Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passkey adoption and phishing resistance: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Organisations face evolving AI-driven phishing pressure as passwordless authentication becomes more available, according to Yubico’s 2025 Global State of Authentication survey, which draws on responses from 18,000 employed adults and pairs that data with updates on device-bound passkeys, PIN enhancements, and expanded delivery options. The bigger issue is not whether passwordless authentication is available, but whether identity programmes can make phishing-resistant access usable, deployable, and governable at scale.

NHIMG editorial — based on content published by Yubico: 2025 authentication updates, survey findings, and upcoming event sessions

By the numbers:

Questions worth separating out

Q: How should organisations roll out passkeys without disrupting existing login flows?

A: Start by adding passkeys alongside current authentication methods, then use adoption and recovery data to decide when to reduce password dependence.

Q: Why do passkeys improve security but not eliminate identity risk?

A: Passkeys remove the shared secret that attackers usually steal, guess, or phish, which is a major improvement.

Q: What should IAM teams measure when moving to passwordless authentication?

A: Measure how much access still depends on replayable credentials, how many high-risk flows remain on OTPs, and whether the enrolled devices can be revoked and recovered cleanly.

Practitioner guidance

  • Assess passkey readiness by user population and recovery path Map which employee groups can move to device-bound passkeys now, which need transitional support, and where recovery would fall back to weaker controls.
  • Define assurance requirements before broad rollout Decide what enrollment proof, device binding, and fallback conditions are acceptable before passkeys are made the default login method.
  • Track authenticator lifecycle operationally Inventory issuance, replacement, decommissioning, and support turnaround so authentication availability does not degrade as the programme scales.

What's in the full article

Yubico's full update covers the operational detail this post intentionally leaves for the source:

  • Survey breakdowns from 18,000 employed adults that can support internal awareness or executive messaging.
  • Specific passkey usability and PIN enhancements that shape deployment planning.
  • Global delivery and subscription coverage details for teams managing distributed authenticator rollout.
  • Session-by-session event listings for practitioners who want the implementation discussion directly.

👉 Read Yubico's authentication survey and passkey update for 2025 →

Passkey adoption and phishing resistance: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Phishing-resistant authentication only works when it is operationally reachable. The strongest authentication model still fails if users cannot get a usable authenticator when and where they need one. That is why delivery coverage, enrollment support, and recovery design matter as much as cryptographic assurance. For IAM teams, the real control question is whether the authentication method can survive enterprise scale without turning into a bottleneck.

A few things that frame the scale:

A question worth separating out:

Q: How do security teams keep phishing resistance consistent across global locations?

A: Standardise enrollment, replacement, and support rules across regions, then validate whether local delivery and recovery processes match policy. Global consistency matters because authentication assurance breaks down when issuance and support vary by geography or business unit.

👉 Read our full editorial: Passkeys, phishing resistance, and authentication trends in 2025



   
ReplyQuote
Share: