TL;DR: Governments are increasingly pushing phishing-resistant authentication such as WebAuthn, FIDO and passkeys, according to Yubico, but the harder problem is now identity lifecycle control: onboarding and recovery can become the weakest links when attackers exploit fake identities and weak verification. Strong authentication does not fix bad identity proofing.
NHIMG editorial — based on content published by Yubico: an interview with acting CEO Jerrod Chong on passwordless authentication and identity lifecycle risk
By the numbers:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: How should organisations implement passwordless IAM without weakening recovery controls?
A: Treat passwordless as an assurance program, not a user-experience feature.
Q: Why do phishing-resistant authenticators still leave organisations exposed?
A: Because authentication strength does not prove the identity was legitimate at enrolment.
Q: What do security teams get wrong about passwordless authentication?
A: The most common mistake is treating passwordless as a user-experience upgrade instead of an identity control change.
Practitioner guidance
- Strengthen enrolment assurance Require identity proofing steps that match the sensitivity of the account being issued, and do not let convenience-driven onboarding bypass verification thresholds.
- Review recovery workflows Map every account recovery path, including support desk resets and fallback factors, to confirm that each route carries the same assurance expectations as primary sign-in.
- Add lifecycle checks to IAM governance Include onboarding, recovery, and re-verification events in access review and recertification workflows so that identity legitimacy is re-checked over time.
What's in the full article
Yubico's full interview covers the operational detail this post intentionally leaves for the source:
- Jerrod Chong's perspective on why onboarding and account recovery are now the weakest links in the identity lifecycle.
- The article's discussion of generative and agentic AI-powered phishing as an emerging pressure on identity assurance.
- Yubico's view on how passkey adoption changes the security conversation from password removal to identity trust design.
- Personal background and leadership discussion that frames the interview beyond the security analysis.
👉 Read Yubico's interview on passwordless authentication and identity lifecycle risk →
Passwordless authentication: are onboarding and recovery keeping up?
Explore further
Identity assurance is now a lifecycle problem, not just an authentication problem. Passwordless methods remove password theft from the attack path, but they do not remove the need to verify who is being enrolled or recovered. The governance mistake is assuming that stronger login factors automatically make the whole identity process trustworthy. Practitioners need to separate authentication strength from identity legitimacy.
A few things that frame the scale:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how often identity governance is operating without complete inventory.
A question worth separating out:
Q: Which frameworks should govern onboarding and recovery controls?
A: Human identity programmes should align onboarding and recovery with NIST SP 800-63 guidance, Zero Trust principles, and internal lifecycle governance. The goal is to ensure identity proofing, authentication, and recovery are all governed as part of one trust model, not separate operational steps.
👉 Read our full editorial: Passwordless authentication is pushing identity lifecycle controls