TL;DR: Despite 92% of organisations implementing passwordless, only 7% are fully passwordless, according to RSA Security, suggesting the blocker is not technology maturity but how teams interpret identity telemetry and recovery friction. The real gap is operational: organisations measure events, but too rarely interrogate where trust breaks and why.
Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “You Don’t Have an Identity Data Problem. You Have a Question Problem.”.
By the numbers:
- 92% of organisations are implementing passwordless, but only 7% have gone completely passwordless.
- RSA Security reached 94% passwordless adoption across its global workforce in 12 months.
Key questions
Q: What breaks when passwordless is rolled out to only part of an application estate?
A: Users and support teams end up operating under two authentication models at once.
Q: Why do passwordless programmes fail even when the technology is secure?
A: They fail when the user journey is fragmented.
Practitioner guidance
- Audit the gap between deployed and usable passwordless coverage Compare where passwordless is enabled against where users can actually complete the secure journey without workarounds.
- Treat recovery flows as part of the authentication control surface Map every recovery and account access path that is easier than login, including help desk resets, alternate verification methods, and fallback approvals.
- Interrogate telemetry for trust breaks, not just event volume Move beyond counts of successful logins and failed attempts.
Bottom line: Passwordless adoption can stall even when the technology is deployed broadly, because users still encounter workflows that push them back to passwords.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
The passwordless gap is really a question-design gap. The article’s core point is that identity data already exists in most enterprises, but teams ask reporting questions instead of operational questions. That means they see deployment status, not trust failure. The practitioner lesson is that programme maturity depends on interrogating the journey, not merely counting enabled users.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: How do you know if passwordless is actually working?
A: You know it is working when users can complete every common access and recovery journey without reverting to passwords. Look for consistent success across devices, locations, and applications, and check whether support tickets or fallback usage are declining. If recovery is still easier than login, passwordless is only partially working.
👉 Read our full editorial: Passwordless adoption reveals a question problem, not a data one
The passwordless gap is really a question-design gap. The article’s core point is that identity data already exists in most enterprises, but teams ask reporting questions instead of operational questions. That means they see deployment status, not trust failure. The practitioner lesson is that programme maturity depends on interrogating the journey, not merely counting enabled users.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: How do you know if passwordless is actually working?
A: You know it is working when users can complete every common access and recovery journey without reverting to passwords. Look for consistent success across devices, locations, and applications, and check whether support tickets or fallback usage are declining. If recovery is still easier than login, passwordless is only partially working.
👉 Read our full editorial: Passwordless adoption reveals a question problem, not a data one
Passwordless adoption is now a telemetry interrogation problem, not a deployment problem. RSA Security's numbers show that implementation and completion are not the same outcome, which means the governance failure sits in how organisations read their own signals. Most teams can prove the control exists, but far fewer can prove it is being used as intended. The practitioner conclusion is simple: operational evidence has to replace checkbox coverage as the measure of progress.
A question worth separating out:
Q: How do teams know whether identity-first passwordless is actually working?
A: They should look for complete coverage across users, devices, and machine interactions, plus measurable reduction in unmanaged exceptions. If the organisation still relies on ad hoc approvals, manual certificate handling, or unsupported identity types, the programme is only partially working.
👉 Read our full editorial: Passwordless adoption reveals a question problem, not a data one