Delivering FIDO Security Keys at Banking Scale: Simplify Distribution and Provisioning for Optimal Adoption

Delivering FIDO Security Keys at Banking Scale: Simplify Distribution and Provisioning for Optimal Adoption
lee.potok@thal…
Tue, 09/22/2026 – 07:12

In previous articles, I explained how financial institutions, driven by regulatory pressures and a surge in phishing attacks, are adopting the FIDO2 standard to secure their transactions and reduce frauds and data breaches. Under the FIDO standard, various types of authenticators – from synchronized passkeys to those bound to a mobile or hardware security keys – are offering distinct benefits in terms of user convenience and assurance levels. Device-bound passkeys and especially hardware security keys, provide the highest level of assurance and are recommended by analyst and regulatory bodies for workforce authentication and strong customer Authentication. Consequently, Thales has observed major banks considering the adoption of FIDO security keys and has supported them in large-scale deployments.

Identity & Access Management

Sarah Lefavrais | IAM Product Marketing Manager
More About This Author >

Summary: Banks deploying FIDO2 security keys at scale need a practical way to get them to employees, customers, and partners without creating more work for internal teams. Provisioning keys before they are shipped and delivering them directly to users can make large deployments faster and easier to manage.

In previous articles, I explained how financial institutions, driven by regulatory pressures and a surge in phishing attacks, are adopting the FIDO2 standard to secure their transactions and reduce frauds and data breaches.

Under the FIDO standard, various types of authenticators – from synchronized passkeys to those bound to a mobile or hardware security keys – are offering distinct benefits in terms of user convenience and assurance levels. Device-bound passkeys and especially hardware security keys, provide the highest level of assurance and are recommended by analyst and regulatory bodies for workforce authentication and strong customer Authentication. Consequently, Thales has observed major banks considering the adoption of FIDO security keys and has supported them in large-scale deployments.

Choosing a FIDO2 security key is only the start. Banks still need to work out how those keys will reach employees, customers, and partners, particularly when there is no IT team on hand to issue them.

This becomes more complicated when these users are remote and spread across different countries. Shipping from one central location can mean longer delivery times, higher costs, customs delays, and more work for internal teams receiving and redistributing devices.

Simplify the Distribution

Handing keys out through an IT desk may work for employees based at headquarters, but it quickly becomes impractical for a remote or international workforce. The same problem arises when a bank needs to distribute physical security keys to thousands of digital banking customers.

If keys first arrive at one central location, the bank must receive the shipment, sort the devices, and send them out again to individual users or regional offices. Banks relying on international delivery services also must account for customs, tariffs, and the delays these can cause.

Last-mile delivery can take those steps out of the logistics. A FIDO security key can be sent to the intended recipient without first being shipped to an office for manual setup. A network of fulfillment centers, like the one owned by Thales for Payment card issuance, can also allow FIDO security keys to be shipped from locations closer to the people receiving them, rather than sending every key from a single country.

 This can make a considerable difference at banking scale. One large European bank needed phishing-resistant authentication for digital banking customers who could or prefer not to use a mobile app to access its banking application. Thales created authentication kits containing FIDO USB-C NFC tokens, USB-C to USB-A converters, key cords, and manuals. In total, hundreds of thousands of kits were fulfilled and delivered to end users.

Getting a key to someone's door is not the end of the process. There is also a practical reason to reduce the work left for the user. A key that arrives blank still must be registered before it can be used. That creates another step between delivery and first login and can lead to users contacting support if they have problems getting started. The closer the key is to being ready to use when it arrives, the less work remains for both the user and the bank.

Bind & Provision the Key Before It Is Used

A FIDO2 security key needs to be linked to the right user before it can provide the assurance the bank expects from it. NIST

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Thales CPL Blog Feed

Read the original article: