TL;DR: Password-based authentication remains costly and risky, with the average employee managing 190+ passwords, over 40% of help desk calls tied to password issues, and more than 80% of data breaches linked to password problems, according to Axiad. The real issue is not convenience alone: password-centric IAM still depends on weak, reusable, and stealable secrets.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “This Password Day, we think you deserve better.”.
Key questions
A: Security teams should treat passwordless as the authentication layer, not the proofing layer.
Q: Why do passwords create so much help desk demand?
A: Because they fail in predictable ways: people forget them, reuse them, lock themselves out, or need resets after expiry.
Q: What signals show that passwordless adoption is actually working?
A: Look for fewer password resets, fewer help desk unlock requests, lower use of workarounds, and stable clinician throughput during login-heavy periods.
Practitioner guidance
- Replace password-centric login paths Prioritise passwordless methods for high-volume employee authentication flows where resets, reuse, and phishing exposure are driving measurable risk.
- Track help desk dependency as a control signal Measure password-related tickets, lockouts, and one-time password requests as a proxy for authentication design failure, not just support demand.
- Extend passwordless scope beyond workforce login Map which devices, servers, applications, IoT devices, and signed communications still rely on passwords or other long-lived secrets.
Bottom line: Passwordless authentication is valuable because it reduces dependence on reusable secrets that create both breach risk and recurring support work.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless authentication is an identity-risk control, not a convenience feature. The article shows that the real problem is not only user friction but the security model built around reusable secrets. When the authentication factor is something humans must remember and re-enter, the organisation inherits phishing exposure, reuse pressure, and recovery complexity. Practitioners should treat passwordless as a way to shrink the attack surface of identity itself.
A question worth separating out:
Q: What should security teams do when passwordless is only covering user logins?
A: Expand the design review to include devices, servers, applications, and secure communications, because attackers often pivot through whatever still depends on a long-lived secret. A narrow rollout may improve one login flow while leaving the rest of the identity estate exposed.
👉 Read our full editorial: Passwordless authentication reduces identity risk and help desk load