Join our Newsletter — 33% off our NHI Course

Passwordless authentication and phishing resistance: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: 2023 breach patterns kept converging on stolen credentials, password reuse, and MFA bypass, while the average cost of a breach reached $4.5 million, according to IBM and Apple cited by Axiad. Passwordless, phishing-resistant authentication is no longer an edge case; it is the baseline control families now need to close.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Top Data Breaches in 2023 and Why Organizations Need Passwordless, Phishing-Resistant Authentication”.

By the numbers:

  • The average cost of a data breach was $4.5 million in 2023, according to IBM research cited by Axiad.
  • Data breaches were up by 20% over 2022 in the first nine months of 2023, according to Apple research cited by Axiad.

Key questions

Q: What breaks when organisations rely on passwords and basic MFA to stop account takeover in identity verification flows?

A: Passwords and basic MFA break down when attackers already possess personal data or can intercept one-time codes.

Q: Why do password reuse and credential stuffing remain so effective?

A: They remain effective because many users still reuse passwords and many environments still accept credentials without enough contextual risk checks.

Q: How can security teams tell whether passwordless is actually safer?

A: Look for consistency, not just adoption.

Practitioner guidance

  • Prioritise phishing-resistant authentication for high-risk users Move privileged admins, support personnel, and high-value customer accounts to FIDO or certificate-based authentication before broad rollout.
  • Remove shared-secret fallback paths Map every recovery, reset, and help-desk flow that can restore access without a phishing-resistant factor.
  • Separate genuine passwordless from hidden-password designs Review whether your passwordless stack still stores, recovers, or indirectly depends on a backend secret.

Bottom line: Passwords, reused credentials, and weak MFA remained recurring breach paths in 2023, so authentication design is still a primary control gap.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Password-based authentication has become a breach multiplier, not a control boundary. When breach patterns keep converging on stolen credentials, password reuse, and basic MFA bypass, the issue is no longer user discipline alone. The control assumption that a shared secret can still anchor trust has collapsed, and identity programmes have to treat that collapse as a design problem, not a training problem.

A few things that frame the scale:

  • Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.

A question worth separating out:

Q: What is the difference between adaptive authentication and phishing-resistant MFA?

A: Adaptive authentication changes the challenge based on risk signals such as device, location, or behaviour. Phishing-resistant MFA changes the quality of the factor itself so stolen secrets are harder to reuse. The two controls solve different problems and work best together for regulated identity flows.

👉 Read our full editorial: Passwordless authentication is the real control gap in 2023 breaches


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.