PASSKEYS
Beyond passwords Martin Wegrostek, cyber security portfolio manager at managed IT specialist OryxAlign, explains why passkeys are becoming essential for modern cybersecurity for businesses.
For years, passwords have been treated as the first line of defence in cybersecurity. Yet despite increasingly complex password policies and multi- factor authentication (MFA) requirements, password-related breaches continue to dominate the threat landscape, with phishing and stolen credentials remaining common attack methods. As a result, the conversation around digital identity is changing, with the UK’s National Cyber Security Centre (NCSC) encouraging organisations to move towards passkeys as the future of authentication. According to Microsoft’s Digital Defense Report 2024 , cyberattacks have increased to approximately 7,000 password attacks per second, while identity-based cyberattacks now account for nearly 80% of breaches. The figures highlight how cybercriminals continue to exploit weak, stolen and reused credentials as one of the easiest ways to gain access to corporate systems.
As organisations look for more phishing- resistant alternatives to traditional passwords, passkeys are increasingly emerging as a practical solution. As the NCSC explains, passkeys “only require user approval rather than needing to input a password”, making them “quicker and easier to use and harder for cyber attackers to compromise”. As a result, passkeys are increasingly being viewed as an important step towards strengthening identity protection and reducing password-related risk. No password, no problem A passkey is a cryptographic credential tied to a specific device and verified through something the user already does naturally: a fingerprint scan, a face recognition check or a device PIN. When a user authenticates with a passkey, a private key stored securely on their device signs a challenge from the server, without that key ever leaving the device. There is
Martin Wegrostek
oryxalign.com
“
...cyberattacks have increased to approximately 7,000 password attacks per second, while identity-based cyberattacks now account for nearly 80% of breaches.
”
48
Powered by FlippingBook