
Paul Inglis at Ping Identity explores the latest password guidance and explains how habits can be improved while the shift to passwordless steadily gathers pace
Passwords were once an effective lock-and-key to people’s information. However, unlike other innovations, they haven’t evolved to meet today’s digital demands. As the internet expanded and the number of online accounts grew, passwords quickly became more of a liability than a reliable safeguard, earning them a reputation as a legacy authenticator.
Today, passwords pose a persistent threat to both individuals and organisations. It doesn’t take hackers long to crack passwords, allowing them an easy gateway to credentials, accounts and money. Major tech companies, like Amazon, have awoken to the ineffectiveness of passwords in today’s threat landscape and introduced alternative authentication in the form of passkeys.
Despite these efforts, fresh guidance from the US National Institute of Standards and Technology (NIST) indicates it will be a while until we realistically transition to passwordless systems.
The NIST guidance sheds light on the challenges associated with complex passwords. Most people either reuse passwords, add predictable elements to meet complexity requirements or worse, write them down – actions that undermine security.
Therefore, the updated framework also serves as a reminder that passwords are leaving networks of organisations open to an array of attacks and change is necessary. While they remain part of our lives, improving password habits and gradually adopting passwordless systems is the only way to reduce the risk of compromise.
Looking at some of the most recent cyberattacks, passwords are a constant point of vulnerability. For example, passwords belonging to nearly 600 Ministry of Defence personnel were stolen and leaked on the dark web and the largest ever discovered breach, dubbed RockYou2024, saw almost 10 billion unique passwords extracted. These events reveal how deeply ingrained poor password habits are and the scale of the issue.
Compounding this is the tendency for individuals to reuse passwords across multiple accounts, multiplying their exposure in the event of a breach.
The psychological toll of password management, often referred to as "password fatigue," further complicates the problem. Users juggling numerous accounts feel overwhelmed, leading to shortcuts like reusing passwords or neglecting updates. This fatigue, combined with the increasing sophistication of cybercriminals, makes it clear that passwords are no longer sufficient.
Users’ frustrations with passwords are also driving demand for alternative authentication methods. Although security tops the list of concerns for 78% of users when interacting with online brands, ease of use comes in at a close second for 76%. Consumers want seamless online experiences, whether making purchases or booking appointments, without compromising security.
This has led to growing interest in methods such as biometrics, where users authenticate themselves through ‘something they are’, like a fingerprint or face ID, as opposed to ‘something they know’, like a password or a first pet’s name. This resonates with the updated NIST guidance also, urging for the discontinuation of password hints and other knowledge-based recovery methods that can so easily be surpassed by hackers using people’s personal information posted online.
What online users are revealing in research is that they’re much more open to a series of other authentication methods which meet expectations for the new digital experience. 47% of consumers are reassured by text-email prompts like one-time logins, while 46% are open to using multi-factor authentication, and 40% biometrics, all of which make them feel more in control of their log-in experience without detracting from the ease of use.
This interest indicates that adopters of authentication methods will stand apart from non-adopters by achieving a desirable end-to-end experience.
Passwordless authentication tools appease both the appetite for security and seamlessness due to the lack of a crackable code and more efficient access due to biometrics. As there’s no need to allocate budget for password management or storage solutions, passwordless ultimately works out a cheaper option as well.
While the full transition will take time from both a B2B and B2C perspective, our research indicates that users will welcome passwordless authentication. In fact, 65% of survey respondents said if passwordless authentication was offered, they’d be happy to switch. This comes as most (97%) have concerns about their personal data being online and over a third (36%) have already fallen victim to identity fraud.
Those fears are manifesting themselves into greater acceptance of change and a move away from poor password habits that have so long been engrained in us. And with big tech acting as the first domino, more will begin to adopt passwordless authentication over time.
There are steps individuals and organisations can take now to strengthen online security. NIST’s standards emphasise password length over complexity, a practice that organisations should encourage among employees and customers. Offering tools to generate strong passwords and implementing multi-factor authentication can further bolster defences while transitioning to passwordless systems.
Ultimately, passwords remain the weak link in a digital world plagued by fraud. However, with guidance from NIST and initiatives from the private sector, we can accelerate the shift to passwordless authentication. This transition promises not only greater security but also the seamless digital experiences users increasingly demand.
By educating organisations and individuals about the benefits of ultra-secure authentication methods, we can take significant steps toward a safer online future.
Paul Inglis is Senior Vice President and General Manager, EMEA at Ping Identity
Main image courtesy of iStockPhoto.com and maselkoo99
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543