TL;DR: Human error still drives a large share of breaches, with IBM cited in the source article saying 90% of successful cyberattacks and 70% of data breaches originate at endpoint devices. Imprivata’s argument is that passwordless authentication, single sign-on, and automated credential rotation reduce risky workarounds by removing friction rather than relying on better user discipline.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “As Employees Remain the Weakest Link, Experts Say It’s Time to Eliminate Passwords”.
By the numbers:
- 90% of successful cyberattacks and 70% of data breaches originate at endpoint devices, according to IBM's Cost of a Data Breach Report cited by Imprivata.
Key questions
Q: How should IAM teams reduce password-related productivity loss?
A: They should start by measuring where password failures interrupt work most often, then redesign the highest-friction journeys first.
Q: When does password-based MFA create more risk than it removes?
A: It creates more risk when users can be tricked into approving prompts, when OTPs travel through interceptable channels, or when fallback recovery paths are weak.
Q: What are the signs that password-only authentication is failing in practice?
A: Password-only authentication is failing when a valid password is enough to grant access from an unusual place, device, or time without any additional checks.
Practitioner guidance
- Prioritise passwordless access for high-friction roles Target roles that operate across shared devices, shift work and time-sensitive workflows, where repeated password entry is most likely to trigger unsafe shortcuts.
- Reduce dependence on shared secrets Replace reusable passwords with stronger authentication paths and limit the number of places where users must manage separate credentials.
- Automate credential rotation where shared access persists Use rotation for credentials that cannot yet be eliminated, especially in environments where shared terminals or applications make manual discipline unreliable.
Bottom line: Human error becomes more dangerous when access design forces employees into workarounds that normal policy cannot absorb.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Password friction is a governance defect when the control assumes ideal user behaviour. The article is right to frame human error as a systems issue rather than a training issue. If an access model only works when employees are never rushed, never interrupted and never juggling multiple shared endpoints, it is not a durable control model. Practitioners should read password fatigue as evidence that the control boundary is misplaced.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: Should organisations prioritise passwordless access before automating credential rotation?
A: Yes, when user friction is driving unsafe behaviour. Rotation helps reduce the lifetime of exposed credentials, but it does not remove the basic pressure that causes reuse, shared logins or session persistence. Passwordless access addresses the root cause in the user experience, while rotation strengthens the back-end governance of remaining secrets.
👉 Read our full editorial: Passwords, user friction and human IAM risk in fast-paced environments