Service 01 · Phishing-resistant migration

Moving an agency off passwords without breaking Monday morning.

The technology is the easy part. The hard part is the front-desk clerk who shares a workstation, the parks crew who do not carry agency phones, and the help desk that will absorb every question in week one. This page is about that part.

What the engagement produces

  • A written posture report ranking every authentication path in your environment
  • A department-by-department migration order, with the hard cases named
  • Enrollment and recovery patterns for staff a passkey rollout usually strands
  • A help-desk runbook written against your actual ticketing process
  • A cutover and rollback plan per department, agreed before anyone switches
The cases that stall rollouts

Six people every passkey rollout forgets.

A migration does not fail on the office workers with agency laptops. It fails on everyone else, and those are the ones we plan for first.

The clerk with no agency phone

Plenty of public employees will not, and should not have to, put a work credential on a personal device.

Our pattern: an issued hardware security key on a lanyard or keyring, inventoried like any other asset, with a spare held by the department.

The shared front-desk workstation

Permits counter, dispatch, the library terminal. Four people, three shifts, one machine, and a queue of residents waiting.

Our pattern: per-person roaming keys against a shared device profile, so identity stays individual and the sign-in stays fast enough for a counter.

The field crew and the truck laptop

Public works, inspections, utilities. Intermittent connectivity, gloves, and a device that lives in a vehicle.

Our pattern: platform passkeys bound to the assigned device where the hardware supports it, with session lifetimes tuned to how the crew actually works rather than to a policy default.

The seasonal and temporary hire

Summer parks staff, poll workers, substitute teachers. On the payroll for weeks, and gone.

Our pattern: a fast enrollment path tied to onboarding, keys returned at exit, and automatic expiry so nobody has to remember to revoke.

The person who lost their key on a Friday

Account recovery is where attackers go once the login itself stops being phishable. It is the weakest point in most rollouts.

Our pattern: in-person, identity-proofed recovery as the default, a documented remote exception path, and a spare key policy that means most people never need either.

The application nobody will let you touch

The permitting system, the tax package, the twenty-year-old thing the clerk's office runs on. Most agencies have at least one.

Our pattern: we name it in the assessment, put it behind phishing-resistant access where it cannot be changed directly, and tell you plainly if the honest answer is that it stays a risk until the vendor moves.

The four stages, in detail

What you get at the end of each stage, in writing.

Stop after any stage and keep every deliverable produced up to that point. Nothing here depends on you buying the next one.

Stage 01

Posture assessment

Typically 2 to 4 weeksFree call first

We work through every way a human being can authenticate into your environment: domain logins, the VPN, email, the finance package, remote access for the IT vendor, the shared accounts nobody documented. Each one gets placed on the CISA ladder and ranked by what it would cost an attacker to get through it.

You end up with something you can act on without us: a prioritized order, the hard cases named, and cost ranges you can take into a budget request.

You receive

  • Written posture report
  • Authentication path inventory
  • Prioritized migration order
  • Costed options for stages 2–4
Stage 02

Pilot on one department

Typically 4 to 8 weeks

A dedicated authentication instance stood up for your agency, then one real department moved onto passkeys end to end. We pick the department with you, and we deliberately choose one with at least one hard case in it rather than the easiest team in the building.

The point is evidence. At the end you know your real enrollment time, your real help-desk volume, and whether anything in your environment objects, before you commit to the rest.

You receive

  • A running dedicated instance
  • One department fully migrated
  • Help-desk runbook
  • Staff enrollment materials
  • Pilot findings memo
Stage 03

Agency-wide rollout

Typically one fiscal year

The pilot pattern repeated department by department, on a schedule your help desk can absorb. Each department gets a named date, a pre-cutover session with its supervisors, and its own rollback plan, so a bad week for one team never stalls the whole rollout.

Legacy logins are retired as we go, deliberately and one at a time, rather than left running quietly next to the new system where an attacker can still reach them.

You receive

  • Scheduled cutover plan
  • Per-department rollback plan
  • Legacy login retirement log
  • Recovery policy, written
Stage 04

Operate and evidence

Renews annually

We keep the system patched and are on call when something breaks, and we re-run the posture assessment every year so what you hand an auditor is current rather than a snapshot from the year you migrated.

This stage is optional in both directions. If your team would rather run it themselves, we hand it over and document the handover, because the software is open source and yours either way.

You receive

  • Managed dedicated instance
  • Support response commitment
  • Annual posture report
  • Exportable audit event history
Your side of it

What we need from your agency.

A migration is not something done to an agency from outside. The engagements that go well have these four things, and the ones that stall are usually missing the second or the fourth. We would rather say that before you sign anything than discover it in month three.

01

One person who owns it

Not a committee. Someone with enough authority to set a cutover date for a department and make it stick.

02

Help-desk time in week one

Every department cutover produces a spike of questions. We write the runbook, but your desk answers the phone. Budget the hours honestly.

03

An honest inventory

Including the shared account in the clerk's office and the vendor with standing remote access. We will find them anyway; finding them in week two is cheaper.

04

Willingness to retire things

A phishing-resistant login next to a legacy one that still works is not a migration. Some old paths have to actually be turned off.

Start with a conversation, not a contract

Tell us your three hardest cases. We will tell you how we would handle them.

Thirty minutes, free, with the person who would run the work. If your hard cases are ones we cannot solve well, that is a useful answer too and you will get it on the call.