Company Overview
About Duo Security
Duo Security (now Cisco Duo) is an enterprise-grade zero-trust security platform providing multi-factor authentication (MFA), device trust, and secure access solutions that protect applications and users against credential-based attacks. Founded in 2009 by Dug Song and Jon Oberheide in Ann Arbor, Michigan, Duo was acquired by Cisco in 2018 for $2.35 billion and has grown significantly under Cisco ownership, expanding from MFA to a comprehensive zero-trust access platform.
Business Model & Competitive Advantage
Duo's simplicity was its defining early advantage — deploying MFA took hours instead of weeks, and the end-user experience (a push notification to a smartphone) was frictionless compared to hardware tokens. This drove rapid adoption at technology companies, universities, and eventually enterprises across all industries. By 2024-2025, Duo protects access for millions of users at tens of thousands of organizations, with particularly strong penetration in education, government, and healthcare.
Competitive Landscape 2025–2026
In 2025, Cisco Duo is a core component of Cisco's security portfolio, integrated with the Cisco Security Cloud platform alongside Umbrella (DNS security), Secure Endpoint, and Cisco Identity Intelligence. The platform has evolved from standalone MFA to a comprehensive continuous trust evaluation layer that considers device health, user behavior, and network context in every access decision. Duo competes with Microsoft Entra (Azure AD MFA), Okta Verify, and RSA SecurID in the MFA market, with the broader zero-trust access competition including Zscaler and Palo Alto Networks. Cisco's distribution network gives Duo access to enterprise accounts that might not otherwise evaluate a standalone identity tool.
Recent Activity
View all →Quarterly Report filed 2026-08-13
Material Event filed 2026-08-12
I’m excited to announce that Duo Federal Edition FedRAMP High Class D certification is now generally available! This represents a significant milestone in our commitment to supporting U.S. Federal, State, and Local Government agencies with enterprise security solutions that meet strict compliance requirements. Cisco Duo Federal Edition High Class D is a FedRAMP High Class D (IL4) authorized instance of our authentication solution, purpose-built specifically for U.S. Government requirements and compliance standards. It’s a cloud-delivered multi-factor authentication solution grounded in zero trust principles that provides seamless, transparent, and phishing-resistant user access from both desktop and mobile devices to any application—whether internet-based, SaaS, or private applications hosted in the cloud or on-premises. Duo Federal Edition FedRAMP High Class D is built for the environments you actually operate in: Federal agencies handling mission-critical workloads Contractors suppor
Choosing the right authentication protocol depends on your applications, your user types, and the protocols supported by your identity provider. This article considers these three main factors, and others, explaining how modern organizations deploy protocols, their best use cases, and common security risks introduced during configuration. Most organizations use more than one protocol. Match each protocol to the right use case and manage them through a single identity platform, not to consolidate onto one standard. SAML remains widely deployed for enterprise single sign-on, with a market projected to grow through 2033. Use it for legacy applications and deployments that do not neatly communicate with newer protocols like OIDC. OIDC and OAuth 2.0 are built for modern and mobile applications. OIDC verifies who the user is. OAuth 2.0 governs what a third-party application can do with their account. If your stack is moving toward cloud-native architectures, these are the protocols that fit.
Most organizations have outgrown their identity infrastructure. The Identity Provider (IdP) configurations and directory services that worked five years ago were not designed for distributed workforces, hundreds of cloud applications, and machine identities that outnumber people. Here, we cover the principles of designing an identity architecture that keeps up. Explore Duo's approach to identity Legacy identity infrastructure creates security blind spots and operational drag that compound as organizations grow. Cloud-native IAM is not just cloud-hosted identity. It is an identity built for API-driven, distributed, continuously verified environments. Identity orchestration platforms coordinate authentication across multiple identity sources, devices, and risk signals to make dynamic access decisions. An identity management roadmap starts with consolidation and ends with continuous verification. Most organizations are somewhere in between. Most identity infrastructure was designed f
Microsoft’s Active Directory (AD) manages user identities for roughly 90% of Fortune 1000 companies . It controls who can log in, what they can access, and which security policies apply to every connected device. That reach is exactly why attackers treat it as a high-value target, and why security teams should develop strategies that adapt to emerging threats. Active Directory is involved in 9 out of 10 cyberattacks, according to the Semperis 2024 Ransomware Risk Report. Its centrality to enterprise identity makes it the highest-value target in most organizations. Traditional Active Directory hardening—static policies, periodic audits, perimeter firewalls—leaves gaps that attackers routinely exploit between review cycles. A modern Active Directory security strategy layers adaptive authentication, single sign-on, device trust, and continuous verification on top of existing directory infrastructure. Cloud directory services let organizations extend or replace on-premises directories with
Material Event filed 2026-07-07
Duo is joining PlainID's IDP Authorizer program. Your tokens are about to get smarter. When a user authenticates through an IdP, the resulting token carries claims that downstream applications use to make access decisions. In most enterprise environments today, those claims are static. They reflect what was mapped at configuration time, not what the user should actually be able to do right now. A user whose role changed this morning still carries yesterday's entitlements in their token. An employee who moved from Engineering to Sales still has access to developer tools until someone manually updates the IdP mapping. The token does not know what changed, it only knows what was configured. Organizations that have invested in dedicated authorization engines like PlainID have already solved the "what can this user do" problem. They have policies, context, and real-time evaluation. But that investment only pays off if the IdP can call out to the authorization engine at t
Enterprise identity has changed a lot over the last few years. Users are no longer sitting behind a single network perimeter, accessing a small set of applications from managed devices. Today, they work from anywhere. Applications sit across SaaS, private data centers, cloud platforms, and partner environments. Devices can be managed, unmanaged, personal, mobile, or sometimes simply unknown. And then there are the identities. Human and non-human identities (NHIs), such as service accounts, SaaS accounts, cloud identities, legacy accounts, and now even AI-driven workflows are adding to the mix. Identity sprawl has become one of the biggest challenges security teams are trying to solve. Attackers have noticed this shift too. They are not always trying to force their way in through exposed infrastructure. Increasingly, they are logging in with valid credentials, abusing excessive privileges, hijacking sessions, and blending into everyday user activity. That means identity can no longer be
For years, multi-factor authentication has been the baseline for protecting accounts, but not all MFA is created equal. Attackers have grown adept at phishing their way past weaker methods like SMS, phone calls or one-time passcodes, tricking users into handing over the very factors meant to keep them safe. In response, Duo continues to invest in phishing resistant authentication like passkeys and Duo Mobile Proximity Verification to make sure our customers are able to widely adopt these methods and better protect your organizations. Phishing-resistant authentication is moving from a best practice to a hard requirement for many, starting with the accounts that matter most: your administrators and privileged users. Salesforce is now one of those platforms. Beginning July 20, 2026 Salesforce requires phishing-resistant MFA for all privileged users in production , including anyone with the System Administrator profile or permissions like Modify All Data, View All Data, Customize Applicati
Material Event filed 2026-07-01
When it comes to multi-factor authentication (MFA), not all methods provide the same level of protection. Telephony-based MFA, including SMS passcodes and phone callback verification, was once considered a reliable and accessible option. Today, evolving security standards and an increase in sophisticated cyberattacks has rendered these methods increasingly vulnerable, and many organizations are replacing SMS MFA with stronger alternatives like Duo Push notifications, security keys, and biometric authentication. This blog post explains why telephony-based MFA is no longer sufficient, what stronger MFA options are available, and how to migrate your organization away from telephony methods step by step. Whether you are just starting to evaluate the change or ready to execute, this guide gives you a clear path forward. Explore the versatility of Duo’s authentication methods and how they support a modern security strategy. Phone call and SMS-based MFA methods are vulnerable to several well-
Key Differentiators
Emerging Innovator
Duo Security is an emerging player bringing innovative solutions to the Security market.
Frequently Asked Questions
Estimated Visibility Trend (Beta)
Simulated 8-week rolling score
Based on estimated brand signals. Historical tracking coming soon.
Similar Brands
Reality Defender
Reality Defender is an AI-powered deepfake and synthetic media detection platform protecting enterprises, media organizations, and government agencies from AI-generated voice cloning, video manipulati
Tracecat
Tracecat is a San Francisco-based open-source security automation platform — backed by Y Combinator (W24) with $500,000-$2 million in seed funding from Y Combinator, Pioneer.app, Pioneer Fund, and Sur
1Password
1Password is an enterprise password manager and secrets management platform enabling individuals, teams, and businesses to securely store, manage, and share credentials, credit cards, and sensitive in
Bitwarden
Bitwarden is a Santa Barbara-based open-source password manager and identity security platform — backed with $100 million raised in a Series C led by PSG in September 2022 — providing individuals, tea
Anduril Industries
Anduril Industries is a defense technology company building autonomous weapons systems, surveillance infrastructure, and AI-driven defense platforms for the US military and allied nations. Founded in
Browser Use
Browser Use is an open-source project that provides a Python library allowing AI agents and large language models to control web browsers as a tool. The library sits between LLM APIs and browser autom
Compare Duo Security with Competitors
Side-by-side AI visibility scores, platform breakdown, and market position.
Claim This Profile
Are you from Duo Security? Claim your profile to see full AI mention excerpts, get weekly visibility change alerts, and optimize how AI systems describe your brand.
Claim Duo Security Profile →Track AI Visibility in Real Time
Monitor how ChatGPT, Gemini, Perplexity, and Claude mention Duo Security vs competitors. Get alerts when AI recommendations shift.
Start Free Tracking →