What is a passkey, and should your business ditch passwords?
A passkey is a passwordless login that replaces your password with your device's fingerprint, face or PIN, making sign-in both simpler and far harder to hack. Instead of typing something you can forget, reuse or have stolen, you prove who you are with the device already in your hand. For businesses tired of password resets and phishing scares, that's a genuinely different way of working, and it's arriving faster than most people realise.
Stolen credentials were behind more than 1 in 5 confirmed breaches in Verizon's 2025 Data Breach Investigations Report, and they featured in a striking 88% of attacks on web applications. Passwords, in other words, are still the single easiest door for an attacker to walk through. Passkeys close that door. Here's how they work, and how to judge whether your business is ready to switch.
What is a passkey?
A passkey is a digital credential that lets you sign in to an app or website without a password. It's built on the FIDO and WebAuthn standards developed by the FIDO Alliance, an industry body whose standards are supported across all the major platforms, so passkeys work consistently from device to device.
When you create a passkey, your device generates a pair of cryptographic keys. One (the public key) is stored by the website or service. The other (the private key) never leaves your device and can only be unlocked by you, using the same biometrics or PIN you already use to unlock your phone or laptop. There's no secret to type, and nothing for an attacker to steal in a data breach.
Adoption has moved from novelty to mainstream quickly. The FIDO Alliance reported around 5 billion passkeys in use worldwide in 2026, with 68% of organisations having deployed or actively deploying passkeys for employee sign-ins.
How do passkeys work?
The clever part is that the two keys are useless without each other, and only one of them ever leaves your device.
When you sign in, the website sends your device a challenge. Your device signs that challenge with the private key, but only after you approve it with your fingerprint, face or PIN. The website checks the signature against the public key it holds, and lets you in. The private key itself is never transmitted, so there's nothing to intercept.
Because the passkey is tied to the specific website it was created for, it also won't work on a fake lookalike site. That's what makes passkeys phishing-resistant: even a convincing scam page can't trick your device into handing over a credential, because there's no credential to hand over. Passkeys can also sync securely across your own devices, so a new phone doesn't mean starting from scratch, and for a business this is best handled through a managed credential manager, which keeps sign-in consistent and recoverable across your team.
Passkeys v passwords
The difference comes down to what's actually stored and where.
A password is a shared secret: you know it, and the service stores a version of it. That means it can be guessed, reused across accounts, stolen in a breach, or phished out of a busy employee. A passkey is never shared. The private half stays locked on your device, so there's nothing for an attacker to steal in bulk and nothing to trick out of your staff.
The practical gap shows up in everyday use, too. FIDO's research put passkey login success at roughly 93%, against about 63% for traditional passwords, largely because people don't get locked out or fumble resets. For a business, every failed login and every reset is lost time and, often, a support ticket.
The benefits for your business
The headline benefit is security. Passkeys are resistant to phishing, credential stuffing and password reuse, which between them account for a large share of the breaches the NCSC and others track each year. Take the password away and you remove the attacker's favourite entry point.
The second benefit is productivity and cost. Password resets are one of the most common IT support requests in any organisation. Passkeys largely remove them, freeing your helpdesk and getting staff back to work faster. Sign-in is quicker, too: a glance or a fingerprint rather than a remembered string of characters.
There's a compliance angle as well. Frameworks such as Cyber Essentials and the NCSC's guidance increasingly favour strong, phishing-resistant authentication. Passkeys help you demonstrate that you're taking access security seriously. For businesses running across multiple sites, they also travel well: a member of staff can sign in securely from any location without juggling VPN passwords or worrying about which site they're logging in from.
The limitations and what to watch for
Passkeys are not quite a finished story, and it's worth going in clear-eyed.
Not every application supports them yet, so for a while you'll be running passkeys alongside passwords and multi-factor authentication rather than instead of them. Legacy and line-of-business systems are the most common sticking point, and FIDO's own research names legacy compatibility (38%) and budget approval (35%) as the top barriers organisations report.
Device recovery is the other thing to plan for. If a passkey lives on a device and that device is lost, staff need a reliable, secure way to get back in. This is exactly what a managed credential manager is for: it syncs credentials securely across a user's devices and gives you a proper recovery process, rather than leaving it to chance. And because passkeys lean on biometrics or a device PIN, you'll want a clear policy for shared or communal devices.
None of these are dealbreakers. They're reasons to roll out in stages rather than flip a switch overnight.
Should your business make the switch?
For most businesses the answer is yes, but as a planned migration rather than an overnight cut-over. The NCSC now recommends using passkeys wherever a service supports them, so the direction of travel is clear. The sensible path is to turn passkeys on where your key systems already support them, keep MFA in place as a fallback, and phase out passwords as coverage grows.
The simplest way to do this well is with a managed credential manager. It gives your team one secure, consistent way to sign in, with recovery and oversight built in rather than left to individual devices. It's a service we provide and manage for businesses, and it's the piece that turns "passkeys sound good" into a rollout that actually sticks.
If you'd like a hand working out where passkeys fit, which of your systems support them, and how to roll them out cleanly across your sites, our cyber security team can talk it through.
FAQ
Are passkeys safer than passwords?
Yes. Passkeys can't be phished, guessed or stolen in a data breach the way passwords can, because the private key never leaves your device and is never shared with the website.
Do passkeys replace multi-factor authentication?
In effect, a passkey combines two factors in one step (your device plus your fingerprint, face or PIN), so it delivers MFA-level protection. Most businesses keep MFA enabled during the transition while some systems still rely on passwords.
What happens if I lose the device with my passkey on it?
Passkeys can sync securely across your devices, so you can sign in from another one. A managed passkey manager makes this reliable, with a defined recovery process so nobody gets locked out.
Can my business roll passkeys out across all our systems?
Wherever your systems support them, yes. Support is growing fast, and a managed password and passkey manager helps you roll them out consistently across your team and sites, and keep the stragglers on passwords and MFA until they catch up.
Do all websites and apps support passkeys yet?
Not yet, though support is growing fast. Around half of the world's top 100 websites now support passkeys, so expect to run them alongside passwords for a while rather than switching everything at once.
-1.jpg?width=1200&height=400&name=Blog%20CTAs%20(3)-1.jpg)