How Did the Capital One Breach Happen?**

The attacker was a past employee of AWS and knew the layout of the infrastructure. Realizing that a web application firewall that could have prevented access to the files was not configured, she was able to access these files and the content within them.

[Capital One was an avid user of AWS services](https://www.wsj.com/articles/how-the-accused-capital-one-hacker-stole-reams-of-data-from-the-cloud-11564911001); consequently, it would be reasonable to assume that they were using the AWS Key Management Service (KMS), a software-based encryption service, or their CloudHSM, backed by a FIPS-certified cryptographic hardware security module, to encrypt the information. Since the attacker had already reached a privileged location within the infrastructure, it also reasonable to conclude that she was able to assume either a Capital One or an AWS service account to ask the KMS and/or CloudHSM to decrypt the content for her.

#### **Will Such Breaches Continue?**

Most definitely. Here’s why:

- Use of passwords: Most of the internet, including the cloud service providers, continues to use an anachronism to determine access to protected resources: shared secrets. These are either passwords or any of the varieties of one-time PINs (OTP), knowledge-based answers (KBA), etc. All of the shared secret authentication mechanisms have been attacked and compromised over and over again, with [systems using passwords having an 81% probability of being compromised by a data breach](https://www.infoworld.com/article/3193028/annual-verizon-security-report-says-sloppiness-causes-most-data-breaches.html);
- Failing to encrypt the right way: Most companies will not encrypt sensitive data unless they are forced to do so. And, when they do, they take short cuts. [TJ Maxx](https://phys.org/news/2007-03-tjx-intruder-retailer-encryption-key.html) used database encryption with the encryption key stored in the database and protected by, you guessed it, a password. [Marriott](https://blog.strongkey.com/blog/marriott-the-500m-record-scandal-marring-the-hospitality-industry) stored encryption key components on the same machine as encrypted data. [Heartland Payment Systems](https://www.forbes.com/sites/davelewis/2015/05/31/heartland-payment-systems-suffers-data-breach/#7e2a6fb8744a) never encrypted credit card data. [Target](https://www.zdnet.com/article/anatomy-of-the-target-data-breach-missed-opportunities-and-lessons-learned/) did not separate their credit card processing systems from their refrigeration systems, allowing attackers to get to sensitive data through password-based accounts of service mechanics monitoring refrigerators. The list goes on and on…
- Most cloud users assume they are protected by their CSP, and consequently, do little to protect themselves: AWS used to have a webpage explicitly stating that users were responsible for the security and compliance efforts of their regulated applications. That page isn’t live anymore—the disclaimer is probably buried within legal clauses in their terms of service.

Any one of these causes is sufficient to result in a data breach. When one or more of these causes are present within an application system, a data breach is inevitable.

#### **How Can You Prevent a Data Breach from Ever Happening to Your Organization? **

The short answer: you can’t. Cyberthreats evolve constantly and rapidly, which means there’s no foolproof solution to all cybersecurity issues. Recognizing this, the best way to protect your organization against data breaches is to make it highly difficult for criminals to access your data in the first place. In the event a breach does happen, your best bet is to make it irrelevant. Here’s how you can do both of these things:

- Passwordless Authentication: [Use powerful protocols, such as FIDO2](https://go.strongkey.com/free-security-assessment), in web and mobile applications to enable passwordless authentication and eliminate shared secrets—a magnet for attackers.
- Targeted data encryption: Protect your data by encrypting and tokenizing it in the application layer, the highest layer of the technology stack. This means that data is protected no matter where it travels.
- Data integrity: Digital signatures protect data from being modified by “side-channel” attacks—where someone with access to the database may make unauthorized changes, bypassing rules built into the application. Businesses are assured that users are using accurate data to make business decisions.
- High-assurance key management: By using a FIPS-certified cryptographic hardware module you can ensure that all cryptographic keys being generated, stored, and used, are protected.
- Hybrid cloud security: Companies’ IT strategies generally leverage the cloud. If this is the case of your organization, find a solution that enables customers to take advantage of the benefits of the cloud, while still maintaining control of your keys in a dedicated secure zone.

Combined, these are formidable defenses designed to protect data against the vast majority of attacks. They work in concert to ensure that even if an attacker is on the network, it would be extremely difficult to compromise data and/or cryptographic keys within the solution.

The Capital One data breach provides important lessons. Keeping them in mind, the steps outlined in this article can help companies become resilient to continual attacks on the internet, finally allowing them to get **ahead** of the problem.

**ALSO SEEN IN: [Health IT Answers](https://www.healthitanswers.net/chronicle-of-a-data-breach-foretold/)**

[![Cybersecurity can be hard, we get it. Click here to request a free security assessment.](https://no-cache.hubspot.com/cta/default/4723359/36fc7565-d889-4514-b5d0-f05165a346f9.png)](https://cta-redirect.hubspot.com/cta/redirect/4723359/36fc7565-d889-4514-b5d0-f05165a346f9)

### ALL TOPICS

- [FIDO (45)](https://blog.strongkey.com/blog/tag/fido)
- [Culture/Influence (31)](https://blog.strongkey.com/blog/tag/culture-influence)
- [Cybersecurity ROI (29)](https://blog.strongkey.com/blog/tag/cybersecurity-roi)
- [Breaches (16)](https://blog.strongkey.com/blog/tag/breaches)
- [Encryption/Tokenization (16)](https://blog.strongkey.com/blog/tag/encryption-tokenization)
- [Payments/E-Commerce (15)](https://blog.strongkey.com/blog/tag/payments-e-commerce)
- [Disruptive Defenses (14)](https://blog.strongkey.com/blog/tag/disruptive-defenses)
- [Key Management (11)](https://blog.strongkey.com/blog/tag/key-management)
- [PSD2 (11)](https://blog.strongkey.com/blog/tag/psd2)
- [GDPR and CCPA (8)](https://blog.strongkey.com/blog/tag/gdpr-and-ccpa)
- [SCA (8)](https://blog.strongkey.com/blog/tag/sca)
- [Events (7)](https://blog.strongkey.com/blog/tag/events)
- [Employee Spotlight (6)](https://blog.strongkey.com/blog/tag/employee-spotlight)
- [Ransomware (5)](https://blog.strongkey.com/blog/tag/ransomware)
- [COVID-19 (4)](https://blog.strongkey.com/blog/tag/covid-19)
- [PCI DSS (4)](https://blog.strongkey.com/blog/tag/pci-dss)
- [Products (4)](https://blog.strongkey.com/blog/tag/products)
- [Blockchain (3)](https://blog.strongkey.com/blog/tag/blockchain)
- [Healthcare (3)](https://blog.strongkey.com/blog/tag/healthcare)
- [Hybrid Cloud (RC3) (3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)
- [IoT (3)](https://blog.strongkey.com/blog/tag/iot)
- [PKI (3)](https://blog.strongkey.com/blog/tag/pki)
- [Press Releases (2)](https://blog.strongkey.com/blog/tag/press-releases)
- [Citrix (1)](https://blog.strongkey.com/blog/tag/citrix)
- [Passkeys (1)](https://blog.strongkey.com/blog/tag/passkeys)

### Most Popular

<https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Key Management](https://blog.strongkey.com/blog/tag/key-management) [Passkeys](https://blog.strongkey.com/blog/tag/passkeys)

**[“Would you trust your bank with both keys to your ....](https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box)**

<https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)

**[An In-depth Guide to FIDO Protocols: U2F, UAF, and....](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2)**

<https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how>

[Key Management](https://blog.strongkey.com/blog/tag/key-management) [Cybersecurity ROI](https://blog.strongkey.com/blog/tag/cybersecurity-roi)

**[Key Custodians: Who, What, Where, When, Why, and H....](https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how)**

<https://blog.strongkey.com/blog/fido-101-strong-authentication>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses) [Culture/Influence](https://blog.strongkey.com/blog/tag/culture-influence)

**[FIDO 101: Understanding FIDO Strong Authentication....](https://blog.strongkey.com/blog/fido-101-strong-authentication)**

### Archive

- [March 2026 (1)](https://blog.strongkey.com/newsroom/archive/2026/03)
- [June 2025 (1)](https://blog.strongkey.com/newsroom/archive/2025/06)
- [March 2022 (1)](https://blog.strongkey.com/newsroom/archive/2022/03)
- [December 2021 (1)](https://blog.strongkey.com/newsroom/archive/2021/12)
- [March 2021 (6)](https://blog.strongkey.com/newsroom/archive/2021/03)
- [December 2020 (4)](https://blog.strongkey.com/newsroom/archive/2020/12)
- [November 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/11)
- [October 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/10)
- [September 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/09)
- [August 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/08)
- [June 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/06)
- [April 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/04)
- [February 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/02)
- [January 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/01)
- [December 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/12)
- [September 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/09)
- [August 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/08)
- [July 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/07)
- [June 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/06)
- [May 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/05)
- [April 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/04)
- [March 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/03)
- [February 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/02)
- [January 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/01)
- [December 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/12)
- [November 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/11)
- [October 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/10)
- [September 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/09)
- [August 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/08)
- [July 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/07)
- [April 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/04)
- [January 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/01)
- [October 2017 (1)](https://blog.strongkey.com/newsroom/archive/2017/10)

![Strongkey - Logo](https://blog.strongkey.com/hubfs/Strongkey%20-%20Logo.png "Strongkey - Logo")

StrongKey provides solutions to companies looking to solve for PCI DSS, PSD2 Strong Customer Authentication, passwordless authentication with FIDO, data privacy, public key infrastructure and other security challenges.

Copyright 2022 StrongKey, Inc.

- [Privacy Policy](https://www.strongkey.com/about/privacy-policy)
- [Terms of Use](https://www.strongkey.com/about/terms-of-use)
- [Cookie Policy](https://www.strongkey.com/about/cookie-policy)

#### About

- [Company](https://www.strongkey.com/about/company)
- [Newsroom](https://blog.strongkey.com/newsroom)
- [Events](https://www.strongkey.com/about/events)
- [Careers](https://www.strongkey.com/about/careers)

#### Solutions

- [PCI DSS](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services)
- [FIDO](https://www.strongkey.com/products/software/fido-strong-authentication)
- [PSD2 SCA](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication)
- [CCPA](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)
- [GDPR](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2)
- [NACHA](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection)

#### Resources

- [Library](https://blog.strongkey.com/resources)
- [CONTACT US](https://www.strongkey.com/contact)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526cad36f3a5e723525fba_GitHub_logo_white_10%25.png)](https://github.com/StrongKey) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa071787d2c3_Twitter.png)](https://twitter.com/strongkeyinc) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa775287d2c0_Linkedin.png)](https://www.linkedin.com/company/strongkey)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526bcf0df80d185f961b8d_youtube_white_icon.png)](https://www.youtube.com/channel/UCueU61oRt9G6MILRSHIfimA) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036be2bdf2d65e2d2fc906f_Instagram_5%25.png)](https://www.instagram.com/strongkeyinc/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036bd8ef3da6a4bb2e24382_facebook_10%25.png)](https://www.facebook.com/strongkeyinc/)

#### Subscribe to Our Newsletter

Receive helpful information and the latest news from the world of cybersecurity