Company Overview
About Duo Security
Duo Security (now Cisco Duo) is an enterprise-grade zero-trust security platform providing multi-factor authentication (MFA), device trust, and secure access solutions that protect applications and users against credential-based attacks. Founded in 2009 by Dug Song and Jon Oberheide in Ann Arbor, Michigan, Duo was acquired by Cisco in 2018 for $2.35 billion and has grown significantly under Cisco ownership, expanding from MFA to a comprehensive zero-trust access platform.
Business Model & Competitive Advantage
Duo's simplicity was its defining early advantage — deploying MFA took hours instead of weeks, and the end-user experience (a push notification to a smartphone) was frictionless compared to hardware tokens. This drove rapid adoption at technology companies, universities, and eventually enterprises across all industries. By 2024-2025, Duo protects access for millions of users at tens of thousands of organizations, with particularly strong penetration in education, government, and healthcare.
Competitive Landscape 2025–2026
In 2025, Cisco Duo is a core component of Cisco's security portfolio, integrated with the Cisco Security Cloud platform alongside Umbrella (DNS security), Secure Endpoint, and Cisco Identity Intelligence. The platform has evolved from standalone MFA to a comprehensive continuous trust evaluation layer that considers device health, user behavior, and network context in every access decision. Duo competes with Microsoft Entra (Azure AD MFA), Okta Verify, and RSA SecurID in the MFA market, with the broader zero-trust access competition including Zscaler and Palo Alto Networks. Cisco's distribution network gives Duo access to enterprise accounts that might not otherwise evaluate a standalone identity tool.
Recent Activity
View all →Identity lifecycle management governs user access from onboarding through role changes and offboarding. It sounds simple: give people the right access when they join, update access when they move, and remove access when they leave. But in a Cisco Duo survey of 680 IT and security leaders , 60% of CISOs said they lacked confidence in their joiner-mover-leaver (JML) process, and especially the leaver stage. That is a lot. And honestly, I get it. JML is one of those things that looks fine on the dashboard until you actually run an audit on terminated accounts. Then you realize the technology is doing its job, but the humans around it are not always doing theirs. I recently had the opportunity to sit down with a few top CISOs featured in Cisco Duo's new CISO Perspectives 2026 report: Frank Aiello at Maximus, Lock Langdon at Aprio, and David Cass at Keyrock. In candid conversations, we covered automation, manager accountability, mover privilege creep, contractors, and the regulator per
Most teams comparing Cisco Duo and Okta are deciding between two priorities: securing the login, or governing the identity lifecycle. Duo is security-first IAM. It leads with phishing-resistant multi-factor authentication (MFA), device trust, single sign-on (SSO), and Duo Directory, its own identity provider, and it is built to protect every stage of the login journey, from enrollment to the help desk call. Okta's depth is in identity governance (IGA), privileged access management (PAM), and lifecycle provisioning at scale. That distinction matters more today because the role of IAM has changed. Organizations once compared authentication capabilities, integration options, and perhaps the user experience before making a decision. Today, the conversation looks very different. Identity has become the front line of cybersecurity . Every employee, contractor, application, managed device, cloud service, and increasingly, AI agent, represents another identity that needs to be verified an
Today's security leaders often find themselves stuck between a rock and a hard place: Active Directory (AD) continues to be a foundational legacy infrastructure (in fact, 90% of the Fortune 1000 still uses AD ) but inherent technical debt, visibility gaps, and an inability to extend MFA to these legacy authentication paths have created a serious security gap that enterprising threat actors are actively targeting. Cisco recently surveyed 28 CISOs from around the world to better understand their concerns about the AD security dilemma. The consensus is that it would be impractical to walk away from AD despite the inherent security risks—forcing them to implement new security strategies and controls that harden this legacy identity infrastructure. For a comprehensive dive into all our conversations, visit our CISO Perspectives homebase . Here's how security leaders are securing their legacy identity infrastructure for modern architectures. The 28 security and IT leaders surveyed
Security leaders at universities, colleges, technical schools, and local K-12 school districts all share a common goal: to make learning safe and enjoyable for students and teachers from any location, and any device. With ransomware attacks targeting education rising 23% year over year in 2025, security teams face a formidable set of challenges around securing identity. Identity and access management (IAM) for education is the practice of verifying and controlling access for large, fast-changing populations of students, faculty, and staff across campus, remote, and BYOD environments. The core challenges include: Keeping track of large, constantly changing user populations Protecting sensitive personal information like social security numbers, payment data, and medical records Rapid change as infrastructures evolve to support remote learning, BYOD, and cloud-based learning applications Increasing risk from AI-powered phishing and MFA fatigue attacks targeting credentials Whatever goals
Material Event filed 2026-08-26
In identity security, the hardest questions often sound simple. Who should have access? What should they be allowed to do? What happens when they change roles, leave the company, join as contractors, or create AI agents to act on their behalf? These questions are not new, but the speed, scale, and stakes around them have changed. To better capture how identity is shifting, Cisco Duo engaged third-party research firm AimPoint Group to interview more than two dozen CISOs and security executives across industries and company sizes. The final 2026 CISO Perspectives report shows how identity has become both a challenge and a potential change agent. Here are four key takeaways. Artificial Intelligence (AI) adoption has renewed urgency around identity and access management (IAM). Identity security is a top-three priority for most organizations ; AI-driven business questions run through security, and nearly every important security question now runs through identity. If you do not know who or
Quarterly Report filed 2026-08-13
Material Event filed 2026-08-12
I’m excited to announce that Duo Federal Edition FedRAMP High Class D certification is now generally available! This represents a significant milestone in our commitment to supporting U.S. Federal, State, and Local Government agencies with enterprise security solutions that meet strict compliance requirements. Cisco Duo Federal Edition High Class D is a FedRAMP High Class D (IL4) authorized instance of our authentication solution, purpose-built specifically for U.S. Government requirements and compliance standards. It’s a cloud-delivered multi-factor authentication solution grounded in zero trust principles that provides seamless, transparent, and phishing-resistant user access from both desktop and mobile devices to any application—whether internet-based, SaaS, or private applications hosted in the cloud or on-premises. Duo Federal Edition FedRAMP High Class D is built for the environments you actually operate in: Federal agencies handling mission-critical workloads Contractors suppor
Choosing the right authentication protocol depends on your applications, your user types, and the protocols supported by your identity provider. This article considers these three main factors, and others, explaining how modern organizations deploy protocols, their best use cases, and common security risks introduced during configuration. Most organizations use more than one protocol. Match each protocol to the right use case and manage them through a single identity platform, not to consolidate onto one standard. SAML remains widely deployed for enterprise single sign-on, with a market projected to grow through 2033. Use it for legacy applications and deployments that do not neatly communicate with newer protocols like OIDC. OIDC and OAuth 2.0 are built for modern and mobile applications. OIDC verifies who the user is. OAuth 2.0 governs what a third-party application can do with their account. If your stack is moving toward cloud-native architectures, these are the protocols that fit.
Most organizations have outgrown their identity infrastructure. The Identity Provider (IdP) configurations and directory services that worked five years ago were not designed for distributed workforces, hundreds of cloud applications, and machine identities that outnumber people. Here, we cover the principles of designing an identity architecture that keeps up. Explore Duo's approach to identity Legacy identity infrastructure creates security blind spots and operational drag that compound as organizations grow. Cloud-native IAM is not just cloud-hosted identity. It is an identity built for API-driven, distributed, continuously verified environments. Identity orchestration platforms coordinate authentication across multiple identity sources, devices, and risk signals to make dynamic access decisions. An identity management roadmap starts with consolidation and ends with continuous verification. Most organizations are somewhere in between. Most identity infrastructure was designed f
Microsoft’s Active Directory (AD) manages user identities for roughly 90% of Fortune 1000 companies . It controls who can log in, what they can access, and which security policies apply to every connected device. That reach is exactly why attackers treat it as a high-value target, and why security teams should develop strategies that adapt to emerging threats. Active Directory is involved in 9 out of 10 cyberattacks, according to the Semperis 2024 Ransomware Risk Report. Its centrality to enterprise identity makes it the highest-value target in most organizations. Traditional Active Directory hardening—static policies, periodic audits, perimeter firewalls—leaves gaps that attackers routinely exploit between review cycles. A modern Active Directory security strategy layers adaptive authentication, single sign-on, device trust, and continuous verification on top of existing directory infrastructure. Cloud directory services let organizations extend or replace on-premises directories with
Key Differentiators
Emerging Innovator
Duo Security is an emerging player bringing innovative solutions to the Security market.
Frequently Asked Questions
Estimated Visibility Trend (Beta)
Simulated 8-week rolling score
Based on estimated brand signals. Historical tracking coming soon.
Similar Brands
1Password
1Password is an enterprise password manager and secrets management platform enabling individuals, teams, and businesses to securely store, manage, and share credentials, credit cards, and sensitive in
Fortinet
Fortinet is a global leader in network security, providing enterprise firewalls, endpoint protection, network access control, and cloud security products under the FortiGate and Fortinet Security Fabr
Anduril Industries
Anduril Industries is a defense technology company building autonomous weapons systems, surveillance infrastructure, and AI-driven defense platforms for the US military and allied nations. Founded in
S2
S2 is an AI-powered security platform focused on vulnerability discovery and attack surface management for enterprise security teams. The company's platform combines automated scanning, AI-powered ana
Splunk
Splunk is a data platform for security and observability founded in 2003 in San Francisco, built on the idea that machine-generated data — logs, events, metrics, traces — contains the intelligence org
CrowdStrike
CrowdStrike is an AI-native cybersecurity company founded in 2011 by George Kurtz, Dmitri Alperovitch, and Gregg Marston and headquartered in Austin, Texas, that built the endpoint detection and respo
Compare Duo Security with Competitors
Side-by-side AI visibility scores, platform breakdown, and market position.
Claim This Profile
Are you from Duo Security? Claim your profile to see full AI mention excerpts, get weekly visibility change alerts, and optimize how AI systems describe your brand.
Claim Duo Security Profile →Track AI Visibility in Real Time
Monitor how ChatGPT, Gemini, Perplexity, and Claude mention Duo Security vs competitors. Get alerts when AI recommendations shift.
Start Free Tracking →