Identity

The future of workforce access: Why security leaders must get password-smart

(Adobe Stock)

For today’s security leaders, the mandate is clear: reduce identity risk without slowing the business down. Yet despite major investments in authentication tools, credentials remain one of the most exploited attack vectors. Passwords continue to be both a critical vulnerability and a source of everyday friction for employees.

As highlighted in a recent CyberArk whitepaper, 87% of data breaches involve some form of credential theft or compromise -- a reality that places workforce authentication at a crossroads. 

Modern organizations are increasingly pursuing passwordless authentication driven by advances in biometrics, the rise of passkeys, and growing adoption of FIDO2 standards. However, as the whitepaper notes, many enterprises still rely on legacy systems, inconsistent platform readiness, or regulatory requirements that assume the use of passwords. These obstacles create a hybrid state where password-based and passwordless systems must coexist for the foreseeable future. 

The growing threat landscape

Identity-based attacks are escalating in frequency and sophistication. More than 9 in 10 organizations experienced an identity-related breach in the past year, according to the whitepaper. Threat actors are now leveraging AI to craft highly targeted phishing emails, generate polymorphic malware, and harvest long-lasting session cookies that bypass traditional controls. Once an attacker obtains a single password—before login, during login, or post-authentication—the opportunity for lateral movement expands dramatically. 

This evolving threat landscape underscores a critical reality: simply enforcing MFA or strengthening password policies is no longer enough.

Why passwords persist

Despite being widely recognized as a weak link, passwords persist due to several practical barriers. The paper outlines three primary challenges:

  • Legacy systems that don’t support modern protocols like FIDO2
  • Fragmented environments with inconsistent readiness across cloud, on-premises, and third-party systems
  • Workforce resistance due to usability concerns, privacy hesitations, and change fatigue

Regulations such as PCI DSS 4.0 and SOC 2 further complicate matters by still requiring password-based controls for certain systems. 

WPM: The bridge to a passwordless future

Because organizations cannot “flip a switch” and go passwordless overnight, CyberArk recommends a phased strategy, starting with Workforce Password Management (WPM) as a foundational capability. WPM provides:

  • Secure, encrypted storage of business credentials
  • Risk-based visibility and real-time monitoring
  • Automatic credential capture and one-click access for users
  • Integrations with SSO, MFA, and modern authentication methods like passkeys

By centralizing and securing passwords early, organizations reduce immediate risk while building employee familiarity with streamlined, low-friction login experiences—paving the way for full passwordless adoption.

Knowing when your organization is ready

The whitepaper identifies five readiness signals, including high volumes of password reset requests, persistent identity-based attacks despite MFA, and modernization of legacy applications. Combined, these indicators help security leaders determine when their environment and culture can support more advanced authentication methods. 

Beyond passwordless: A modern identity strategy

Finally, CyberArk emphasizes that passwordless authentication alone isn’t sufficient. Organizations must combine it with continuous identity assurance, AI-powered analytics, risk-adaptive controls, and privilege-centric protections across the entire identity lifecycle. 

The future of workforce access isn’t just passwordless -- it’s password-smart. By securing the passwords you must keep, eliminating the ones you no longer need, and modernizing authentication holistically, security leaders can reduce risk while creating a seamless and productive experience for every user.

Bill Brenner

InfoSec content strategist, researcher, director, tech writer, blogger and community builder. Senior Vice President of Audience Content Strategy at CyberRisk Alliance.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds