Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Strobes Security Welcomes Ed Adams as Strategic Advisor

March 18, 2026

Your Browser Turns Against You: The Rise of AI-Driven Attacks

March 18, 2026

Enhancing AI Systems: Unlocking Visibility for Proactive Risk Detection

March 18, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » How to “Go Passwordless” Without Getting Rid of Passwords
Insights

How to “Go Passwordless” Without Getting Rid of Passwords

Staff WriterBy Staff WriterJuly 21, 2025No Comments5 Mins Read1 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Passwordless / SaaS Security

With every credential breach that hits the news, CISOs and security professionals continually reach the same conclusion: passwords are insecure, and we should abandon them in favor of less risky authentication factors. But, secure or not, passwords are stubborn. The 2025 Verizon DBIR rated the likelihood of this being the year we finally eliminate passwords as being on par with “this being the year of the Linux desktop.”

Any IT or security pro who has had to explain passkeys to their coworkers can tell you that 2025 isn’t going to be the year we do away with passwords. Frankly, that year’s not likely to come any time soon. Even if it were technically feasible (it often isn’t) to transition every single login at a company to passkeys or biometrics, that would take years of concentrated effort. In the meantime, security leaders can’t afford to sit on their hands and ignore the credential risks currently facing their company.

We need a new approach to thinking about secure authentication. To achieve that, we first need to answer the question: what is it, specifically, that makes passwords so high-risk?

Of course, it’s the user.

The human element is a complicating factor in every aspect of cybersecurity, and it’s particularly challenging when it comes to securing credentials. In fact, the 2025 DBIR reported that the human element served as a “gating factor” in 60% of breaches last year. The most surprising thing about that statistic is that it’s not 100%. After all, users are the ones who:

Create weak and duplicated passwords.
Share unencrypted passwords with coworkers.
Give up their passwords in social engineering attacks.

To be clear, this isn’t because users are problematic; it’s because passwords are problematic as a knowledge factor. Users are tasked with remembering passwords for multiple tools and systems, and sharing those passwords across teams and apps is incredibly complex from a security perspective.

It goes without saying that IT and security teams need to manage credential risk. And passwordless authentication should certainly be the eventual goal. While we work towards a passwordless future, we can take steps to secure passwords as they’re being used now.

That begins by figuring out where passwordless authentication can and can’t be used at your company:

Discover what authentication methods are in use across your apps and systems. Identify any areas with weak authentication and credential risks.
Identify and prioritize the systems and apps where you can immediately transition from passwords to passwordless authentication methods.
Create clear and enforceable policies for passwordless. Guide end-users to set up passwordless authentication on the apps you’re prioritizing.

There are various tools that can support this effort. For instance, 1Password’s free Passkeys Directory indexes apps and services that support passkeys.

The 1Password Enterprise Password Manager (EPM) provides a clear overview of which authentication methods are being used across your company. You can identify any areas with weak authentication methods or compromised credentials. It can even guide users to transition any critical apps to passwordless logins.

That’s sufficient for systems that can support passwordless. But what about the ones that can’t? For those, it’s not enough to focus on removing passwords from authentication. As much as possible, we need to be removing users from the authentication flow.

Passwordless’ greatest strength is how it lets users authenticate without any phishable knowledge factors. But for those apps that can’t support passwordless, there are other ways to obfuscate that information from the end-user.

Even when users must log in with passwords, there are methods to ensure that they don’t handle them directly. Tools like SSO are one common example of this practice in action, but their complexity (not to mention the infamous SSO tax) tends to limit the number of SaaS applications that they can manage.

Beyond that, teams can remove users from the equation by requiring the use of password managers. These solutions allow admins to ensure that:

Each password used in their company is strong and unique.
Teams can securely share encrypted passwords with coworkers.
Passwords are randomly generated and obscured from the users themselves.

Removing users from the authentication flow is often the more user-friendly security option. For example, 1Password Enterprise Password Manager is designed to work with users, making it easy to adopt and enforce secure password practices across teams. Admins have the ability to provision and revoke access to SaaS applications as needed, and to then oversee which users have access to which applications. Users can create and autofill strong passwords without ever having to see them. They’re also given simple tools allowing them to share encrypted passwords with other team members. At all times, the passwords to those apps stay encrypted and out of the hands of the human element.

Every team should strive to implement passwordless authentication factors. While we wait for a future where we can fully eliminate credentials, we must manage the risks of today. That means securing passwords from their most potent risk factor – the user.

About the Author: Jason Meller is a vice president of product at 1Password, the founder of Kolide, and the author of “honest.security.” Jason began his security and product career at GE’s elite computer incident response team. From there, he moved to Mandiant, quickly working his way up to becoming the chief security strategist in 2015. He later founded and served as the CEO of Kolide until its acquisition by 1Password in 2024.

Jason Meller — Vice President of Product at 1Password
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFSE-0gvI2Hb_8pjxruid12bPuB_-O9TmYMsAcxItgrn8677BRXvnZJZeAbyEVIXEyojOoSEqR-68MEtGGciNz3bO21-0SGDlwhEH5uBBLhNTed3yNQpGKE_IPGppbT8kqmp91CpjH0_axC9_qZwSVyIq6whON5Rt-6DvdCdSWOZYzGQmJM8TnV7p5eVw/s728-rw-e365/Jason.png

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article750,000 Affected by Major Data Breach at Alcohol & Drug Testing Service
Next Article Data Breaches Hit Over 200,000: Law Firms Sound the Alarm
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Your Browser Turns Against You: The Rise of AI-Driven Attacks

March 18, 2026

Enhancing AI Systems: Unlocking Visibility for Proactive Risk Detection

March 18, 2026

Unlocking Cyber Talent: The Power of Apprenticeships

March 16, 2026
Leave A Reply Cancel Reply

Latest Posts

Uncovering the Hidden Pattern Behind Cisco’s Rising Vulnerabilities

March 18, 2026

Critical Firewall Zero-Day Breach Sparks Interlock Ransomware Attacks

March 18, 2026

New iOS Exploit: Advanced Tools Targeting iPhone Users to Steal Personal Data

March 18, 2026

FancyBear Server Leak Exposes Credentials, 2FA Secrets, and NATO-Linked Targets

March 18, 2026
Don't Miss

Your Browser Turns Against You: The Rise of AI-Driven Attacks

By Staff WriterMarch 18, 2026

Summary Points AI-powered browsers like Perplexity’s Comet can be hijacked through hidden prompt injections, leading…

Enhancing AI Systems: Unlocking Visibility for Proactive Risk Detection

March 18, 2026

Unlocking Cyber Talent: The Power of Apprenticeships

March 16, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Strobes Security Welcomes Ed Adams as Strategic Advisor
  • Your Browser Turns Against You: The Rise of AI-Driven Attacks
  • Enhancing AI Systems: Unlocking Visibility for Proactive Risk Detection
  • C2 Implant ‘SnappyClient’ Turns Its Focus to Crypto Wallets
  • Uncovering the Hidden Pattern Behind Cisco’s Rising Vulnerabilities
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Strobes Security Welcomes Ed Adams as Strategic Advisor

March 18, 2026

Your Browser Turns Against You: The Rise of AI-Driven Attacks

March 18, 2026

Enhancing AI Systems: Unlocking Visibility for Proactive Risk Detection

March 18, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202624 Views

The New Face of DDoS is Impacted by AI

August 4, 202523 Views

Absolute Launches GenAI Tools to Tackle Endpoint Risk

August 7, 202515 Views

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.