Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passwords, MFA, and passkeys: what authentication teams should fix now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19628
Topic starter  

TL;DR: Passwords and SMS-based authentication still dominate, while passkey awareness remains uneven and AI-driven phishing concerns are rising, according to Yubico’s 2025 Global State of Authentication survey of 18,000 employed adults across nine countries. The gap is not technical novelty but user education, inconsistent policy, and weak phishing-resistant coverage across work and personal accounts.

NHIMG editorial — based on content published by Yubico: 2025 Global State of Authentication survey

By the numbers:

Questions worth separating out

Q: How should organisations roll out passkeys without disrupting existing login flows?

A: Start by adding passkeys alongside current authentication methods, then use adoption and recovery data to decide when to reduce password dependence.

Q: Why does SMS-based MFA still create account takeover risk?

A: SMS creates risk because the factor travels through a channel that can be redirected through SIM swapping, message interception, or social engineering.

Q: What do security teams get wrong about MFA in identity attacks?

A: They often assume MFA ends the problem once the code is entered.

Practitioner guidance

  • Replace password-first access paths Make phishing-resistant MFA the default for all workforce and privileged applications, then remove password-only fallback where business risk justifies the change.
  • Eliminate weak second factors from critical workflows Phase out SMS-based authentication for accounts that can reach sensitive data, finance systems, or administrative consoles, and document every remaining exception.
  • Standardise authentication by risk tier Apply the same minimum authentication baseline across roles, countries, and device classes unless a formal exception is recorded and reviewed.

What's in the full report

Yubico's full report covers the operational detail this post intentionally leaves for the source:

  • Country-by-country breakdowns of MFA, passkey familiarity, and device-bound authentication adoption.
  • Survey methodology across 18,000 employed adults in nine countries, useful for benchmarking your own workforce data.
  • Comparisons between personal and work account behaviour that help separate consumer habits from enterprise controls.
  • Regional differences in concern about AI-driven phishing, which can inform awareness and training priorities.

👉 Read Yubico's 2025 Global State of Authentication survey findings →

Passwords, MFA, and passkeys: what authentication teams should fix now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19219
 

Passwords are no longer an acceptable strategic control for modern identity programmes: They remain common because they are familiar, not because they are secure. The survey shows that user confidence is still detached from authentication reality, which is exactly why password-heavy programmes continue to underperform. IAM teams should treat this as a governance failure, not a user preference issue.

Authentication modernisation is increasingly a governance programme, not a feature rollout. The organisations that will reduce account takeover most effectively are the ones that standardise phishing-resistant MFA, remove weak fallbacks, and treat role-based exceptions as temporary risk decisions rather than permanent access design. The pattern is clear in the 2026 Infrastructure Identity Survey, where 70% of organisations grant AI systems more access than they would give a human employee, which shows how quickly access policy drifts when governance is inconsistent.

A question worth separating out:

Q: Should organisations prioritise passkey adoption or remove SMS first?

A: Remove SMS first for high-value accounts, because it preserves a weak recovery and verification path even when stronger options exist. Then expand passkeys and hardware security keys as the default, since adoption works best when the insecure alternative is no longer the easy choice.

👉 Read our full editorial: Global authentication habits still favor passwords over passkeys



   
ReplyQuote
Share: