Join our Newsletter — 33% off our NHI Course

Passwordless adoption and the credential gap teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Poor password hygiene remains widespread, with 66% of employees reporting risky password behaviour and 89% of security and IT professionals saying their company is pushing passkeys, according to 1Password's Annual Report 2025 analysis. The governance challenge is not whether passwordless will arrive, but whether teams can reduce raw credential exposure while it is still partial and uneven.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Password habits are worsening, but security leaders see a path to passwordless”.

By the numbers:

  • 66% of employees report having poor password hygiene, including default passwords and password reuse.
  • 44% of CISOs report that employees using weak or compromised passwords is one of their top security challenges.
  • 89% of security and IT professionals say their company is encouraging employees to shift logins to passkeys.

Key questions

Q: What is the biggest failure mode in passwordless onboarding?

A: The biggest failure mode is treating the first credential as harmless because it is temporary.

Q: Why do passwordless programmes still need MFA and step-up authentication?

A: Passwordless removes the password, not the need to verify identity under higher-risk conditions.

Q: What signs show that passwordless controls are not yet reducing risk?

A: The warning signs are weak-password pockets, repeated fallback logins, inconsistent adoption across business units, and continued manual handling of passwords for shared or legacy access.

Practitioner guidance

  • Map the remaining credential surface Inventory where passwords still exist across users, recovery flows, shared accounts, and legacy applications so you can see what passwordless has not yet removed.
  • Treat fallback paths as governed exceptions Document password recovery, shared access, and legacy login exceptions with ownership, expiry, and review so the transition state does not become permanent.
  • Keep MFA on all residual password flows Require multifactor authentication wherever passwords remain in use, including fallback and administrative access, so residual credentials do not become easy takeover paths.

Bottom line: Passwordless adoption reduces one category of exposure, but it does not eliminate credential risk while passwords and fallback flows still exist.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Passwordless adoption is an access-governance transition, not an authentication finish line. The article makes clear that organisations can push passkeys while still living with password reuse, fallback credentials, and uneven adoption. That means the programme question is not whether passwordless exists, but how much raw credential exposure remains during the transition. Practitioners should judge maturity by reduction in handling, not by enrollment headlines.

A few things that frame the scale:

A question worth separating out:

Q: How should teams govern access when some users have passkeys and others still rely on passwords?

A: Teams should govern the transition as a lifecycle issue, with explicit ownership for exceptions, recovery methods, offboarding, and review of any remaining passwords. The goal is to control the mixed state until passwordless becomes the default, not to treat coexistence as an end state.

👉 Read our full editorial: Passwordless access still leaves credential risk wide open


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.