Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSecure employee accounts by requiring multifactor authentication (MFA) across business systems and limiting each account to the access its user needs. MFA makes a stolen password less useful; least privilege limits the damage an account can do if it is compromised. Neither control replaces safe recovery, monitoring, or prompt removal of obsolete access.
For a small or midsize business, the practical order is to inventory identities and systems, enforce MFA, choose methods that resist phishing where possible, separate everyday and administrator accounts, then review access and account lifecycle procedures regularly.
1. Inventory accounts and the systems they can reach
Start with a current list of who can sign in and where. Include employees, contractors, administrators, service accounts, and emergency accounts. Map each identity to the systems it can access, including email, remote access or VPN, file sharing, the identity provider, cloud consoles, finance systems, and business applications.
Flag applications that cannot enforce MFA, as well as local accounts, legacy protocols, and alternate sign-in routes. Assign each gap an owner and a mitigation or replacement plan. A strong sign-in policy is incomplete if another credential or recovery path bypasses it.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
2. Require MFA across business access
Configure the identity provider and application policies to require MFA rather than leave it optional. During rollout, prioritize administrator accounts and employees who handle sensitive information, then extend enforcement to all users and services. Include remote and third-party access.
Check that the policy is enforced in the actual applications and covers their alternate credentials, legacy access methods, local accounts, and recovery flows. CISA advises small businesses to require MFA for accounts and systems; its guidance notes, “Strong passwords help, but they are no longer enough to keep accounts and systems safe when used alone.” See CISA’s Require Multifactor Authentication guidance.
3. Select an MFA method that fits the threat and environment
MFA options differ in how well they resist phishing, and in compatibility, user accessibility, recovery burden, and support effort. Prefer FIDO/WebAuthn security keys or platform authenticators when the identity provider, applications, and employee devices support them. These use cryptographic methods designed to resist credential phishing. CISA characterizes security keys as providing “the best protection against phishing” and being easy to use; that is CISA’s guidance, not a comparative product test. Its small-business page names YubiKey as an example of the category: CISA MFA guidance.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If phishing-resistant methods cannot be deployed immediately, number-matching push is a useful interim measure because it can reduce indiscriminate approval prompting. Plan a transition where stronger methods are supported. Authenticator-app one-time codes are a practical option but can still be phished. SMS and voice codes are weaker and should be fallback options when stronger methods are unavailable. NIST SP 800-63B Revision 4 states, “Passwords are not phishing-resistant”; its requirements address digital identity services and are not a universal legal mandate for every private business. See NIST SP 800-63B Revision 4.
| Method | Phishing resistance and role | Deployment checks |
|---|---|---|
| FIDO/WebAuthn security key or platform authenticator | Preferred where supported; designed to resist credential phishing. | Confirm support in the identity provider, applications, browsers, operating systems, and device fleet. Plan enrollment, backup authenticators, and safe recovery. |
| Number-matching push | Useful interim option; helps reduce indiscriminate approval prompts, but is not a substitute for phishing-resistant authentication. | Check identity-provider support, employee usability, and a path to stronger methods where available. |
| Authenticator-app one-time code | Practical alternative, but codes can be phished. | Plan secure enrollment, authenticator replacement, and recovery. |
| SMS or voice code | Weaker option; reserve for cases where stronger methods are unavailable. | Identify accounts relying on it and plan stronger coverage when compatible methods become available. |
For a physical FIDO2 key, verify USB-A or USB-C connectors, NFC needs, supported protocols, the device fleet, identity-provider compatibility, spare-key policy, and account recovery before selecting a model. A key is one authenticator, not a complete MFA and least-privilege program.
4. Separate routine work from administration
Give each employee a standard account for email, browsing, and ordinary line-of-business work. Administrators should use separate privileged identities only for administrative tasks; everyday accounts should not have administrator-level privileges by default. Where possible, grant elevated rights only when needed and for a limited period, then disable or remove them.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
CISA recommends separating user and privileged accounts and reviewing permissions regularly. Its small-business resource, Take the First Steps Towards Better Cybersecurity With These Four Goals, provides related implementation guidance.
5. Grant access by role and review it regularly
Define roles around job duties and grant only the systems, data, and administrative rights required for the work. Restrict sensitive information and administration to people who need them. Review access on a recurring schedule and whenever someone changes roles, leaves, or a vendor relationship changes. Remove stale accounts and unused privileges; monitor active accounts and maintain a controlled emergency-access process.
IAM capabilities can help organizations manage roles and access privileges. CISA discusses these practices in Identity and Access Management: Recommended Best Practices for Administrators and its #StopRansomware Guide, which also supports least privilege and separation of duties for third-party access.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
6. Build enrollment, recovery, and offboarding into the rollout
Document how identities are verified during enrollment, how authenticators are issued, and what employees must do if a device is lost or stolen. Set a replacement and recovery process, decide how backup authenticators are enrolled, and store recovery material securely. Test the process to make sure it does not become an easier route around MFA.
Include role changes, contractor expiration, and employee offboarding: remove access when it is no longer justified, and invalidate lost or stolen authenticators as appropriate. NIST SP 800-63B Revision 4 addresses authenticator binding and invalidation after loss or theft, as well as recovery concepts: NIST SP 800-63B Revision 4.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.7. Track coverage, exceptions, and unresolved risk
Use a recurring review to identify where controls are in place and where work remains. Track:
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
- MFA enforcement by application and account class.
- Adoption of phishing-resistant methods.
- Privileged accounts that are not separated from standard-user accounts.
- Legacy exceptions, with an owner, expiration or review date, and remediation plan.
- Dormant accounts and completion of access reviews.
Escalate systems that cannot enforce MFA and document the mitigation while a replacement or remediation is pending. There is no single established statistic here for the impact of this exact combined rollout; report your organization’s own coverage and incident measures rather than applying a figure from a different control or population.
This is general U.S.-oriented cybersecurity guidance, not a determination of legal or regulatory duties. Tailor assurance and access requirements to the data, services, applicable rules, and threat model.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

