Going 'Passwordless' is not straightforward - Espria Skip to main content
Espria Cyber Security Team

Going ‘Passwordless’ is not straightforward

Going ‘Passwordless’ is not straightforward

In Short

Going ‘Passwordless’ in your business is not a simple process, so what do you need in order to move to a simpler, more secure system?

Organisations rushing to adopt passwordless authentication are doing so for a variety of reasons: to deliver stronger security, reduce IT support costs, support remote working and to adopt a Zero Trust approach to verify each access request. But it is not a simple process and should not be rushed.


Passwordless authentication simply replaces passwords with a more suitable authentication factor. This means moving from a centralised credential repository (where passwords are saved) to a decentralised model in which no passwords are saved and each individual is responsible for their own passwordless authentication. This therefore eliminates threats posed by passwords.


But unlike Multifactor Authentication (MFA) which secures organisations, users often get frustrated with the additional security layer on top of having to remember their passwords. Passwordless authentication methods are more convenient because there’s no password to remember, and they’re compatible across most devices and systems.


One of the biggest benefits of going passwordless is its simplicity. While most people have already adjusted to using password managers, there are still some passwords (like master passwords) that need you may need to remember.


By going passwordless, you can verify your identity without having to remember anything. You may need to authenticate with a mobile app or scan your face or fingerprint, and that’s it.

Password image

However, there are barriers to immediate adoption and a host of elements to consider before implementing a passwordless environment to the enterprise. Central to this is inertia. According to a survey from Cyber Security Insiders some 22% of businesses still need persuading of the benefits of going passwordless. This could be because of the difficulty in adapting an entire IT infrastructure to a passwordless login. According to this research, two-thirds of its sample claimed they did not have the right in-house teams and skills for the seamless adoption of passwordless authentication.


Many applications are just not designed to go passwordless because identity authentication has traditionally been fragmented. It’s a complicated picture, even among the cloud providers that include multifactor authentication and identity management as part of their services. There is no doubt that this is a journey many organisations are now embarking on as they realise that passwords really are the weakest link and are costing billions in terms of data breaches. But it is not an immediate fix – it is going to take time to scope, plan and implement. It certainly cannot be rushed.


News & Insights

UK businesses cannot continue risking reputation with shoddy security, says Espria

Sophos’ 2024 Threat Report recently highlighted ransomware as the biggest existential cyber threat to small businesses. While cyberattacks on large companies and government agencies may receive more news coverage, Sophos reported that SMB’s are generally more vulnerable to cybercriminals and suffer more proportionally from the results of a breach.

Peace of mind: Cloud is key in scaling systems to your business needs

Meeting the demands of the modern-day SMB is one of the challenges facing many business leaders and IT operators today. Traditional, office-based infrastructure was fine up until the point where greater capacity was needed than those servers could deliver, vendor support became an issue, or the needs of a hybrid workforce weren’t being met. In the highly competitive SMB space, maintaining and investing in a robust and efficient IT infrastructure can be one of the ways to stay ahead of competitors.

UK SMEs should prioritise creating disaster recovery plans for cloud data to ensure business continuity and prevent data loss amid rising cyber-attacks

Cybercrime is a significant issue for businesses of all sizes in the UK. Although we usually hear more about cybersecurity incidents impacting large businesses, smaller businesses are also a target
Please fill out the below form and one of our team will get back to you asap. Alternatively please call 0330 175 5588 to speak to a member of the Espria team.

Please fill out the below form and one of our team will get back to you asap. Alternatively please call 0330 175 5588 to speak to a member of the Espria team.