Most of us have a password habit we’re not proud of.

A favourite password, slightly changed for each account. A password saved in a browser. Perhaps the same one used for more accounts than we’d like to admit.

We all know the advice: use long, unique passwords and never reuse them. But expecting people to remember dozens of complex passwords is not a particularly realistic security strategy.

Passkeys offer a different approach: instead of making people better at passwords, remove the password from the equation.

What is a passkey?

A passkey uses cryptographic keys to authenticate you.

When you create a passkey, your device generates a pair of keys. The private key stays securely on your device, while the corresponding public key is registered with the service you’re accessing.

When you sign in, your device proves that it holds the private key. You might simply use your fingerprint, face recognition or device PIN to approve the login.

There is no password to type, send or reuse.

That distinction matters.

A phishing website can imitate a genuine login page, but it cannot simply trick you into handing over your passkey in the same way it can steal a password.

Why should businesses care?

Passwords remain an attractive target for attackers.

They can be stolen through phishing, exposed through data breaches or reused across multiple services. Even multi-factor authentication, while extremely valuable, can sometimes be targeted through convincing phishing or social engineering.

Passkeys address a fundamental weakness: there is no password for an attacker to steal or trick an employee into revealing.

For businesses, particularly smaller organisations without large security teams, that can provide a meaningful reduction in credential-related risk.

There is also a usability benefit.

Instead of remembering another password, employees can authenticate using something already familiar: their device and its biometric security or PIN.

Better security does not always have to mean more friction.

But is it really time to go passwordless?

Not necessarily everywhere.

Passkeys are increasingly supported across major platforms and services, but many businesses still operate a mixture of modern cloud applications, legacy systems and specialist software.

That means the realistic goal for most organisations is not to remove every password tomorrow.

It is to start reducing where passwords are necessary.

There are also practical considerations around device management and account recovery.

If an employee loses a device, the organisation needs a clear process for restoring access. Businesses also need to understand how passkeys are managed across corporate devices and accounts.

And employees need to understand what is changing.

A short explanation such as “you’ll use your fingerprint or device PIN instead of entering a password” can be much more effective than a lengthy technical document.

A sensible way to start

You don’t need to roll out passkeys across the entire organisation immediately.

Start with your highest-value accounts.

Consider:

●      Corporate email

●      Your identity provider

●      Administrator accounts

●      Cloud platforms

●      Systems containing sensitive business information

Check which services already support passkeys and establish how they fit with your existing MFA and identity management strategy.

Then test the experience with a small group of employees.

The objective is to understand both the security benefits and the practical experience before expanding further.

Don’t forget the bigger picture

Passkeys are not a complete cybersecurity strategy.

They do not remove every risk associated with compromised devices, social engineering, malware or poor security practices.

But they can remove one particularly persistent problem: the password itself.

For businesses reviewing their identity and access controls, passkeys are worth putting on the agenda.

The question is no longer simply:

“How can we make our employees use better passwords?”

It may be:

“Where can we stop needing passwords altogether?”

For organisations across the Thames Valley, this is exactly the kind of practical cybersecurity conversation worth having.

At OxCyber, we bring together cybersecurity professionals, businesses, educators and the wider community to share knowledge and practical experience.

If your organisation is considering passkeys, passwordless authentication or improving its approach to identity security, connect with the OxCyber community and share what you’re learning.

Sometimes the best password is no password at all.