Skip to content
  1. Home
  2. Cyber Defense
Cyber Defense

What actually breaks when an organisation goes passwordless

Enrolment goes fine. Account recovery, shared devices and the contractor who lost a phone are the real project.

What actually breaks when an organisation goes passwordless
What actually breaks when an organisation goes passwordless — XENVORA Photograph: U.S. Customs Border Protection operations, Rawpixel (CC0) · Licence

Three organisations shared their rollout data with us. In all three, more than 90% of staff enrolled without a support ticket, and every serious problem showed up afterwards.

Recovery is the whole difficulty

A password can be reset by someone who knows a secret. A passkey has to be re-established by proving identity through another channel, and most help desks were not built for that.

Shared workstations were the second surprise: nurses, warehouse staff and lab technicians rotate through machines in ways that passkey UX rarely anticipates.

Passwordless does not remove the recovery problem. It concentrates it.

All three organisations kept a break-glass path. All three said keeping it was the decision that made the rollout survivable.

Yara Khalidi
Security Desk
Yara Khalidi

Yara covers privacy engineering, incident response and the policy fights that follow every breach.

Reader comments 0 comments

Sign in to comment.

No comments yet. Be the first.