Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Phishing resistance, passkeys, and NHI governance in 2026


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: A widening gap between security perception and actual authentication hygiene is evident in a 2025 global survey of 18,000 employed adults across nine countries, according to Yubico. The practical lesson is that phishing resistance now spans human identity, digital identity, and emerging NHI trust models, not just password replacement, including 70% who say AI has made phishing more successful and 29% who still lack MFA on personal email.

NHIMG editorial — based on content published by Yubico: a 2026 outlook on phishing resistance, digital identity, and AI

By the numbers:

Questions worth separating out

Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?

A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel.

Q: When should organisations prioritise PKI over another MFA method?

A: Prioritise PKI when the business needs certificate-based trust for devices, secure email, document signing, or regulated communications.

Q: What do IAM teams get wrong about AI-driven identity security?

A: They often treat AI-driven features as a tooling upgrade rather than a governance shift.

Practitioner guidance

  • Expand phishing-resistant MFA coverage Move high-risk users and workflows to device-bound authentication first, then extend coverage to external collaboration and privileged access paths.
  • Create a cryptographic bill of materials for identity systems Inventory which identity platforms, authenticators, and trust services depend on algorithms that may require post-quantum updates.
  • Define assurance levels for digital identity workflows Set explicit policy thresholds for when passkeys, verifiable credentials, or stronger verification are required.

What's in the full article

Yubico's full post covers the operational detail this post intentionally leaves for the source:

  • Survey breakdown by country that shows how phishing perception and MFA adoption differ across regions.
  • The post’s discussion of post-quantum cryptography planning, including the cryptographic bill of materials approach.
  • More context on digital identity wallets and the enterprise use cases Yubico expects to expand in 2026.
  • Additional commentary on agentic AI, social engineering, and how leaders should raise the security bar.

👉 Read Yubico's 2026 outlook on phishing resistance, digital identity, and AI →

Phishing resistance, passkeys, and NHI governance in 2026?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Phishing resistance is no longer just a human IAM control, it is a trust architecture decision. AI has reduced the cost of deception, which means the security value shifts from spotting bad messages to proving legitimate identity at the point of access. That is why passkeys, verifiable credentials, and phishing-resistant MFA now matter as programme design choices, not only authentication features. The practical conclusion is that identity leaders must measure how much of their access model still depends on user judgment.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
  • Another finding in that research shows that 97% of NHIs carry excessive privileges, which widens the attack surface when trust is delegated across vendors and external systems.

A question worth separating out:

Q: Who is accountable when AI-assisted access workflows make the wrong trust decision?

A: Accountability stays with the organisation that defines the workflow and the access policy, even if the workflow uses AI or automation. If an agent or assistant can initiate actions, the programme must define the authority boundary, the approval point, and the evidence trail before the action is allowed to complete.

👉 Read our full editorial: Phishing resistance and NHI governance are converging in 2026



   
ReplyQuote
Share: