Home Technology Security Firms confident in identity security despite failures

Firms confident in identity security despite failures

While most organisations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third report experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise. 

This is according to a report from the FIDO Alliance and HID, which is based on a survey of  500 IT and cybersecurity decision-makers across the United States, Canada, the United Kingdom, France, and Germany.

Findings show that while confidence is high, so are security incidents. Among organisations, 94% claim confidence that all physical and logical access can be revoked within 24 hours of an employee leaving.

Yet, 35% experienced delays or failures doing exactly that in the past two years — and 70% experienced at least one identity-related security incident overall.

Also, governance is fragmented. Only 50% of enterprises have unified reporting ownership for physical and digital identity, and just 48% have consolidated budget control.

Finance is the most governance-fragmented sector, with 34% operating fully separate reporting structures despite operating under stringent regulatory access-control obligations.

Further, complexity is growing and enterprises manage three separate systems on average. Among enterprises, 59% manage three or more distinct credential and authentication systems, and 58% say managing digital identity has become more complex over the past two years.

The public sector carries the highest incident rate of any industry. It has the highest identity security incident rate of any industry, with 43% experiencing access revocation failures.

The sector has a 20% manual credential revocation rate, which is more than double the IT/Technology sector.

The report says that the passkey adoption must scale to protect businesses as 93% are at some stage of passkey adoption and 65% report high or expert technical familiarity.

However, only 13% have deployed passkeys at scale, explaining why organisations experience such high levels of security incidents.

Phishing-resistant authentication is a top business priority. The leading driver for moving to passwordless authentication is reducing phishing and credential-based breach risk (45%), followed by reducing IT costs from password resets and help desk load (44%).

“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organisations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. 

Shikiar said that phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organisation that are already protected.

Sean Dyon, VP of the authentication business unit at HID, said that as organisations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. 

“This research shows that fragmented governance, disconnected systems and limited visibility create real business risk,” said Dyon.

- Advertisement -