PASSKEYS
no shared secret to steal or phish. The NCSC’s new technical report confirms that passkeys are “at least as secure as, and generally more secure than, pairing the strongest password with two-step verification.” Critically, the NCSC found that passkeys are highly resistant to phishing attacks and cannot be intercepted, reused or guessed in the way that passwords can. They also dramatically improve the user experience. Passkey logins can be completed significantly faster than the traditional username, password and verification code workflow. This removes the traditional trade-off between security and convenience. Raising the Cyber Essentials baseline The growing adoption of passkeys also aligns closely with frameworks like Cyber Essentials, which place increasing emphasis on access control, authentication integrity and protection against common attack techniques. While passkeys are not currently mandated within the certification itself, they directly support many of its underlying security principles by reducing organisational exposure to credential theft and account compromise. For organisations pursuing Cyber Essentials or Cyber Essentials Plus, identity security is becoming increasingly crucial as threat actors continue to target authentication layers rather than attempting to breach infrastructure directly. Traditional password policies and MFA remain important controls, but they still rely heavily on user behaviour and can be undermined through phishing or credential reuse. Many organisations still treat MFA as the end goal for identity security, when in reality attackers have already adapted their tactics around it. Security teams are therefore placing greater emphasis on limiting exposure to authentication methods vulnerable to credential compromise and social engineering.
This becomes particularly significant within hybrid and cloud-centric environments, where identities increasingly act as the gateway to critical systems and applications. In these environments, passkeys offer a more phishing-resistant authentication model that strengthens cyber resilience while supporting a more mature and forward-looking approach to governance and identity assurance.
“
For organisations serious about cyber resilience, moving beyond passwords is rapidly becoming a strategic priority, one that compliance pressures and the growing frequency of credential- based attacks are only accelerating.
The end of the password era Passwords are unlikely to disappear entirely overnight, particularly as many organisations continue to operate legacy systems and mixed authentication environments. However, the direction of travel is becoming increasingly clear. As identity-based attacks continue to rise and phishing techniques become more sophisticated, organisations are being forced to reconsider whether traditional passwords remain fit for purpose as a primary security control. Passkeys reflect a wider shift towards phishing-resistant authentication and a more resilient security posture built around today's threat landscape. For organisations serious about cyber resilience, moving beyond passwords is rapidly becoming a strategic priority, one that compliance pressures and the growing frequency of credential-based attacks are only accelerating. n
”
www.newsinthechannel.co.uk
49
Powered by FlippingBook