YubiKey en el trabajo
Guides and Tutorials

YubiKey at Work: How to Convince Your Company to Use It

Corporate accounts — Google Workspace, Microsoft 365, company VPN — are one of phishing's favorite targets. An employee with a password + SMS is still vulnerable. A YubiKey, on the other hand, makes that kind of attack stop working. The problem isn't technical: it's convincing your company to take the step.

Here you have the arguments and the script to bring it up, whether you're the one making the decision or you need to convince IT or your manager.

Why the 2FA you're already using isn't enough

SMS can be intercepted through SIM swapping. Authentication apps are vulnerable to MFA fatigue — the attacker floods notifications until someone accepts by mistake. And real-time phishing (adversary-in-the-middle) can steal the session even if the one-time code is correct.

A FIDO2-based security key eliminates these three vectors because authentication is tied to the real domain of the service. A fake website, no matter how well copied, cannot complete the process.

Verifiable fact

After deploying physical security keys across its entire workforce, Google reported zero account thefts due to phishing among its more than 85,000 employees (Google Security Blog, 2019).

If you want to better understand what a security key is and how the protocol behind it works, you have the full explanation in What is a security key? and in what is 2FA and how to protect your accounts.

The argument that matters to your company

You're not going to convince your company by talking about technology. You convince them by talking about risk and cost.

The argument in one sentence

A compromised corporate account costs much more — in time, data, reputation — than the price of a physical key per employee.

Add these three points, in this order:

  • Low cost: a YubiKey costs once, it's not a subscription.
  • Quick implementation: Google Workspace and Microsoft 365 already support FIDO2/passkeys natively.
  • Compliance: if your company handles sensitive data, strong authentication is usually part of your industry's regulatory requirements.

How to bring it up — step by step

1
Don't ask for a change across the entire company

Propose a pilot with 3-5 people, including yourself. It's much easier to approve.

2
Bring the cost argument already calculated

The price of one key per employee against the estimated cost of a phishing incident.

3
Explain that it doesn't replace the password, it strengthens it

It's added as a second factor. You don't have to change the current system from scratch.

4
Have the answer ready to "what if I lose it?"

With a second backup key registered, losing it doesn't block access.

If you need arguments specifically for whoever manages the purchase (how many keys, how to organize them by team), you have the full guide in Yubico for enterprises: how many YubiKeys do you need and how to manage them.

Common objections — and how to answer them

What if I lose the key?

A second YubiKey is registered as backup from day one. If the main one is lost, it's revoked and you continue accessing with the backup.

Is it complicated to use for someone non-technical?

No. You connect it or bring it close to your phone via NFC and tap it. No code to type or app to open.

Is it expensive to implement?

It's a one-time purchase per employee. Compared to the cost of a security incident, the difference is considerable.

Do we need to change our entire access system?

No. It's added as an additional verification method within Google Workspace or Microsoft 365, without touching the rest of the infrastructure.

Once approved: don't let it gather dust in a drawer

The most common reason a company abandons this kind of initiative isn't technical: it's that the key gets lost or stays at home. Carrying it comfortably — with backup included — is what keeps the habit going.

Credit card format holder for YubiKey, 1 slot

Credit card format

Credit card format holder with 1 slot. Fits in any wallet, next to your other cards. NFC works without taking the key out. Made in Spain (EU).

Dimensions: 85.6 × 54 mm
Material: PLA+
Compatible with: YubiKey 5 NFC · YubiKey 5C NFC · Security Key NFC · Security Key C NFC
View on Amazon
Credit card format holder for YubiKey, 2 slots

For backup

Holder with 2 slots: main key + backup in the same holder. Ideal if you follow the advice of always having a second registered key.

Dimensions: 85.6 × 54 mm
Material: PLA+
Compatible with: YubiKey 5 NFC · YubiKey 5C NFC · Security Key NFC · Security Key C NFC
View on Amazon

Want to learn more?

If you prefer to compare all the options for cases and holders before deciding, you have the guide in Carry your YubiKey in your wallet: credit card format holder.

Verdict

The decision doesn't always depend on you — but the right argument speeds up the yes

You can't guarantee your company will approve the change. But bringing the cost argument, a small pilot, and pre-answered objections makes the conversation move much faster than just asking for it.


As an Amazon Associate, I earn from qualifying purchases.

Back to blog