• Solutions
    • Passwordless Authentication
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
© All rights reserved.
Nok Nok Nok Nok
  • Solutions
    • Passwordless Authentication
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
Free Trial
Sign In
Nok Nok
30 Mar
3 Min read

What Is The Ponemon Institute?

March 30, 2022 Nok Nok News Industry News 0 comments

There’s a popular saying in the modern-day that “facts don’t care about your feelings.” Nowhere is this more true than in the field of cyber security where, just because you have a good feeling that your data is safe, this doesn’t make it actually true. The facts, like the level of cyber security maintained and the security practices followed, will be the determining factors.

One of the best ways to maintain and practice cyber security is to have experts make recommendations. In this capacity, the Ponemon Institute is a critical ally to companies, schools, and any organization concerned with ensuring their networks and data are secure.

Just The Facts

The Ponemon Institute was created in 2002 by Dr. Larry Ponemon and Susan Jayson. It is an organization dedicated to two principles: studying information security and privacy issues and educating people about those results and their implications. It’s an independent organization dedicated to objective study and gathering data to present it without bias or agenda. In other words, the Ponemon Institute studies issues of cyber security and privacy and then faithfully preserves the data acquired from those studies.

The Ponemon Institute covers both the issues of preserving data privacy, such as handling personal data of clients or patients, and it also covers security issues, such as preventing financial data, social insurance numbers, or credit card numbers from being stolen by cybercriminals.

The Institute has worked with pharmaceutical companies, financial services, telecommunications companies, hospitality, government sectors, and many more to identify the costs of data breaches as well.

Learning From The Data

The results derived from Ponemon Institute studies have a broad array of implications for cyber security. They can accurately measure the costs and losses involved with network breaches and data theft. They can show the effectiveness and cost efficiencies that come with implementing one type of network security, such as biometrics, over another, such as traditional single-password systems.

This data is not just useful for the organizations that have conducted studies. It can benefit anyone through education. Cyber security is not the only important thing; data privacy is as well. It’s not enough to ensure that companies protect their own data; the private personal data of individuals must be protected from corporate exploitation as well, especially today as Trust and Safety becomes a new category of enterprise value.

These concerns of modern cyber security form the cornerstone of the Ponemon Institute’s studies. With their data, implementing new security measures, such as multi-factor authentication and cryptographic biometric authentication, can be assured of greater effectiveness. If you’re interested in modernizing your digital security using the latest research and data, you can learn more here about Nok Nok’s modern identity and passwordless authentication and how it protects multifactor security measures.

Read more
29 Mar
0 Min read

Authentication Failures Result in the Loss of Customers – New Ponemon Institute Report Finds

March 29, 2022 Nok Nok News Industry News 0 comments

Read more
23 Mar
3 Min read

University of Sunderland A Recent Victim of Wave of Cyberattacks

March 23, 2022 Nok Nok News Industry News 0 comments

The University of Sunderland, a tertiary institution located in Northeast England, has become just one more victim in an increasing wave of cyberattacks that have been aimed at universities. In recent months, other schools, such as Newcastle University also in England, and Howard University in Washington DC, United States, have suffered similar threats to their cybersecurity.

In the case of the University of Sunderland, the cyberattack rendered students unable to log in for online, remote/distance learning classes and left staff unable to access their email and other data stored on the university network. The school’s online infrastructure was disabled for five days before restoration operations could bring the network back online and accessible to students and staff.

Universities Are New Targets

As the global pandemic changed the way people lived and worked, especially in school situations that put many young people in close proximity of each other, universities, like other organizations, had to change. Remote learning through the Internet had already made in-roads for some universities and certain courses. However, the pandemic accelerated the use and reliance of these systems, causing universities to lean more heavily on their digital infrastructure.

For many cyber-criminals, this presented new opportunities. Rather than corporations or government agencies with years of experience and “hardened” their cyber security against incursion, universities were viewed as easier targets that now relied on their digital infrastructure to work smoothly more than ever.

Ransomware On The Rise Without Cyber Security

One of the most popular forms of cyberattack in the modern day is known as “ransomware.” Rather than for the purposes of mischief or destruction, ransomware is entirely profit-motivated. In these attacks, hackers successfully bypass cyber security and seize control of a network. They then lock out legitimate users so they can no longer access their own data or manipulate the network.

The hackers then offer to restore control of the network back to the facility provided that their release fee is paid. Depending on how crucial the data is and how quickly it needs to be accessed, this can be very lucrative for digital criminals. Organizations may sometimes determine that it will be cheaper and faster to give in to the demands.

Digital Security Is Crucial

With more and more valuable data being stored digitally on networks, it is more important than ever to ensure access to confidential and critical information is properly protected. Modern cybersecurity is about more than just strong passwords, with multi-factor authentication and anti-phishing measures critical to good network security.

For modern digital protection and peace of mind, learn more about Nok Nok’s multifactor authentication technology and passwordless identity and authentication measures.

Read more
22 Mar
3 Min read

S3 Authentication Suite Makes Cyber Security Easier & More Secure

March 22, 2022 Nok Nok News Industry News 0 comments

View the official press release.

The Nok Nok S3 Authentication Suite is now ready for corporate use with a scalable, passwordless authentication system to protect both businesses and the customers they deal with. Both in-house workflow and customer transactions can enjoy a higher level of protection against identity theft and incursion thanks to updated passwordless systems that are faster and easier to implement, with minimal downtime or system reconfiguration to start enjoying more security benefits and peace of mind.

Improvements to this new suite include:

  • Pluggable Authentication for Backend Database Access
  • Enhanced Transaction Confirmation Support
  • Federation Integration
  • Enhanced Risk-Based Authentication
  • Integration with Existing Enterprise Cryptographic Infrastructure
  • Support an External Backend “Secrets” Store

And more.

The S3 suite is designed to integrate into existing APIs easily and can be easily scaled up as corporate growth demands. FIDO compliant authentication protocols are a part of the system. They can also integrate external, hardware-based key-vaults for even more added security.

Even larger enterprises using existing security systems can easily streamline them for greater ease and accessibility using S3 Authentication Suite, improving not just security but also efficiency.

Easier Implementation

Nok Nok’s S3 Authentication Suite is designed to provide minimal disruption to operations both internally for clients and externally for the customers they may serve. One of the chief concerns many businesses have when implementing security is that the additional protection comes at the cost of slowing down processes and workflow because of implementation, training, and then usage.

Nok Nok’s S3 Authentication Suite not only improves security but also reduces onboarding time to learn the system, and most important of all, it reduces the sign-in speed from existing security protocols. Using Nok Nok products can reduce sign-in times by as much as 78%, thanks to the elimination of needing to remember strong passwords if passwordless and other multi-factor authentication systems are used.

These improvements not only save time but eliminating a single-password-only security system significantly increases the chances of successfully fending off cyber attacks. Even if passwords are still part of an existing security system, with other components such as biometrics, physical keys, or one-time generated codes, securing a password is only one part of a security puzzle and is no longer enough to break into a system.

As companies continue to rely on both local devices and storage and cloud-based storage and applications, cyber security is more important than ever. For the best digital protection and peace of mind, learn more about Nok Nok’s multi-factor authentication technology and passwordless security measures.

Read more
21 Mar
3 Min read

Pentagon Official Resigns Citing US Cybersecurity As “Kindergarten” Level

March 21, 2022 Nok Nok News Industry News 0 comments

Nicholas Chaillan worked as a software chief for the United States Air Force and was assigned to the Pentagon to modernize the organization’s digital security in August of 2018. In September of 2021, he resigned from his post and claimed, “We have no competing fighting chance against China in 15 to 20 years. Right now, it’s already a done deal; it’s already over, in my opinion.”

Chaillan’s concerns stem from two major issues. The first and most important is that the United States military does not take the threat to digital security seriously enough and was unwilling to commit the funds that would have been necessary for adequate protection against military-grade digital incursions.

“I am just tired of continuously chasing support and money to do my job,” he said. “My office still has no billet and no funding, this year and the next.”

The other concern Chaillan had was the Pentagon’s reluctance to recognize that the next looming threat in digital security was not conventional attacks like “phishing” to illicitly secure passwords, but instead, the threat comes from next-generation, highly sophisticated digital attacks reliant on artificial intelligence to penetrate systems that still don’t use newer techniques like biometrics.

While not true artificial intelligence in the sense of software that can think autonomously, AI refers to increasingly complex algorithms capable of finding patterns and solving problems. When directed for offensive purposes, AI can be used for digital reconnaissance, such as scanning and compiling social media profiles to construct a digital “alias” of a trusted individual. It can be used to intelligently guess passwords, reducing brute force time by accessing profiles of relevant individuals. For systems not using biometrics, this collects a list of potentially useful keywords, and uses those in alphanumeric combinations for user-ID/password combinations.

Chaillan contends that China is aggressively pursuing AI in a cyber warfare capacity. They are putting in both the money and eliminating any professional or ethical barriers that might slow progress. Conversely, the United States is experiencing difficulties in this same area as expertise from companies like Google is withdrawn on ethical grounds, such as when Google objected to the use of its technology to increase the precision of drone targeting systems.

Digital Warfare Continues To Evolve

As with real-world defensive and offensive measures, digital attack and defense are in a constant state of new measures being developed requiring new countermeasures to repel. With increasingly sophisticated and automated phishing attacks, relying exclusively on 40 year old legacy password security technology is no longer be enough. If you’re still relying on a legacy password security technology and want to upgrade your network to modern identity and authentication security technology, (including the new global standard of key-pair biometrics), look at Nok Nok products for secure, password-free cyber authentication solutions. The largest global financial brands depend on Nok Nok’s modern auth platform for improving and protecting customer trust.

Read more
18 Mar
3 Min read

Insurance Companies Are Charging Higher Premiums For Less Cyber-Intrusion Coverage

March 18, 2022 Nok Nok News Industry News 0 comments

Insurance companies around the USA are now following an alarming trend of increasing premiums on hacking and digital security breach coverage while providing less coverage when these issues occur. When it comes time to renew a policy for digital security, some companies are now facing as much as a 300% increase for budgeting in this contingency. A major reason for the increase is the rising number of successful attacks, forcing insurers to pay out to clients. Throughout the pandemic, as various organizations have moved work and data to local networks and even to cloud-based networks to facilitate data sharing, digital intrusions have increased. Ransomware and similar attacks have plagued many sectors, including construction, healthcare, government, and education that have failed to upgrade to more secure forms of protection like multifactor authentication.

More Measures Required Like Multifactor Authentication

Insurance companies themselves are becoming increasingly stringent when it comes to even considering giving coverage to a company for digital security. For example, many insurance companies won’t approve an application from a company that doesn’t use MFA, or multifactor authentication, a verification system that relies on more than just a person using only a single password to gain access to a network. Single password systems are incredibly vulnerable and far more prone to a successful intrusion than networks using MFA protocols.

Insurance companies are now also using their own scanning and digital reconnaissance technologies to “audit” the networks of potential clients and see how vulnerable they are. This has played a role in how insurers determine the monthly rates for the premiums a company must pay if they are serious about getting insured against cyber attacks.

Cyber Attacks Are Real And On The Rise

The days when only large companies or government agencies had to worry about hacking or other forms of digital intrusion are over. As more and more businesses of every size—and even private citizens—move more of their crucial data into the digital space, it becomes more lucrative for criminals.

Identity theft, where other individuals use personal identity details like credit cards and social insurance numbers, is rising. Ransomware, where network access and other critical functions are taken over and locked out until money is paid, is also hitting more companies. Network security is a real concern for any person or organization collecting and storing important, sensitive, or confidential data digitally. Legacy security systems based on single-passwords and personal information (knowledge-based access) is proving to be insufficient to protect against modern digital threats that are increasingly more sophisticated and automated. If you’re interested in upgrading your legacy security systems to modern FIDO-based multifactor authentication, Nok Nok has a variety of platform solutions and is trusted by the biggest financial institutions for protecting their customer’s identity and authentication.

Read more
16 Mar
3 Min read

Google Provides Digital Security Keys To Disrupt State-Level Hacking

March 16, 2022 Nok Nok News Industry News 0 comments

The world is now experiencing a time of conflict unlike anything seen in years, but because this is a modern-day, 21st-century clash, the war is not just being fought on a physical battlefield but also a digital one. As the invasion of Ukraine began official state hackers from both Russia and the West engaged in digital warfare, as did independent organizations such as “Anonymous,” a rogue hacking collective that has decided to stand against Russian cyber warfare.

Unfortunately, the worlds of military, corporate and civilian government data spaces are now considered fair game for state-level cyberattacks, funded and driven by government agencies. Now some companies are taking a stand.

Google Intervenes

Google, one of the premier technology companies globally for data management and analytics, is now providing security keys to groups and individuals to help protect them against cyberattack activity. They are distributing 10000 Titan security keys to individuals like journalists, whistleblowers, government officials, and others with sensitive or confidential data to encrypt and protect systems against intrusion and spying.

A Titan security key is an added level of encryption and access control. It is two devices, one a USB card shaped like a key, a Bluetooth device that functions similarly for wireless connections. This adds an extra level of multifactor authentication to an account. In addition to inputting a password to access data on, for example, a Gmail account, an account linked to a Titan security key would require the presence of the USB key plugged into the computer or a confirmed connection to the Bluetooth version for verification.

In other words, like with older multifactor authentication, methods that require a one-time code sent to a phone as an added layer of security, a Titan key system means that even if a password has been stolen through phishing or other means, the data can’t be accessed without a Titan security key to open the second “lock” on the data.

Multifactor Authentication Is The Best Defense

What Google and many other technology companies are discouraging is the use of only a single password to gain access to data and control of systems. A single password means that everything from identity theft, spying on confidential data, and outright seizure of control of systems is possible once that password is discovered.

Now that government agencies like Russia’s GRU are going after many systems and data, security is more important than ever.  If you’re still relying on a legacy password security technology and want to upgrade your network to modern identity and authentication security technology, (including the new global standard of key-pair biometrics), look at Nok Nok products for secure, password-free cyber authentication solutions. The largest global financial brands depend on Nok Nok’s modern auth platform for improving and protecting customer trust. 

Read more
16 Mar
4 Min read

Nok Nok Unveils Latest S3 Suite

March 16, 2022 Nok Nok News Press Release 0 comments

Nok Nok unveils the latest version of the S3 Authentication Suite – Version 8.0.1.

With this latest release, companies and organizations can now more easily operationalize modern identity and passwordless authentication in their system-level workflows, business processes and customer payment transactions. The enhancements to the Nok Nok S3 Authentication Suite are also designed to streamline large-scale operations in modern cloud environments and securely integrate with existing cryptographic infrastructure.

Key features and business benefits in this release include:

  • Enhanced Risk-Based Authentication: The S3 Suite now simplifies Registration and Authentication rules into a single ruleset. This allows customers to have full control over registration and authentication workflows based on predetermined business risk criteria to create very low friction customer journey experiences.
  • Federation Integration:  The S3 Suite now supports OpenID Connect as an integration mechanism allowing S3 to serve as an “authentication provider” that works with industry-leading identity providers (e.g., ForgeRock, Azure B2C) which allows Nok Nok customers to quickly integrate into existing identity and authentication systems.
  • Enhanced Transaction Confirmation Support: The S3 Suite will support payment transaction confirmation in Web Applications. Customers supporting PSD2-SCA workflows will be able to implement dynamic linking on both Mobile native and Web applications so that a fraudulent merchant or man-in-the-network can’t change the details of a FIDO-authenticated transaction to hijack and steal transaction revenue.
  • Integration With Existing Enterprise Cryptographic Infrastructure: Customers will be able to store sensitive digital system keys of our S3 server into standalone HSM (hardware security modules) or cloud-HSM hardware infrastructure to provide the ultimate business safeguards for storing and managing digital keys that control access to business servers and databases.
  • Pluggable Authentication for Backend Database Access: The S3 Suite servers will offer a pluggable connection framework that supports multiple architectural approaches to help our customers eliminate vulnerable database connections based on username and passwords from all of their existing system-level workflows and applications.
  • Support an External Backend “Secrets” Store: The S3 Server will support the ability to send push notifications and email-OTP messages through typically insecure, external gateways. To be secure, connecting and opening sessions to those external systems requires strong authentication.  With the new “external backend secrets store”, S3 offers the highest security in connecting with the systems of external MFA vendors.

“Through continued innovations that stay ahead of changing threat environments, Nok Nok continues to raise the bar above the modern authentication standards we helped to create. These new capabilities will offer greater integration flexibility for our customers that will enable them to integrate our S3 Suite with the use of their own APIs for handling encryption operations and also the use of external, hardware-based key vaults for storing sensitive information,” said Dr . Rolf Lindemann, Vice President of Products at Nok Nok.

Nok Nok’s S3 Authentication Suite was the first commercially deployed, highly scalable authentication suite built from the ground up leveraging the industry’s FIDO authentication protocols. With its modular architecture and container support, the Nok Nok S3 Suite has proven to run at internet scale, supporting mission-critical identity and modern authentication for tens of millions of users while protecting over 1B daily authentications around the globe.

About Nok Nok

Nok Nok is a pioneer in the FIDO standards and the trusted leader in next-generation identity and passwordless authentication solutions. The Nok Nok™ S3 Suite empowers companies to transform their customer experiences, transactions, business processes, and workflows by leveraging modern identity and passwordless authentication. The Nok Nok™ S3 Suite offers the most scalable and feature-rich passwordless solution that integrates into existing system-level workflows and legacy security infrastructure. Companies that implement the Nok Nok next-gen passwordless platform experience authentication success rates above 99%, onboarding conversion improvements of more than 10%, a 90% reduction in account recovery requests, and significantly reduced OpEx. Headquartered in Silicon Valley, California, the company has delivered unique inventions and innovations that are protected by a robust global patent portfolio. As a founder of the FIDO Alliance and an inventor of FIDO specifications, Nok Nok is the expert in deploying standards-based authentication, and its industry-leading customers and partners include Verizon, T-Mobile, Intuit, Cigna, Softbank, MUFG, NTT Docomo, Fujitsu Limited, Hitachi, Ericsson, MTRIX GmbH, NTT DATA, and OneSpan. For more information, visit www.noknok.com.

 

View the Official Press Release
Read more
16 Mar
4 Min read

Nok Nok Unveils Latest S3 Suite

March 16, 2022 Nok Nok News Press Release 0 comments

Nok Nok unveils the latest version of the S3 Authentication Suite – Version 8.0.1.

With this latest release, companies and organizations can now more easily operationalize modern identity and passwordless authentication in their system-level workflows, business processes and customer payment transactions. The enhancements to the Nok Nok S3 Authentication Suite are also designed to streamline large-scale operations in modern cloud environments and securely integrate with existing cryptographic infrastructure.

Key features and business benefits in this release include:

  • Enhanced Risk-Based Authentication: The S3 Suite now simplifies Registration and Authentication rules into a single ruleset. This allows customers to have full control over registration and authentication workflows based on predetermined business risk criteria to create very low friction customer journey experiences.
  • Federation Integration:  The S3 Suite now supports OpenID Connect as an integration mechanism allowing S3 to serve as an “authentication provider” that works with industry-leading identity providers (e.g., ForgeRock, Azure B2C) which allows Nok Nok customers to quickly integrate into existing identity and authentication systems.
  • Enhanced Transaction Confirmation Support: The S3 Suite will support payment transaction confirmation in Web Applications. Customers supporting PSD2-SCA workflows will be able to implement dynamic linking on both Mobile native and Web applications so that a fraudulent merchant or man-in-the-network can’t change the details of a FIDO-authenticated transaction to hijack and steal transaction revenue.
  • Integration With Existing Enterprise Cryptographic Infrastructure: Customers will be able to store sensitive digital system keys of our S3 server into standalone HSM (hardware security modules) or cloud-HSM hardware infrastructure to provide the ultimate business safeguards for storing and managing digital keys that control access to business servers and databases.
  • Pluggable Authentication for Backend Database Access: The S3 Suite servers will offer a pluggable connection framework that supports multiple architectural approaches to help our customers eliminate vulnerable database connections based on username and passwords from all of their existing system-level workflows and applications.
  • Support an External Backend “Secrets” Store: The S3 Server will support the ability to send push notifications and email-OTP messages through typically insecure, external gateways. To be secure, connecting and opening sessions to those external systems requires strong authentication.  With the new “external backend secrets store”, S3 offers the highest security in connecting with the systems of external MFA vendors.

“Through continued innovations that stay ahead of changing threat environments, Nok Nok continues to raise the bar above the modern authentication standards we helped to create. These new capabilities will offer greater integration flexibility for our customers that will enable them to integrate our S3 Suite with the use of their own APIs for handling encryption operations and also the use of external, hardware-based key vaults for storing sensitive information,” said Dr . Rolf Lindemann, Vice President of Products at Nok Nok.

Nok Nok’s S3 Authentication Suite was the first commercially deployed, highly scalable authentication suite built from the ground up leveraging the industry’s FIDO authentication protocols. With its modular architecture and container support, the Nok Nok S3 Suite has proven to run at internet scale, supporting mission-critical identity and modern authentication for tens of millions of users while protecting over 1B daily authentications around the globe.

About Nok Nok

Nok Nok is a pioneer in the FIDO standards and the trusted leader in next-generation identity and passwordless authentication solutions. The Nok Nok™ S3 Suite empowers companies to transform their customer experiences, transactions, business processes, and workflows by leveraging modern identity and passwordless authentication. The Nok Nok™ S3 Suite offers the most scalable and feature-rich passwordless solution that integrates into existing system-level workflows and legacy security infrastructure. Companies that implement the Nok Nok next-gen passwordless platform experience authentication success rates above 99%, onboarding conversion improvements of more than 10%, a 90% reduction in account recovery requests, and significantly reduced OpEx. Headquartered in Silicon Valley, California, the company has delivered unique inventions and innovations that are protected by a robust global patent portfolio. As a founder of the FIDO Alliance and an inventor of FIDO specifications, Nok Nok is the expert in deploying standards-based authentication, and its industry-leading customers and partners include Verizon, T-Mobile, Intuit, Cigna, Softbank, MUFG, NTT Docomo, Fujitsu Limited, Hitachi, Ericsson, MTRIX GmbH, NTT DATA, and OneSpan. For more information, visit www.noknok.com.

 

View the Official Press Release
Read more
07 Mar
3 Min read

A Nation’s Move To Modern Cyber Security

March 7, 2022 Nok Nok News Industry News 0 comments

Cyber attacks do not only target private individuals, but they can also represent increasingly sophisticated and persistent threats to national security. Billions of dollars are spent on legacy security annually, yet data breaches and theft are accelerating. Many institutions and organizations have suffered. That is why it is important to leverage modern security technologies and zero-trust architectures across sectors.

Becoming More Proactive

In its bid to address exposed areas of weakness in US digital infrastructure, the United States Federal Government updated its cyber security strategy.  In January 2022, President Biden signed Executive Order (EO) 14028 on Improving the Nation’s Cybersecurity. With this modern approach to cyber security, the US Federal Government boldly transitions from incremental improvements to legacy perimeter-based defenses – to significant investment in modern “zero-trust” architectures that never trust and always verify “anything and everything attempting to establish system and data access.”

Aiming for Safer Cyber Infrastructure

When multifactor authentication (MFA) was added to legacy knowledge-based-access (KBA) that is based on the storing and passing of passwords and other personal secrets, there was indeed, a measurable reduction in risk to digital systems and data compared to single factor authentication.

However, the attack strategies of bad actors (attack vectors) evolved such that today, these legacy KBA methods, even with MFA, no longer protect against sophisticated phishing attacks that easily fool account owners into providing account credentials to the attackers. Once a legitimate account is taken over (such as the case in the ransomware attack against Colonial Pipeline), it is very hard for any system to detect a bad actor before significant damage is done, data is stolen, or malicious code is embedded that creates security vulnerabilities at a later time (such as the case with the Solarwinds supply chain attack.)

In a very bold move and positive development for the modern identity and authentication industry, our nation’s new cyber security executive order recommends that federal agencies achieve zero trust security goals with strong, FIDO-based MFA by the end of Fiscal Year (FY) 2024, with plans for implementation due within 60 days.

Among other requirements for networks, devices, endpoints plus encryption for data and DNS traffic, the directive includes centralized enterprise-managed identities with phishing-resistant MFA to protect users from sophisticated attacks (including both PIV credentials and FIDO2 Web authentication (known as “WebAuthn”) created by the FIDO Alliance and published by the World Wide Web Consortium (W3C). The directive also includes enterprise-wide identity systems based on zero trust architecture that always verifies users before granting access.

Strong Defense for All

In a push for safer cyberspace infrastructure, the US Federal Government joins the thousands of enterprises that are leaving legacy KBA and perimeter-based security thinking behind in favor of modern and strong MFA identity and authentication.

As the world continues to see a massive proliferation in devices and network connectivity, technological advancements are required to address the growing challenges in fighting cyber threats and risks. Nok Nok Inc in partnership with the global FIDO Alliance they founded, is among those at the forefront of this fight.

The FIDO Alliance is an open industry association that develops and promotes authentication standards. At the same time, it also pushes for safer and more convenient cyber security measures for the end-user. Thus, making it a mission to reduce people’s insecure and over-reliance on legacy password and KBA-based system access. Learn about Nok Nok’s industry-leading FIDO platform for strong user and IoT authentication here.

Read more
    12

Contact Us

Nok Nok, Inc.
2890 Zanker Rd #203
San Jose, CA 95134

(650) 433-1300

[email protected]

Get Google Maps Directions

Contact and Subscribe

* indicates required

Latest Posts

  • World Password Day: Time to Ditch Passwords for Good?
  • Verizon 2025 DBIR: Credential Attacks Still Dominate – A Nok Nok Perspective
  • Phillip Dunkelberger Recognized as a “Champion in Security” by Portal26 at RSA Conference 2025
  • Another Step Towards a Passwordless Future

Navigation

  • Subscribe
  • Careers
  • Resources
  • Support

Nok Nok Labs, Nok Nok, and NNL are all trademarks of Nok Nok Labs, Inc. © 2025 Nok Nok Labs, Inc.
FIDO is a trademark of the Fast IDentity Online, (FIDO), Alliance. All rights reserved.
Terms Of Use and Privacy Policy

 

Demo
Free Trial
Videos
Contact Us
Support

Contact Us: (650) 433-1300 • [email protected]

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}

Please complete this form to view and download this resource.

Submit to Download Forms

* indicates required

[mc4wp_form id=”18773″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18790″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18789″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18788″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18787″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18786″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18785″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18784″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18783″]

MUFG-800×600

“Transactions using mobile devices are rapidly spreading and it is essential to support both usability and security. By combining Hitachi’s abundant system development capabilities and know-how in the financial system and security related fields, and Nok Nok’s globally deployed and proven FIDO certified products, we achieved this compatibility, which led to this adoption.”

– Mr. Nobuo Nagaarashi, General Manager, Financial Information Systems 1st Division, Hitachi, Ltd.

 

The M in MUFG stands for Mitsubishi, which is a combination of the words mitsu and hishi. Mitsu means three. Hishi means water chestnut, and the word denotes a rhombus or diamond shape.  In partnership with Hitachi, MUFG has enabled passwordless authentication solutions across many of the bank’s apps and services.

Coverage In The Paypers
Coverage In Finextra
intuit

“As an early adopter of FIDO, we’ve seen significant business benefits and are completely on board with continuing to leverage the latest FIDO innovations with our partner, Nok Nok.”

– Rakan Khalid, Group Product Manager, Identity.

 

Intuit has delivered passwordless authentication across mobile applications and devices using Nok Nok’s S3 Suite. The results have reduced customer friction in their Intuit application experience.

Read The Nok Nok Intuit Case Study
Watch the FIDO Alliance Webinar: The Right Mix
Watch Marcio Mello discuss Intuit’s Nok Nok implementation at Identiverse 2019:
docomo-800×600

“DOCOMO is a worldwide innovator in providing its millions of customers with simple and strong authentication backed by a standards-based approach.”

– Phillip Dunkelberger, President & CEO of Nok Nok Labs.

 

As one of Nok Nok’s earliest customers, NTT DOCOMO became the first carrier to offer a billing system that is enabled by FIDO, the first to offer a federated Identity system integrated FIDO, and was the first to offer a mobile device that authenticates via the iris biometric modality.

Coverage In Find Biometrics
Coverage In Telecompaper
bbva-800×600-2

“Traditionally, one of the biggest challenges of authentication systems has been to balance security with user experience. Due to the FIDO standard, we are confident that both elements work together seamlessly to provide customers with the highest security standards, along with a transparent and agile user experience.”

– Juan Francisco Losa, Global Technology & Information Security Officer.

Nok Nok partnered with banking leader, BBVA to improve the security and user experience of the bank’s mobile banking services through state-of-the-art biometric capabilities.

Coverage In American Banker
Coverage In Planet Biometrics
Softbank-800×600-1

“We can no longer rely on passwords for our financial or other sensitive transactions as they are weak, forgotten and easily hacked. We are very pleased with SoftBank’s decision to choose our standards-based authentication platform for their millions of customers.”

– Phillip Dunkelberger, President & CEO of Nok Nok Labs.

 

Millions of SoftBank’s mobile subscribers now have the ability to use biometrics for authentication through the mobile application “My SoftBank Plus”. With this implementation, SoftBank’s mobile users access data with the My SoftBank service using biometrics for a frictionless, simple and fast authentication experience.

Coverage In Mobile ID World
Coverage In Planet Biometrics
Coverage In The Paypers
Aflac-Japan-800×600-1

“Aflac is the first Japanese insurance provider to deploy a FIDO-certified solution, and we would like to continue collaborating with Nok Nok Labs to introduce it to banks, insurance industry and other industries.”

– Michihiko Ejiri, VP, Head of Portal Service Division, Service Technology Unit, Fujitsu Limited.

With the Nok Nok S3 Suite, Fujitsu has provided Aflac customers with strong authentication to their mobile claims payment application using any biometrics on their iOS and Android devices. The solution also provides Aflac and their customers with a scalable method to authenticate users that is interoperable with their existing security environments and reduces or eliminates the reliance on usernames and passwords.

Coverage In Find Biometrics
Coverage In Find Authority
lichtenstein-800×600-1

“For our customers, we only use the most secure products on the market that meet their requirements. Nok Nok perfectly aligns within our product portfolio and we are proud of the very trusted partnership.”

– Lukas Praml, CEO of YOUNIQX.

 

YOUNIQX Identity AG, the award-winning subsidiary of the Austrian State Printing House (OeSD) and Nok Nok partnered to deliver a electronic identity system (eID) for the citizens of the country of Liechtenstein.  This deployment represents the first time that Nok Nok’s FIDO platform has been used to deliver an eID.

FUN FACT
As of 2009 Liechtenstein’s per capita income was $139,100, the highest of any country in the world.

Learn How FIDO Supports EIDAS Regulation
Coverage In Mobile ID World
Coverage In The Paypers
Coverage In Biometric Update
Gallagher-800×600-1

“Nok Nok’s state-of-the-art, standards-based platform will deliver a tremendous user experience,”

– Steve Bell, Chief Technology Officer at Gallagher

When a horse called Joe took too much of a liking to using a car as a scratching post, owner Bill Gallagher Sr. devised a cunning electrical circuit that delivered a shock whenever the horse rocked the vehicle, and in doing so created a company.  Today, with passwordless authentication from Nok Nok, Gallagher is leading the IoT industry with innovative solutions that work in your office and in the outback.

Coverage In Biometric Update
Coverage In Mobile ID World
Coverage In Planet Biometrics
tmobile-800×600-1

“Our Forgot Password flows were running at about 65%. After we rolled out FIDO by Nok Nok, our forgot passwords dropped to 7%.”

Michael Engan, T-Mobile

 

Using the Nok Nok S3 Suite, T-Mobile has become a leader in carrier adoption of passwordless authentication. Their solutions have reduced forgotten passwords and dramatically improved customer satisfaction.

Watch Michael Engan from T-Mobile talk about their implementation of Nok Nok’s S3 Authentication Suite at Identiverse 2019.

  • 日本語