Opens in a new tab
vmblog logo 2024 wht (updated)

World Password Day 2026: Industry Experts Weigh In on the Future of Authentication, Passkeys, and Password Security

Share: 

David Marshall | Published: May 7, 2026
world password day

Every year on the first Thursday of May, World Password Day serves as a timely reminder that the way we protect our digital identities still matters, perhaps now more than ever. In 2026, the cybersecurity landscape looks dramatically different than it did when Intel first championed this awareness day back in 2013. Passkeys are gaining serious mainstream traction, AI-powered credential stuffing attacks have grown more sophisticated, and the long-promised “passwordless future” is finally starting to feel less like industry wishful thinking and more like an inevitable reality. Yet despite all of this progress, weak, reused, and compromised passwords remain one of the leading root causes of data breaches worldwide.

The tension between where we are and where we need to be is exactly what makes World Password Day such an important moment for reflection and action. Organizations of every size are navigating a complicated transition, balancing legacy systems that still depend on traditional password authentication against the pressure to adopt modern identity and access management frameworks. Regulatory scrutiny around credential security is intensifying, the attack surface continues to expand with hybrid work and cloud adoption, and end users remain the wildcard that no technology alone can fully account for. The stakes have never been higher, and the conversation around authentication has never been more nuanced.

To get a pulse on where the industry stands, VMblog reached out to a broad range of cybersecurity experts, identity and access management professionals, and technology leaders for their thoughts on World Password Day 2026. From practical advice for IT teams and security practitioners to bold predictions about the road ahead, here’s what the experts had to say.

++

Anthony Cusimano, Solutions Director at Object First

The death of the password is closer than we think. Passwords are no longer a secure method of authentication, and the most effective way to protect your accounts and security is by boiling the ocean and using a password manager, in conjunction with MFA, and having recovery accounts set up each following the previous instructions. Sound like overkill? That’s because it’s the only real way to ensure you can get your accounts back when they are compromised and they will be compromised. Passwords just aren’t up to snuff when it comes to real data security.

In order to truly protect your data against emerging security threats such as ransomware, credential theft, and human error, critical data needs to be stored in an absolute immutable backup. 89% of IT professionals say AI-powered cyberattacks have made them more concerned about the safety of their organization’s data, and the top-ranked defense they’ve identified is increasing backup data security (73%). These backups ensure that the data cannot be stolen or manipulated by anyone, including admins, with access to the data. Passwords are important, but it is even more critical to have a recovery plan for when passwords fail, because we know they will.

++

Darren Guccione, CEO & Co-Founder, Keeper Security

Every year, World Password Day generates the same conversation. And every year, attackers walk straight through the same open doors. Credentials remain the most exploited entry points in enterprise breaches – not because the risk is unknown, but because access is still not being controlled with the rigor the threat demands. A compromised password doesn’t just unlock an account. It hands an attacker a foothold for lateral movement, data exposure and, in many cases, full environment takeover.

Password strength alone is not the issue. The real exposure sits in how credentials are stored, shared and governed across users, systems and service accounts. This is where Privileged Access Management (PAM) becomes critical. Enforcing least privilege, rotating credentials, removing standing access and introducing visibility over how credentials are used changes the risk profile entirely.

Passkeys are gaining serious institutional momentum. The UK’s National Cyber Security Centre (NCSC) and US agencies including CISA are actively pushing phishing-resistant authentication aligned with FIDO standards – and adoption is already visible across public services. The direction is set. Even so, most organizations remain in hybrid environments where passwords persist. Governance does not disappear in that model. It expands to both passkeys and traditional passwords in parallel.

Strong passwords still matter. But without control over who can use them, when and under what conditions, they offer a false sense of security. Organizations that treat access as a one-time configuration rather than a continuously managed risk are not protected. The credential problem is solvable. What is lacking is the will to govern access with the same discipline we apply to every other critical business function.

++

Jack Cherkas, Global CISO at Syntax

World Password Day 2026 brings the usual advice for passwords: longer, unique, never reused. That is no longer enough. Passwords are only one of many credentials now under AI-powered attack. Generative AI has industrialized credential attacks: phishing lures that defeat traditional user training, voice clones that pass help-desk identity checks, and credential stuffing at industrial scale.

Credentials remain one of the top initial access vectors year-after-year, and non-human identities, from AI agents to service accounts, are multiplying, each one holding credentials, each one a potential blast radius. When the next breach arrives, “we didn’t know who or what had access” will not be acceptable as a defense.

The fix is not novel. For organizations: phishing-resistant multi-factor authentication (MFA) and passkeys, single sign-on wired into a disciplined joiner-mover-leaver process, vaulted privileged access, and scoped, logged, revocable credentials for every non-human identity, AI agents included, never a shared service account. For individuals: a password manager, unique passwords or passkeys, and MFA on every account. The password era is ending, the credential era is not. Most breaches still begin with a credential someone forgot to protect, revoke, rotate, or retire. The organizations and individuals that master that unglamorous work are the ones that stay resilient when the next AI-powered attack lands.

++

Kevin Higgins, senior consultant at Optiv

World Password Day is no longer just about protecting people. It’s now also about protecting machines. As machine-to-machine communication accelerates, strong, frequently rotated credentials are essential to ensure trusted systems don’t execute malicious or compromised instructions.

The challenge, however, is that many organizations still rely on static credentials. Long-lived API keys and persistent service account passwords create machine credentials with unlimited replay value. When credentials become permanent, compromise becomes persistent. If these credentials leak through logs, configuration files, AI, or repositories, attackers can impersonate trusted systems for extended periods without triggering the authentication signals typically associated with human access.

Modern security requires a shift to short-lived, cryptographic identities, where every workload proves what it is through mechanisms like mutual TLS authentication and temporary identity tokens. This ensures every interaction is verifiable and resilient by design.

The future of cybersecurity will be defined by how effectively we secure the machines that now act on our behalf, and passwords continue to play an important role in the evolving security journey.

++

Kevin Charest, Vice President of Cyber Governance Services at Netrio

World Password Day has been around for more than a decade, but in the last year the conversation has shifted from stronger passwords to MFA, phishing resistance and passkeys. While it probably should be renamed “World Passkey Day,” the reality is that most people still use passwords for everything. Companies are also not using passkeys at scale, which means security tools are left to make up for the shortcomings of how people actually use passwords.

To this day, the single biggest issue remains password reuse. With so much breach and security incident data available, attackers often do not need to crack a password; they can take a known password and try it across multiple services and systems. Complexity rules do not fully solve the problem either. Users often just add a few required characters or move from “password123” to “password124.” Relying on user IDs and passwords as the primary form of security can be the downfall of many companies.

Until organizations can truly move away from passwords, MFA and detection tools must do more of the work. For SMBs and mid-market enterprises in particular, the challenge regarding passwords is especially tough. If they cannot afford to apply the highest level of security across the entire organization – which in many cases is true, due to limited budget – they should at least identify critical roles and apply stronger controls in those areas. At a minimum, financial teams, employees sending or receiving money, and those handling sensitive data, intellectual property or the company’s “crown jewels” need a higher level of security.

However, in the end, the biggest hurdle is not always technology. Culture eats technology for breakfast. Asking users to carry a physical hardware device or adopt a new authentication process can create resistance. At its core, change management is difficult, but necessary. Passwords are still the game for most users, and until that changes, companies need to treat password behavior as a foundational security gap that must be actively managed.

++

Garrett Hamilton, co-founder and CEO of Reach Security

AI-powered attackers don’t care whether you’ve enabled passkeys. They’ll always look for the weakest available or remaining path and exploit it. If legacy authentication still exists anywhere in the environment, that’s the path of least resistance. Especially if the methods were added years ago and quietly forgotten. Security failures today aren’t about missing controls; they’re about inconsistent ones.

Passkeys only deliver real security gains if they actually simplify the environment. In reality, too many organizations are enabling passkeys alongside existing authentication instead of replacing it, which increases complexity and expands the attack surface. The real challenge isn’t going passwordless; it’s removing legacy access paths and continuously validating that it stays removed. Treat passkeys as a platform-level change, or risk repeating the same configuration drift that made passwords fragile in the first place.

++

Steve Shoaff, SVP of Transformation at Imprivata

Today is World Password Day – a reminder of one of the most outdated and frustrating conventions still embedded in modern technology. Passwords have long been a necessary part of digital security, while at the same time being one of its biggest liabilities. Bad password habits have been around for so long that continuing to blame users just isn’t productive. The real problem is that the model itself is broken and increasingly unnecessary for the majority of our logins.

That’s why I’m hopeful this may be one of the last remaining World Password Days. The industry is moving toward a future where passwords fade into the background – or disappear entirely – replaced by stronger, smarter authentication methods built on cryptography, trusted devices, and identity-bound access.

When security depends on people remembering complex secrets, failure is almost guaranteed. When security is designed to happen behind the scenes, organizations can reduce phishing and credential theft, eliminate password reuse, and strengthen protection without adding friction. The goal shouldn’t be better passwords or password managers. It should be a world that no longer asks people to manage passwords at all.

++

Rishi Kaushal, CIO at Entrust

Compromised credentials remain the most common attack vector in data breaches, yet according to recent research, 74% of U.S. banking customers continue to rely on passwords as their primary login method. As fraudsters increasingly target authentication flows and account takeover attacks surge, verification strategies must evolve. Security cannot be compromised for convenience when money, accounts, and personal data are on the line.

The key is to use authentication methods that consumers already trust, like biometrics, to reduce resistance, support adoption, and help create secure experiences that feel familiar rather than disruptive. In practice, biometric authentication should act as a “trust anchor,” not only verifying identity, but also confirming that the individual attempting to access or transact is the same person who originally opened the account. This continuity of identity is critical for confirming that legitimate account holders, not bad actors, are initiating sensitive actions and is essential as AI-powered fraud techniques become more accessible and harder to detect.

++

Tim Chase, Field CISO & Principal Technical Evangelist at Orca Security

Passwords used to be the backbone of security, but they are starting to show their age. They were not built for a world where identities include not just people, but also apps, services, and now AI agents acting on their own. That shift makes identity the real control point. It is no longer enough to protect a login. You need to know who or what is accessing your environment, what they are allowed to do, and whether that behavior actually makes sense. Passwords can still play a role, but only as part of a bigger picture. Strong authentication, least privilege access, and continuous monitoring are what actually keep things in check. As AI becomes more embedded in day-to-day operations, the focus has to move from just securing credentials to managing and understanding every identity in the system.

++

John Cannava, CIO at Ping Identity

As AI continues to evolve and cyberattacks become increasingly sophisticated, much of our digital security still hinges on a single weak point: the password. It’s telling that 39% of people say AI-powered phishing is the threat they fear most, yet less than a quarter feel highly confident in spotting what’s real versus a scam. This gap highlights a growing vulnerability and a critical opportunity to rethink how we secure identities.

Authentication must evolve to meet today’s threat landscape. Passwordless solutions are rapidly replacing traditional passwords with stronger, more user-centric methods like biometrics, authenticator apps, and digital certificates. These approaches significantly reduce the risk of phishing and credential theft while improving the user experience.

World Password Day shouldn’t just be about updating passwords. It should spark a broader shift. To stay ahead of modern threats, organizations and individuals need to move beyond passwords and adopt more resilient authentication strategies that put control back in the hands of users.

++

Ashish Jain, CTO at OneSpan

World Passkey Day is a reminder that there’s a more secure alternative to passwords, which have long been a point of vulnerability. AI is amplifying phishing schemes at scale to target traditional access credentials. Passkeys represent a step towards a more resilient digital infrastructure that emphasizes both security and usability by replacing reusable credentials with cryptographic keys, whether bound to a single device or synced across a user’s trusted platforms. They’re especially valuable for securing high-risk interactions, such as financial transactions, where strong, phishing-resistant authentication is critical.

FIDO passkeys are the industry standard, backed by the world’s leading technology platforms — Google, Microsoft, and Apple — whose native support has accelerated adoption at scale. Going above and beyond traditional authentication, passkeys verify user identities and strengthen authentication across desktops and mobile devices, creating a more secure digital environment. As both cyber threats and passkey adoption grow, I’m confident they will become the underpinning of digital trust and online transactions. The standard exists. The ecosystem is maturing. The window to get ahead of user expectations and regulatory pressure is narrowing fast. The question is no longer whether to adopt passkeys, but how fast you can get them into production.

++

David Lee, Field CTO at Saviynt

World Password Day is a good reminder that passwords alone are no longer enough to protect modern organizations. As AI makes it easier for attackers to scale credential-based attacks, the real challenge is ensuring the right users have the right access at the right time. That means organizations need better visibility into who has access to what, and stronger controls to manage and adjust that access as risks change. Ultimately, reducing reliance on passwords starts with taking a more proactive approach to managing identity and access across the business.

++

Ravi Soin, CIO/CISO at Smartsheet

Every year, World Password Day arrives with the same advice. This year, the conversation needs to shift to the identity challenges that come with AI reshaping how work gets done.

Passwordless authentication like multi-factor authentication, biometrics and passkeys are rapidly becoming the norm, and for good reason: they’re stronger, faster and harder to compromise. This progress is real and worth celebrating. But even as authentication improves, with Zero Trust the deeper challenge remains: whether the humans in your environment—and the systems acting on their behalf—are behaving in ways you can actually verify.

Every day, employees access dozens of apps to do their jobs. Behind them, a growing number of non-human ‘workers’ like automations and AI agents are operating across your environment, often carrying elevated privileges with far less scrutiny than a human login would receive. Even as AI takes on more of the workload, accountability still sits with people.

The organizations that get this right will ensure every identity in their environment—human or not—is governed, traceable and held to the same standard. That’s what modern identity security actually demands.

++

Craig Savage, vice president, Cybersecurity at Spinnaker Support

In Oracle and SAP environments, password risk is no longer about what users choose. The bigger exposure is often non-interactive access such as service accounts, batch jobs, APIs, and integrations. Those identities frequently outlive the people and projects that created them, and that’s where password security becomes an operational control problem.

The 2027 SAP ECC deadline changes the risk picture because support status becomes part of the story. As organizations delay transformation, identity controls around legacy environments matter more, since older estates tend to accumulate access drift, custom interfaces, and brittle authentication dependencies.

The strongest password strategy is to reduce where passwords are needed at all. Phishing-resistant MFA and passwordless methods are increasingly preferred because passwords are not phishing-resistant. At the same time, ERP teams need to look beyond vaulting and focus on which privileged accounts can still authenticate directly, where they are used, and whether they can be rotated without breaking production.

++

Pierre Mouallem, CISO of Delinea

World Password Day feels increasingly outdated. Passwords can no longer be relied on as a meaningful line of defense as they are routinely bypassed through social engineering, and we are seeing increased attacks through third-party apps. The real damage lies in what hackers can access once inside an organization’s system.

More organizations are deploying AI agents to improve productivity and granting them standing access to their core systems, which 73% of leaders acknowledge is increasing their security risk. If just one overprivileged account or agent is breached, attackers can move laterally and comprise critical systems.

Organizations can build true resilience by rethinking access altogether. Adopting ephemeral permissions and just-in-time (JIT) access can ensure privileges exist only when needed and drastically reduce the window of opportunity for attackers. By layering on strict role-based access controls, they can limit both movement and overall exposure.

Ultimately, organizations’ mindsets must shift toward a model of zero standing privilege where no user, device, or agent is inherently trusted, and every access request is continuously verified.

++

Tomer Bar, Associate VP of Security Research at Semperis

Passwords have a terrible reputation, but it’s not their fault. It’s ours. Most of the risk comes from human limitations and predictable behavior, not from the mathematics behind guessing every possible combination. The comforting myth is that ‘strong’ passwords must be safe, but they can be weaker than you think. In reality, very few people choose random passwords, and advanced attackers know this. They don’t brute-force the entire key space; they brute-force your habits.

Are passwords useful today? Yes, but they’re no longer enough on their own. The best practice is to stop letting humans design them. Use a password manager to generate and store long, truly random passwords and never reuse them. Enable multi-factor authentication (MFA) wherever possible to make stolen or guessed passwords far less valuable. For the few passwords you must remember, use long, unique passphrases made of random words instead of lyrics, quotes or clever patterns. The goal isn’t perfection; it’s to make attacking your accounts so difficult and unprofitable that attackers move on to easier targets.

++

Carlos DaSilva, CPO, Unibeam

Multi-factor authentication was supposed to close the door that passwords left open to threat actors. But the lock is only as strong as the second factor, and for most people, that second factor is still an SMS code that hinges on the security of the phone number it’s sent to. Increasingly, phone numbers are being reassigned, ported, and shared through carrier APIs without users knowing. Meanwhile, AI is making it trivially cheap to automate the attacks that exploit them.

Passkeys are widely seen as the answer, but they frequently require separate hardware and often keep a weak fallback MFA alternative.

The solution doesn’t have to be that complicated. The SIM card that’s already in everyone’s pocket has been a secure, hardware-rooted credential for more than 30 years.

We’ve spent the past decade questioning the password. World Password Day 2026 is a good opportunity to apply the same scrutiny to what replaced it and recognize we’re not better off, yet.

++

Dave Lewis, Global Advisory CISO at 1Password

The conversation has shifted from “how do we protect passwords” to “how do we manage identity across everything.” That includes humans, but increasingly, AI agents and automated tools are using credentials as well. Most organizations have no visibility into that. We’re at an inflection point where the old perimeter-based security model no longer holds. The answer is to give every identity, human or machine, the right access at the right time, with full accountability. Password managers were step one. The next step is to treat identity security as infrastructure, not as a setting you configure once and forget.

++

Kevin Charest, Vice President of Cyber Governance Services at Netrio

World Password Day has been around for more than a decade, but in the last year the conversation has shifted from stronger passwords to MFA, phishing resistance and passkeys. While it probably should be renamed “World Passkey Day,” the reality is that most people still use passwords for everything. Companies are also not using passkeys at scale, which means security tools are left to make up for the shortcomings of how people actually use passwords.

To this day, the single biggest issue remains password reuse. With so much breach and security incident data available, attackers often do not need to crack a password; they can take a known password and try it across multiple services and systems. Complexity rules do not fully solve the problem either. Users often just add a few required characters or move from “password123” to “password124.” Relying on user IDs and passwords as the primary form of security can be the downfall of many companies.

Until organizations can truly move away from passwords, MFA and detection tools must do more of the work. For SMBs and mid-market enterprises in particular, the challenge regarding passwords is especially tough. If they cannot afford to apply the highest level of security across the entire organization – which in many cases is true, due to limited budget – they should at least identify critical roles and apply stronger controls in those areas. At a minimum, financial teams, employees sending or receiving money, and those handling sensitive data, intellectual property or the company’s “crown jewels” need a higher level of security.

However, in the end, the biggest hurdle is not always technology. Culture eats technology for breakfast. Asking users to carry a physical hardware device or adopt a new authentication process can create resistance. At its core, change management is difficult, but necessary. Passwords are still the game for most users, and until that changes, companies need to treat password behavior as a foundational security gap that must be actively managed.

++

Jon France, CISO at ISC2

World Password Day on May 7 serves as a reminder that passwords alone are no longer enough to protect us. Every day, we hear reports of cybercriminals using social engineering & AI-powered attacks to gain access to services, information and corporate networks with stolen identities. Recent high-profile software supply chain cyber-attacks underscore the urgent need for stronger identity security.

Such high-profile cases are just the tip of the iceberg, as shown by the latest ISC2 Workforce Study. Over 30% of the 515 German cybersecurity professionals surveyed reported experiencing security incidents due to privacy violations or unauthorized access. It’s no surprise that nearly a quarter (22%) of respondents confirmed that identity and access management ranks among the top 10 skills missing from their security teams.

While World Password Day is a good reminder, identity security remains fundamental to cybersecurity, beyond today and not just for people but also non-human identities such as Ai agents, API and service to service connectors. Although measures such as multi-factor authentication, passkeys and other password less methods are widely recognized as essential, their real value lies in how effectively they are implemented, understood, permissioned and maintained through the full lifecycle. Cybersecurity is a people-driven discipline; attackers exploit gaps in behaviors, skills and awareness just as often as gaps in technology. Strong cybersecurity hygiene depends on knowledgeable professionals who understand current attack methods, think critically about risk and apply defenses with intent rather than by default. Building resilient identity protection, therefore, starts with investing in people who are equipped and trained to make security decisions that stand up under real-world pressure.

++

Craig Birch, Principal Technologist, Cayosoft

World Password Day is about protecting passwords. In today’s hybrid Microsoft environments, that responsibility has expanded.

Strong password policies still matter, but attackers rarely crack passwords directly. They exploit credentials that are valid, reused, or already exposed. Breached passwords, synced identities, service accounts, and legacy authentication paths remain common entry points into Active Directory and Microsoft 365.

Modern password protection includes routinely checking credentials against known breaches, eliminating password reuse, and rapidly responding when exposure occurs. It also requires reducing reliance on passwords through phishing resistant MFA in Entra ID, while tightly governing the credentials that cannot yet be eliminated.

On prem Active Directory accounts, legacy protocols, and directory changes that automatically sync into Microsoft 365 all introduce password backed risk if they are not continuously monitored. A password that has been compromised, over privileged, or silently changed is no longer a control. It is an attack path.

World Password Day should remind organizations that protecting passwords is not a one time exercise. It is an ongoing discipline that combines breach awareness, credential hygiene, and continuous visibility across AD and Entra ID.

++

David Sequino, CEO & Co-Founder of OmniTrust

Passwords were never built for the scale of the modern world. Today, the biggest threat isn’t just a human user with a weak password; it’s the millions of machine identities — the silent background interactions between apps, clouds and devices — that rely on static credentials to function. These credentials have shifted from a security control to a point of exposure.

On World Password Day, we need to stop asking users to pick a better password and start asking organizations to build better environments. We must move toward a model where trust is established in real-time, continuously verified and tightly controlled. Security doesn’t need to be a hurdle; it should be the foundation of every trusted interaction across our digital infrastructure.

++

Vik Desai, global Cybersecurity Strategy and Risk lead, Accenture

AI has turned every amateur hacker into an industrial-scale threat, and a 65-year-old technology, the password, is what’s standing between them and your bank account, your medical records, and your business systems. Passkeys are the solution, replacing passwords entirely with a secure credential tied to your device like your smart phone or laptop. The technology isn’t the holdup. We are.

++

Chandramouli Dorai, Chief Evangelist of Cyber Solutions at Zoho

World Password Day was created to remind people that credentials are still the entry point to the modern business. Our recently released State of Workforce Password Security 2026 Survey shows that the entry points have multiplied; the average U.S. employee now logs into more than fifteen business applications, and most organizations cannot fully account for who has access to what across them,” says Chandramouli Dorai, Chief Evangelist of Cyber Solutions at Zoho. The issue is not under-investment, but investment without architectural coherence, leaving the U.S. with a significant gap between intent for security and actual results.

++

Chris Newton-Smith, CEO at IO (formerly ISMS.online)

World Password Day is a useful reminder, but a reminder is a point-in-time measure. You change the password, tick the box, move on. And the threat landscape doesn’t pause while you do.

The real challenge isn’t that employees use weak passwords. It’s that organisations treat security as a series of one-off actions rather than a continuously managed system. Our State of Information Security Report found that 35% of respondents had used personal devices for work without proper security measures in place. That gap doesn’t exist because people don’t care about security. It exists because the culture, training, and controls weren’t embedded into how those people work every day.

ISO 27001 gets this right. Multi-factor authentication, role-based access control, and ongoing employee awareness training aren’t annual reminders, they’re continuous operating disciplines. The organisations that manage them that way aren’t just better protected against social engineering and business email compromise. They’re building something that holds up under scrutiny from customers, partners, and regulators, not just on World Password Day, but on every other day of the year.

Password hygiene matters. But it’s one signal in a much bigger system. The question worth asking today isn’t “how strong is our password policy?” It’s “what are we doing on every other day of the year?

++

Stephanie Schneider, cyber threat intelligence analyst at secure access solution, LastPass

As the notion of digital identity has expanded beyond a single secret or password, the concept of World Password Day increasingly feels antiquated. Perhaps it’s time to reframe it as World Identity Protection Day. Passwords were never the real problem. They were a rudimentary coping mechanism to securing our online world. Today’s attackers know this better than anyone, and they no longer exclusively rely on cracking or guessing passwords. Instead, they can sidestep them entirely by stealing session cookies, OAuth tokens, and authentication artifacts, or by compromising endpoints and trusted access paths. When an attacker logs in using a valid session token from an infected device, the password hasn’t failed—it’s simply been made irrelevant. The real issue is that identity has become the new control level for everything, including cloud access, data, infrastructure, SaaS, and supply chains. And as identities have multiplied and become more distributed, so too has the attack surface.

++

Morey Haber, Chief Security Advisor, BeyondTrust

Each year, World Password Day arrives with a familiar message that is increasingly outdated. The password, once the foundation for authentication and digital trust, has become the weakest link in agentic AI and identity compromise. The uncomfortable truth is that passwords alone are no longer an effective identity security control. They have become a liability.

Threat actors typically do not hack in the traditional sense anymore via vulnerabilities and exploits. They simply log in via stolen credentials (username and passwords). Credential theft, password spraying, and replay attacks have industrialized access for crime syndicates and nation state threat actors. Billions of compromised credentials circulate across the dark web, and even the most complex password policy cannot defend against password reuse, human behavior, and a leaked secret. Complexity does not equal security and if you rely on password obfuscation, it only increases user and automation friction.

Organizations must treat these changes in password (human) and secrets (machines) management as an inflection point. Identity has become the new perimeter, and passwords cannot carry that burden alone for trust. Multifactor Authentication (MFA) and Single Sign On (SSO) were the first evolution, but even these technologies are under pressure from phishing resistant bypass techniques, social engineering, token theft, and SIM jacking. The next phase demands a shift toward passwordless architectures, implementing the principle of least privilege continuous authentication, just in time access, and behavioral monitoring.

This is not just a technology conversation. It is a governance and cultural transformation that must be led by executives to ask harder questions of the business. For example, why are we still trusting standing privileges in a dynamic threat environment including new deployments of artificial intelligence? The answer often lies in legacy systems, operational inertia, and misplaced confidence in legacy frameworks and security controls.

The path forward is clear:
• Eliminate passwords where possible.
• Enforce least privilege with just in time access.
• Treat every identity, human or machine, as a potential attack vector.
• Measure trust continuously, not only at login.
• Monitor every sensitive session for appropriate behavior.

World Password Day should not celebrate passwords. It should mark their decline and the evolution in technology, best practices, and security controls to protect identities once solely secured by passwords. It should be a day of remembrance for passwords; they served us well for decades.

++

David Cottingham, president of rf IDEAS

The path away from passwords involves the device individuals already carry with them — their smartphone. Mobile phones and the digital wallet capabilities they carry can now be the secure credential that authenticates users across different access points as opposed to passwords or physical badges. Plus, a phased approach lets IT teams gradually roll out mobile credentials while maintaining support for existing card-based systems. With credential abuse remaining the single most common initial access vector for breaches, World Password Day should serve as a reminder that a secure credential has never been more within reach, and every day without upgrading is a risk organizations can no longer afford to accept.

++

Chris Hendricks, Head of Coalition Incident Response at Coalition

We continue to see compromised credentials as one of the most reliable entry points for attackers because they’re routinely exposed, reused, or phished. The fact that compromised credentials remain a leading driver of cyber incidents and claims spotlights a hard truth: no matter how complex a password is, it’s still a single point of failure where attackers can simply log in rather than needing to break in.

What’s more concerning is that many organizations, especially SMBs, are still over-relying on passwords as a primary control. Tools like multi-factor authentication (MFA) can stop the vast majority of account takeover attempts, but still aren’t universally adopted. The shift we’re seeing (and recommending) is toward layered access resilience: combining strong passwords with phishing-resistant MFA, strong identity-based access controls, device trust, and continuous monitoring. World Password Day should serve as a reminder that identity is now the front line of defense, and protecting it requires more than better passwords. Organizations must assume they will eventually fail and build controls accordingly.

++

Joshua Stuts, Director of Security & Trust at Drata

We’re quickly heading toward a world where ‘enter your password’ is the exception, not the norm. As identities span humans, services, and now AI agents acting on our behalf, the only sustainable model is phishing resistant, passwordless auth backed by strong device signals and continuous risk evaluation. In this world, the real question isn’t ‘how strong is your password policy,’ it’s ‘how often can an attacker trick their way into a trusted session at all?’

We’re already seeing security mature teams design for this future: standardizing on passkeys and strong MFA, giving human users and AI agents scoped, auditable access, and proving to customers and regulators that these controls work in practice. As AI agents become a first class part of the workforce, we’ll need to manage their identities, secrets, and permissions with the same rigor as any employee – and have continuous evidence that we’re doing it. That’s the passwordless future we’re building toward: fewer secrets to steal and more provable security built into every identity and action.

++

Darren Wolner, VP Product Management – Managed and Professional Services at GTT

World Password Day is a timely reminder that the perimeter enterprises once relied on is gone. Credentials are now the front door to global infrastructure, and AI-powered attacks are rattling that door harder than ever. Static security policies built for a different era simply can’t keep pace with threats that move at machine speed. Real cyber resilience today means your security posture has to be dynamic, predictive, and always on (not a checklist you revisit once a year). The question for every CIO isn’t whether to modernize, but whether they can afford to wait.

++

Tyler Moffitt, Sr. Security Analyst, OpenText Cybersecurity

The advice we’re used to hearing around password protection — strong passwords, regular updates, MFA — still matters but is no longer enough. Attackers aren’t just trying to crack credentials anymore. They’re logging in with stolen ones, with phishing, infostealers, session hijacking, and other forms of credential abuse all on the rise. Valid logins have become one of the easiest and most reliable ways into an organization, shifting the focus away from stronger passwords and toward how identities are protected.

Today, identity is the new security perimeter. It doesn’t matter how strong or unique a password is if it can be exposed and reused. To truly reduce risk, organizations need to look beyond password hygiene and traditional MFA alone. That means adopting an identity-first security approach that prioritizes control and risk signals, including phishing-resistant authentication, adaptive access policies, and better visibility into endpoints and user sessions. This World Password Day is a reminder that passwords alone can’t carry the weight of security operations. The focus must be on protecting identity at every step.

++

Rishi Bhargava, co-founder of Descope

National Password Day is a reminder that many of the habits people think are improving their security are based on outdated guidance. Changing ‘Summer2025!’ to ‘Winter2026!’ might feel responsible, but it doesn’t meaningfully protect against modern attacks.

++

Christine Barry, Senior Chief Cybersecurity Storyteller, Office of the CTO, Barracuda Networks

World Password Day is back, and if your first reaction is indifference, you’re not alone. Passwords are tedious. They get in the way, are hard to manage and are easy to get wrong. But that frustration is exactly what attackers count on. When 94% of users reuse passwords or choose weak ones, it turns a minor inconvenience into a major security gap.

The threat environment is not slowing down. Automated attacks are doing most of the work now, with bots constantly scanning login portals and testing credentials at scale. Brute-force attacks can crack common passwords almost instantly, while credential stuffing exploits recycled passwords from past breaches. Add phishing into the mix, and it becomes clear how easily a single lapse can turn into account takeover or worse. You may not notice these attacks, but they are persistent and effective.

There’s no silver bullet, but there are practical steps that move the needle. Use a unique password for every account. Lean on a password manager so you don’t have to keep everything in your head. Avoid predictable choices and personal details. Keep an eye on breach alerts and act quickly when something surfaces. And when multi-factor authentication is available, use it. These are not new ideas, but they are still the difference between being an easy target and a harder one.

World Password Day is about a quick reset. Take inventory of your accounts, clean up the weak spots, and tighten the basics. It’s not glamorous work, but it’s necessary. Attackers are getting faster and more automated. The least we can do is make their job harder.

++

Matt Chiodi, Chief Strategy Officer, Cerby

World Password Day focuses on the apps that enterprises can see. The bigger risk is the ones they can’t. On average, organizations run more than 80 applications completely outside their identity control plane: no SSO, no centrally managed MFA, no automated provisioning.

Password hygiene campaigns don’t reach these apps. Neither do most IAM programs. After all, if every enterprise app were connected to the organization’s identity stack, we would need only one password (ok, maybe a handful), not hundreds.

The first mitigation is discovery. You can’t govern what you haven’t found. Security teams need a complete inventory of their disconnected app footprint, not just what IT provisioned, but what business units adopted independently. Until that picture exists, every other control is incomplete.

Once you have visibility, the priority is extending existing authentication controls. For apps that can’t support federated SSO, that means centralized credential management, enforced password rotation, and MFA applied directly at the application layer. Shared accounts are OK, but they must be linked to an individual user (yes, this is possible), moved out of password managers, and linked back to your IdP.

The most common attack path into a disconnected app isn’t sophisticated; it’s a stale, often shared credential nobody owns.

Finally, treat offboarding as a disconnected app problem. 68% of organizations report delayed or incomplete access removal after termination, and that number is almost entirely a disconnected app challenge. Joiner-mover-leaver automation must cover the entire application estate, not just the IdP-connected layer. The apps your identity system can’t reach are exactly where orphaned accounts accumulate.

++

Robb Reck, Chief Information, Trust, and Security Officer, Pax8

For most small and mid-sized businesses, the password is still the front door. After years of breaches, credential stuffing, and cheap compute power, that door is effectively unlocked.
MSPs exist to close that gap. Helping customers eliminate account takeover risk is one of the highest-leverage moves in the SMB security stack.

World Password Day is a reminder to act on the basics. Microsoft’s data is unambiguous: over 99.9% of compromised accounts had no MFA. Turning it on is the single highest-impact control an SMB can implement today. Longer term, FIDO-based passkeys remove the password attack surface entirely by eliminating passwords from the equation.

The path is straightforward: unique credentials and MFA now, passwordless tomorrow. SMBs don’t need enterprise budgets. They need an MSP with a repeatable playbook and the will to enforce it.

++

Erich Kron, CISO Advisor, KnowBe4

The best scams are grounded in truth, and modern AI-enhanced phishing attacks are a perfect example of that. Whether it is a widespread service outage or an official notification about a billing credit, scammers have the opportunity to exploit real-world events. Sometimes they even make up real scenarios like your car being tagged by a security camera for a speed or parking ticket.

The scams they pull often result in people giving up their passwords on fake login pages they are directed to in these phishing attacks, and if they reuse those passwords on other websites and accounts, trouble spreads fast.

This World Password Day, users everywhere must move beyond basic password hygiene and practice cyber hygiene. Organizations and individuals alike need to remain educated about the tactics scammers use to gain an element of trust they would never have in other situations. Treat every urgent notification with a trust but verify mindset; instead of clicking an email link, always go directly to the official app or website to check your status. By taking a second to think before reacting to an emotional trigger, you can avoid a scam and a massive headache.

++

Shawn Dorsey, Senior Director, Global Managed Services, ThreatDown

The era of good enough cybersecurity is over. The same AI advancements empowering defenders, such as Anthropic’s Mythos and OpenAI, are also being weaponized by attackers. Despite these high-powered tools, the human element remains the most targeted and vulnerable link in the chain.

This risk is exponentially higher for midmarket companies and SMBs that may lack the resources for 24/7 internal security. Bad actors have adapted. Phishing attacks are now incredibly personalized, naming specific company leaders or political affiliations to build a false sense of familiarity.

This World Password Day serves as a reminder that AI has supercharged phishing-as-a-service and ransomware-as-a-service, allowing attackers to scale from a few dozen targets to thousands. To avoid becoming a victim, you must prioritize basic cyber hygiene. Enable MFA on every account, use unique and complex passwords, and ensure all devices are running the latest patches. For businesses, staying ahead requires a combination of the right tools and rigorous hygiene. Sometimes, it is simply the innate gut feeling that humans have that prevents a total cyber crisis.

++

Bojan Simic, CEO and co-founder, HYPR

The FIDO2 standard is battle-tested. The enterprise deployment playbook exists. Regulators aren’t just permitting passkeys; they’re pushing them. And yet the same ten objections about passkeys keep surfacing in security reviews, IT all-hands, and CISO briefings across industries. World Passkey Day exists to close that gap.

So in that spirit, here are the ten misconceptions that are quietly holding organizations back: 1) Passkeys are just a fancier word for PIN-based MFA, 2) Passkeys still rely on shared credentials, 3) Passkeys only work for consumers, not enterprises, 4) Passkeys create more friction for users, 5) If I lose my device, I lose access indefinitely, 6) Passkeys require biometrics, 7) Passkeys aren’t ready for regulated industries, 8) Passkeys lock you into Big Tech infrastructures run by Google, Apple or Microsoft, 9) All passkeys are the same, 10) Legacy systems can’t support passkeys.

Reading across all ten, a pattern emerges. The misconceptions aren’t random; they cluster around three underlying anxieties: does this actually work the way they say it does, will we lose control, and will our people actually use it? Those are legitimate concerns for any security technology. The difference with passkeys is that all three have well-documented, field-validated answers. World Passkey Day is a useful forcing function. But the real work is making sure the organizations that need phishing-resistant authentication the most, critical infrastructure, regulated industries, enterprises running hybrid environments, have access to accurate information and deployment-ready platforms. The myths are losing ground. The deployments are accelerating. For security leaders in 2026, the question isn’t whether passkeys work. It’s whether your organization can afford to keep acting like they don’t.

++

Stuart Sharp, Vice President of Product at OneLogin

The most effective password may be no password at all. World Password Day has started to feel ironic because most people already know that passwords are a problem. We’ve spent years telling users to create longer passwords, avoid reusing them, rotate them regularly, and add more layers of authentication on top, but the reality is that passwords still create friction for users and opportunity for attackers. We’ve all been there – people forget them, reuse them, write them down, or work around security policies altogether because the process of managing passwords effectively feels admin-heavy. For years now organizations have been moving toward passwordless authentication like on-device biometrics, and more recently passkeys. If the number one goal is security, we have to reduce our reliance on a system that was never really designed for the way we work today.

Passkeys are a step up because they improve security while at the same time making authentication feel more natural for users. Instead of having to remember a convoluted password, passkeys allow authentication to be tied to a user’s device or their own biometric signals, such as a fingerprint, facial recognition, or device-based credential. With passkeys, we’re finally starting to see authentication move to where it should be – a seamless process that doesn’t interrupt your flow every time you launch an app.

Having said that, passwords aren’t going to disappear overnight. Most companies are still operating across a mix of legacy systems and unmanaged devices, so the full transition to passkeys will happen gradually – but it will happen. In many ways, passwords are starting to feel like a set of physical keys we have to carry – just like physical keys, you need a different one for every digital service you use. They’ve been with us for decades, so they’re accepted as normal, but that doesn’t make them the best fit for how we work today. World Password Day exists to raise awareness about good password hygiene and security practices, but as security becomes more of a fluid, embedded, background process, the need to raise awareness will diminish – because security will simply be designed into whatever process we’re using.

Next year, rather than reminding people to manage passwords better, we should celebrate a future without them.

++

Thi Nguyen-Huu, Founder and CEO of WinMagic

Many believe passkeys are the final answer to the password problem, but passkeys, and most authentication today, still commit three fundamental errors: they verify the wrong identity (a credential instead of the real combination of user, device, and conditions), at the wrong time (a single moment instead of continuously), at the wrong layer (the application instead of the transport).

The real shift is toward continuous, hardware-rooted identity where the endpoint itself proves who you are inside the secure channel, with no token or cookie left to intercept. Passkeys replaced the password with a tap, and the next step is replacing the tap with math, so authentication happens continuously without the user doing anything at all.

++

Munu Gandhi, President, Xerox IT Solutions and Chief Technology Officer, Xerox

World Password Day reinforces a simple reality: identity is the control point in modern cybersecurity.

At Xerox IT Solutions, we apply a Zero Trust model where every access request is continuously validated using adaptive authentication. The focus is not more controls – it’s smarter, contextual access that reduces risk while enabling speed.

Organizations that build integrated identity frameworks will be better positioned to protect operations, earn client trust, and move with confidence in an increasingly distributed, AI-driven world.

++

Doug Kersten, CISO of Appfire

World Password Day reminds us that passwords are still one of the most common ways attackers gain access to systems, and the most common ways to protect information. Password risk doesn’t usually come from a single weak password; it comes from how those credentials are used across an organization. Employees reuse the same passwords across systems, share access to move work forward, or connect them to new tools that aren’t centrally tracked. Over time, no one has a complete view of where access exists or who owns it.

That lack of visibility is exactly what attackers take advantage of. AI is making phishing emails, messages, and even voice calls more convincing, which increases the chances that someone could unknowingly give up a password that can be used across multiple systems. Password risk lies within everything that password connects to. The priority now is to reduce how often passwords are used, limit where they can be used, and ensure every system and account has clear ownership. This includes using multi-factor authentication, where you need a password and something you know, have, or are to increase the level of difficulty needed to compromise your accounts. When organizations have consistent visibility and control over access — alongside clear governance around how tools and credentials are used — a compromised password is far less likely to lead to a broader security issue.

++

Amit Megiddo, CEO and Co-Founder of Native

It’s fitting that the anniversary of the Colonial Pipeline attack falls on World Password Day. That incident is often framed as a password failure, but the real issue was what that credential was allowed to do once inside. A single compromised IT login forced the shutdown of critical infrastructure because it had more access than it should have had in the first place.

The same pattern is playing out today across cloud and AI environments. Systems are given broad permissions to move quickly, without clear limits on what actions are actually possible. AI doesn’t introduce a new category of risk. It operates within the access it’s given. What’s different now is that those actions can happen instantly and at scale. The goal isn’t just to detect problems. It’s to make certain outcomes, like deleting production data or disrupting core systems, impossible by design.

++

Youssef El Maddarsi, Chief Business Officer and Co-Founder of Naoris Protocol

World Password Day marks a genuine shift this year. Across Asia, regulators are already moving banks away from SMS codes toward passkeys and biometric login. The credential has evolved. The cryptographic foundation protecting it has not.

Most passkeys and digital certificates in use today still rely on cryptography that quantum computers are expected to challenge within the decade. Stolen credentials already sit behind the majority of breaches globally. Quantum acceleration narrows that window further.

The conversation can no longer stop at phishing resistance. Trust cannot be granted once at login and assumed to hold. Identity needs continuous validation across user behaviour, device posture, session risk and cryptographic resilience. Passkeys may change how we authenticate, but the next frontier is how continuously we verify and prove trust.

++

Uzair Gadit, CEO and Founder of Dubai-based Secure.com

Every World Password Day, users are asked whether their passwords are unique and strong enough. We’re all urged to use MFA and passkeys.

User hygiene is, for the most part, solved. System governance isn’t.

Microsoft Edge decrypts every saved password and holds all of them in process memory, in cleartext, for the entire session, whether or not they’re actually being used. Microsoft’s official response: it’s by design.

And it’s not just Edge. We’ve found that 5 of 7 critical findings were credentials in the wrong place. Not stolen or phished, just sitting in public JavaScript bundles, unauthenticated endpoints and config files.

Every year, we’re reminded that password hygiene is the user’s responsibility. This year, it’s worth remembering that the architecture of tools managing those passwords is playing by someone else’s rules, asking whether those rules are acceptable, and if not, deciding what you can and should do.

++

Gareth Maclachlan at Gigamon

The Colonial Pipeline attack remains one of the most defining cybersecurity incidents in recent history due to its real-world impact. A single compromised password allowed attackers to gain access, ultimately forcing the shutdown of the largest fuel pipeline in the United States and disrupting supply across the East Coast. It demonstrated how quickly a seemingly simple access issue can escalate into a national-level business and infrastructure crisis.

Five years later, organizations are facing the same fundamental challenge, only at a much greater scale and speed. In the past 12 months alone, 65% of organizations experienced a data breach, and 83% reported AI involvement in those incidents. Yet despite increased investment in security tools, only 30% of organizations that experienced a breach say they had the visibility needed to respond effectively.

With the Colonial Pipeline anniversary and World Password Day coinciding, it’s a reminder that AI makes targeted credential harvesting cost-effective, and so the priority is identifying spurious internal traffic to identify when attackers move laterally, interact with data, and evade detection. Or when they use your new AI platform to do the hard work for them. Without that visibility, organizations are still discovering incidents only after the damage is already done.

##