As we enter 2024, Phishing Resistance is still finding its footing in many enterprise environments. Early adopters have shared mixed results, and the best practices are only beginning to emerge.
The ransomware surge of 2023 — which saw average payouts climb above $1.5 million — has forced security teams to treat Phishing Resistance as a priority rather than a nice-to-have. Yet budget constraints and skills shortages mean progress is uneven.
OpenVPN 2.6, released in late 2023, remains the workhorse for many deployments. WireGuard has gained traction for its simplicity, though some enterprises hesitate over key management at scale. On the commercial side, NordVPN, ExpressVPN, and ProtonVPN dominate consumer rankings, while Cloudflare's WARP and Tailscale are winning over developers.
GDPR enforcement in 2023 set new records, with fines exceeding €2 billion across the EU. The NIS2 Directive transposition deadline looms in October 2024, and many mid-sized organizations are scrambling to understand their obligations. In the US, the SEC's new incident disclosure rules (effective December 2023) require public companies to report material cyber incidents within four days.
From a practical standpoint, the most successful phishing resistance implementations we have observed share a common pattern: they start with a narrow, well-defined use case; they measure outcomes obsessively; and they expand only after proving value. This disciplined approach is especially important in 2024, where budget scrutiny is high and 'pilot purgatory' is a real risk for organizations that chase trends without clear metrics.
Looking ahead to 2025, the trajectory for phishing resistance points toward deeper integration with adjacent technologies — particularly AI-driven automation and confidential computing. Organizations that build with interoperability in mind today will be best positioned to absorb those advances without costly re-architecture. The fundamentals — clear ownership, continuous verification, and user-centric design — will matter more, not less, as the technology matures.
Key Takeaway
Whatever tools and trends come and go, the fundamental principle behind phishing resistance — that trust must be earned, verified, and continuously maintained — is a rule that has not changed in decades and will not change anytime soon.