
Joseph Carson at Delinea explores how organisations can move beyond flawed password-based security and embrace a passwordless future
On average, 78% of people have to reset at least one of their passwords every 90 days. This frustration is widely felt, but imagine a world where the problem of forgotten passwords is a thing of the past. Well, in an era where cyber threats are ever-evolving, this vision is rapidly becoming a reality.
With cyber-attacks on the rise, traditional password systems are increasingly vulnerable. 30% of internet users have experienced a data breach due to a weak password. As we look to find more secure and user-friendly authentication methods, transitioning to a password-less environment is vital.
In this article we explore this transition, examining the critical role of alternative authentication methods and the importance of robust password policy management to boost security and compliance.
Traditional passwords have significant limitations in today’s landscape. Users frequently create weak passwords to ease memory burden, but this makes them easy targets for brute force attacks. Up to 65% of people use the same password for multiple accounts, increasing their vulnerability to attacks. Phishing is another major issue, with approximately 3.4 billion phishing emails sent each day in an attempt to trick users into revealing their passwords.
Beyond the passwords themselves, managing a large number of login details is cumbersome and can lead to insecure practices. Increasingly, passwords alone are becoming insufficient for a secure environment. Multi-factor authentication (MFA) is crucial, but what other methods can we use?
One-Time Passwords (OTPs) are common in processes like financial checks. OTPs provide a temporary, single-use code for authentication, enhancing security by generating a unique password for each login session or transaction. As OTPs are typically valid for just a short period, usually only a few minutes, they are much more secure than static passwords, especially for sensitive data.
Magic Links offer a seamless, user-friendly authentication experience. After entering their username, users receive a confirmation URL via text or email to access the secure site again typically timed based so they cannot be reused later.
The appeal of Temporary Keys lies in their ability to grant exclusive access to a single user for a specific duration, increasing security by limiting the validity of access credentials and ensuring accountability for each use of privileged access.
Transitioning from traditional passwords is crucial, but adherence to regulations and compliance standards is just as important. As the technological environment evolves, laws and policies must keep pace.
Automatic password rotations help businesses meet compliance requirements outlined in regulations like PCI-DSS, HIPAA, and SOX, which often mandate regular password changes to maintain security. Understanding regulatory compliance is part of the challenge, which is why businesses often benefit from partnerships with security specialists.
Using servers that enable automatic password rotations according to a predefined schedule ensures continuous compliance without manual intervention. Detailed reporting on automated management solutions also streamlines audits, allowing organisations to demonstrate their compliance with ease.
Pass-The-Hash (PtH) attacks involve attackers stealing password hashes to authenticate without the actual plaintext password. These attacks exploit how Windows credential stores and uses password hashes, allowing attackers to move laterally through a network and escalate privileges.
But regular password rotations invalidate existing password hashes. When a password is changed, a new hash is generated, making the previously stolen hash obsolete. This therefore significantly reduces the window of opportunity for attackers to use stolen hashes, disrupting their ability to move through the network and cause further damage.
A holistic security approach is essential for continued protection. By integrating alternative authentication methods with strong password policy management, organisations can develop a robust security posture, with multi-factor authentication adding an extra layer of protection against attackers. Additionally, educating employees and training staff on new authentication methods and security practices created long-term attack prevention.
As cyber threats continue to evolve, so must our approach to security. Transitioning to a password-less environment is not just a trend but a necessary step towards a safer and more user-friendly digital future.
By adopting alternative authentication methods like one-time passwords, Magic Links, temporary keys, and just-in-time access, organisations can significantly enhance their security posture. Coupled with automatic password policy management and regular rotations, these strategies help meet regulatory standards and mitigate threats like Pass-The-Hash attacks.
Now is the time for organisations to embrace these innovations, ensuring protection against ever-present cyber-threats while paving the way for a more secure digital world.
Joseph Carson is Chief Security Scientist and Advisory CISO at Delinea
Main image courtesy of iStockPhoto.com and Bussarin Rinchumrus
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543