Opens in a new tab
vmblog logo 2024 wht (updated)

World Password Day 2025: Security Experts Weigh In on the Evolving Identity Landscape

Share: 

David Marshall | Published: May 1, 2025

As we mark World Password Day on May 1, 2025, the security landscape continues its rapid evolution away from traditional password-only authentication toward more robust, multi-layered identity verification systems. This shift comes amid escalating cyber threats and growing recognition that passwords alone-even complex ones-no longer provide adequate protection for our increasingly digital lives.

The past year has witnessed significant advances in passwordless authentication technologies, with major tech companies accelerating adoption of biometric and token-based solutions. Meanwhile, cybercriminals have responded with sophisticated attacks targeting these newer authentication methods, creating an ongoing security arms race.

For enterprises, the challenge remains balancing robust security protocols with frictionless user experiences-all while navigating complex regulatory requirements across jurisdictions. Small businesses and consumers face their own struggles, often lacking resources and technical knowledge to implement advanced security measures.

In this year’s World Password Day roundup, VMblog has gathered insights from leading security experts who share their perspectives on the current state of identity protection, emerging trends, and practical advice for organizations of all sizes navigating this complex terrain.

++

Craig Rodgers, Director, IaaS, 11:11 Systems

With the global proliferation of ransomware, phishing and other security threats, the security of credentials is more critical than ever. Weak passwords, password reuse, phishing attacks, and data breaches are the most abused attack surfaces for malicious actors. World Password Day, observed on May 1st, should be viewed as a crucial reminder that securing these identities is a shared responsibility. As we collectively rely on the internet for communication and work, the strength of our passwords becomes a universal safeguard, protecting not just our individual and company data but the integrity of the digital ecosystem we all share.

Strong, unique passwords are the first line of defense against cyber threats that are not bound by geographic limits. Adopting complex passwords is as simple as mixing upper- & lower-case letters, numbers, and special characters, and keeping them updated regularly. Taking this approach will significantly lower the risk of unauthorized access to our personal and company accounts. Equally important is avoiding the reuse of passwords, as a single breach could otherwise affect multiple systems. Raising awareness about these habits will help foster a global culture of security that benefits us all.

As we mark World Password Day, ask yourself, “Do my password practices best protect me or my company by being unique, complex, multi-factor authenticated, and securely stored in a password manager?” Embracing password security tools and policies are without a doubt the most cost-effective way to enhance digital safety. Leveraging tools like password managers to create and store strong passwords, enabling multi-factor authentication for essential protection, are steps anyone can take. Together, through mindfulness and collective action, we can build a safer digital future, ensuring that our online lives remain secure and trustworthy for everyone.

++

Chris Duffy, Sr. Director, Product Management, 11:11 Systems

At 11:11 Systems, cybersecurity is about more than just keeping up with the latest threats, it’s about building a resilient digital foundation. As we observe World Password Day, it’s a chance to reflect on how far we’ve come in securing our digital lives and recognize how much more needs to be done. Passwords remain one of the most common attack vectors for cybercriminals, with over 80% of data breaches traced back to compromised credentials. However, as critical as password security is, it is only the first step in an effective cybersecurity strategy.

In today’s rapidly evolving threat landscape, relying on passwords alone is no longer enough to safeguard your organization. Many people still reuse passwords across platforms, and these weak practices open doors for cyberattacks. This is why adopting a more comprehensive security approach is essential. The Zero Trust model, for example, advocates for “never trust, always verify,” meaning every access request is continuously validated. Along with frameworks like this, businesses should integrate additional security measures such as multi-factor authentication (MFA), continuous monitoring, and threat detection. These solutions not only help secure access but also provide real-time visibility into your network, allowing you to quickly detect and respond to potential breaches before they escalate.

World Password Day reminds us that digital security requires more than just strong passwords. To build a resilient defense, businesses need a holistic approach that includes multi-factor authentication (MFA), continuous monitoring, and risk scanning. These tools help identify vulnerabilities, detect anomalies, and mitigate threats before they escalate. By integrating these practices with frameworks like Zero Trust and ensuring employee training, organizations can strengthen their security posture and quickly respond to any potential breaches.

++

Anthony Cusimano, Solutions Director at Object First
 
I mentioned this last year, but I still believe the death of the password is just around the corner. Passwords are no longer a secure method of authentication and should not be treated as secure. So, I’ll share the advice I have taken up in the last year: use a password manager, app-based or browser-based (either works!).  
 
Password managers securely store your passwords in a locked vault and come with convenient browser extensions that autofill logins. They can also generate unique, complex passwords for every account. Many of these tools allow you to customize password requirements according to your preferences, including specifying length and incorporating symbols, numbers, and mixed case. Additionally, password managers can alert you to duplicate or weak passwords and often suggest optimal times for changes.  
 
The password alone is NOT a secure authentication method; that’s why I have given up trying to maximize their security and left the brainwork to someone else. It’s 2025, let an app do the password legwork for you, and here’s to hoping that passwords become a thing of the past sooner rather than later.  

++

Takanori Nishiyama, SVP, APAC Sales & Japan Country Manager, KEEPER SECURITY

Why “Clever” Passwords Aren’t Fooling Hackers This World Password Day

We’re celebrating this World Password Day (May 1) in the age of generative AI, where traditional password tricks such as substituting “a” with “@” or adding an exclamation mark at the end don’t offer enough protection. Hackers today use password-cracking tools, many powered by machine learning that can guess common patterns and character swaps in a matter of seconds, meaning that being clever isn’t secure anymore. The more we rely on predictable behavior, the easier we make it for attackers to breach our accounts.

According to Keeper Security’s 2024 Future of Defense report, 95% of IT leaders say cyber attacks are more sophisticated than ever before, with password-related attacks ranking among the top five fastest-growing threat vectors. To stay safe, users must practice good password hygiene by using passwords with at least 16 characters with upper and lowercase letters, numbers and special characters, and using a unique password for each account. They should also enable Multi-Factor Authentication (MFA) wherever available. For both consumers and businesses, adopting a zero-knowledge, zero-trust password management system is essential in defending against phishing, credential stuffing, and other password-related threats.

On the enterprise side, implementing a Privileged Access Management (PAM) solution is equally critical, it enforces least privilege access and empowers IT and security teams to manage sensitive credentials, secrets, and remote access more securely. In the event of a breach, PAM tools help contain the damage by limiting lateral movement within the network.

World Password Day should be more than just a reminder, it should be a turning point. It is time to move from awareness to action, with real investment in tools and practices that protect every user and uphold the principles of strong cybersecurity especially with the threat of AI-wielding hackers growing year-on-year.

++

Arun Shrestha, CEO, BeyondID

Passwords are no longer a viable line of defense in today’s threat landscape, and World Password Day now serves as a reminder of just how outdated this method of authentication has become. Once considered a cornerstone of digital security, passwords are now a liability. With credential-based breaches still leading the charge and phishing attacks surging, fueled by generative AI and deepfakes, traditional login systems are not just ineffective, they’re dangerous. Even multi-factor authentication, while a step up, has proven vulnerable to SIM swaps, push fatigue, and configuration flaws.

To truly protect users and data, organizations need to adopt passwordless authentication. Solutions like passkeys, device-bound biometrics, and FIDO2 remove the human error that comes with creating and managing passwords. This shift not only strengthens security but also improves the user experience and reduces help desk costs tied to password resets. In today’s environment, where identity is both a top target and a critical line of defense, it’s clear that we need to move beyond outdated practices. The future isn’t about better passwords, it’s about leaving them behind altogether.

++

Joel Burleson-Davis, Chief Technology Officer at Imprivata

This World Password Day, it seems appropriate to shift the discussion from securing and managing passwords to the demise of the password. Passwords have served us well (sort of), and we’ve been long talking about ditching the traditional, complex password because of their burden and unintentional insecurity. However, with every second mattering in critical work, now more than ever, passwordless authentication has become business-critical. There are signs of good adoption of both passwordless strategies and shunning our old password-burdened ways in mobile devices, which are built with and extensively leverage facial recognition for security purposes, but some of our most critical technologies in our most critical sectors have been reluctant to implement similar solutions in their operations. As life- and mission-critical industries like healthcare and manufacturing cope with staffing challenges while being increasingly targeted, it’s time they reconsider access management and their relationship with the password paradigm.
 
In healthcare, for example, and in particular, the delivery of health care, where a 17-character password is not practical for clinicians who are treating patients who need rapid and frequent access to Electronic Health Records (EHRs) in all kinds of situations. Entering a complex password for these users only creates barriers that delay patient care, eats up clinician time, and exacerbate burnout.
 
Passwordless solutions, particularly biometrics-based ones, offer a tailored and frictionless experience that enables everyone from healthcare providers to manufacturing operators to maintain the highest security standards while empowering them to deliver timely, critical work without unnecessary barriers. I look forward to a World Password Day in the future that is full of cheering and celebration because we’ve finally released ourselves from the burden of putting memorized, complex strings into a little prompt box for the sake of security.

++

Carla Roncato, VP of Identity at WatchGuard

Today, it’s not just careless password reuse or weak combinations that pose a threat, it’s the industrial-scale theft and sale of login data. Credentials are harvested through phishing, malware, and breaches, then packaged, sold, and exploited at astonishing speed. A single leaked password doesn’t just unlock one account, it can be a skeleton key to an entire digital identity.

Dark web marketplaces function with the efficiency of e-commerce platforms, complete with customer service and user reviews. For as little as a few dollars, attackers can purchase verified credentials tied to financial services, corporate VPNs, or personal email accounts. Once inside, they move laterally, escalate privileges, and often remain undetected for weeks or months.

On this World Password Day, the question is no longer “Are your passwords strong enough?” but “Do you know if your credentials are already out there?”

Organizations must treat credential exposure as a threat to be hunted and mitigated, not just a hygiene issue. That means proactive monitoring of the dark web, real-time alerting on compromised credentials, and an incident response plan that assumes breach, not just tries to prevent it. Cybercriminals have evolved. It’s time our mindset around password security evolves, too.

++

Munu Gandhi, President of IT Solutions at Xerox

On World Password Day, I encourage every organization to prioritize strong password protocols as a critical part of cybersecurity. At Xerox, we’re committed to Zero Trust principles, using multi-factor authentication, regular updates, and user education to protect data wherever it’s accessed. Strong passwords aren’t just good practice, they’re essential to keeping your business secure.

++

Tony Ball, President of Payments & Identity at Entrust

For decades, passwords have been the weak link in cybersecurity – outdated, overused, and increasingly ineffective. But now, organizations are making a clear shift. Multi-factor authentication and sign-in links have emerged as the primary methods for user authentication across the US, UK and globally, overtaking passwords.
 
This step change comes as over half of business and IT decision-makers report higher fraud attempts with username and password alone compared to other methods. We’re at a cybersecurity inflection point: passwords are no longer sufficient. Modern, layered authentication methods, such as facial biometrics, device recognition, or generated codes, are stepping in.
 
Rather than forcing users to create longer, more complex passwords, it’s time for organizations to embrace a passwordless future – one where customers and employees can prove their identity conveniently and securely using their biometrics. This approach reduces risk, streamlines access, and meets the expectations of today’s digital-first users.

++

Erik Nordquist, Global Managed Security Product Director at GTT

As cyber threats continue to evolve, one of the simplest yet most powerful defenses against attacks continues to be proper password hygiene. Weak, reused, or easily guessed passwords are still among the most common attack vectors. Once exploited attackers can access the network and quietly install malware, exfiltrate data or move laterally through systems. If a network lacks a vigilant detection policy such as one that is performed with a managed security service provider, infringements may not be detected for weeks or even months.

Strong password practices, like using complex, unique passwords for every account and enabling multi-factor authentication, act as a critical barrier against unauthorized access and identity compromise. Tools such as password managers can make life easier for users without sacrificing security. And don’t overlook training. Regular reminders, quick refreshers, and building a security-aware culture can go a long way in keeping your network safe!

In today’s interconnected digital landscape, password security isn’t just an IT issue, it’s a fundamental aspect of personal and organizational risk management. 

++

Jared Atkinson, Chief Technology Officer, SpecterOps

On World Password Day, we take a moment to recognize the importance of strong authentication practices. From using complex passwords to enabling multifactor authentication and leveraging password vaults, these measures form the bedrock of identity security. But while these tools help protect credentials at rest and during login, they don’t address what happens next when identities are in motion.
 
Once authenticated, users generate sessions, browser cookies, Kerberos tickets, and other forms of temporary identity that move across the environment. These credentials in transit are often overlooked, yet they present some of the most attractive targets for attackers. Adversaries don’t need to break passwords if they can steal an active session. This is where Attack Path Management becomes essential shedding light on how these ephemeral identities can be exploited and how a single compromise can cascade through an environment toward full domain control.

++

Stephen Christiansen, Principal Security Consultant at Stratascale

First and foremost, there needs to be an emphasis on creating strong, complex passwords. These should contain a mix of numbers, letters, and special characters. Avoid easily guessable things like birthdays or pet names. Next, avoid using the same password across multiple systems. This minimizes your risk in case one service is compromised. Lastly, if your company offers a password manager, provide training on how to use it.

The best thing companies can do to improve how people log in to their systems is offer some form of multi-factor authentication (MFA). This requires a user to not only use a strong password, but also adds additional layers of security through a device or biometrics, or even all three. That way, even if the password is compromised, the bad actor is stopped by the other requirements.

No one wants to make logging in even more cumbersome than it already can be. Leveraging technologies like single sign-on (SSO) allows users to access multiple systems with the same authentication model. And by using behavioral analytics, you can monitor users for abnormal or suspicious activity. Lastly, you can adopt passwordless options like biometrics or “magic links” sent to verified email addresses, which is not only secure but user-friendly!

++

Sam Peters, Chief Product Officer at ISMS.online

World Password Day marks the importance of strong and secure password use, but good password hygiene is only one element in a robust cybersecurity posture. Social engineering attacks and business email compromise (BEC) are still among the most effective ways for attackers to take advantage of the human element of a business and gain access to key systems, data and funds.
 
The ISO 27001 framework outlines information security best practices such as multi-factor authentication, role-based access control and employee information security training and awareness. These are core security measures businesses need to consider alongside good password hygiene.
 
Over a third of respondents (35%) in our latest State of Information Security Report stated that employees had used personal devices for work purposes without proper security measures, which leaves gaps that threat actors can easily exploit. This highlights the importance of organisation-wide training and awareness – as well as the importance of implementing information security best practices.
 
World Password Day presents an opportunity for businesses to analyze their existing security efforts and identify areas for improvement.

++

David Cottingham, President of rf IDEAS

While cybersecurity and IT leaders have become more aware of the risks that password-based authentication systems pose for their users and data, action continues to be delayed. All it takes is one vulnerable end point to open the door to an account takeover and passwords increase that risk daily. I would urge companies across industries to evaluate their credential strategy and migrate to more secure options before a breach happens so the investment can be made in bolstering security infrastructure and not breach consequences.

++

Jon Fielding, managing director, EMEA, Apricorn

Poor password management can allow attackers to guess or steal user credentials before putting them up for sale on the black market. Those login details can then be used for credential stuffing attacks to access and take over online accounts and to carry out fraud. Yet despite the risks, more than a quarter of businesses (27%) still don’t have a password policy compelling users to set a strong password, according to the Cyber Security Breaches Survey 2025, even though this is considered basic cyber hygiene.

For those businesses that do have a password policy in place, it’s imperative that the user is required to set a complex password i.e. of a sufficient length and containing a variety of characters and mix of upper and lowercase letters. However, it’s no longer the case that this should be changed on a regular basis and this can even be counterproductive. Making frequent password resets can frustrate users and lead to them making small changes to the original password or making them easier to remember and therefore bruteforce.

Thankfully, password managers that can generate unique passwords for us are now much more widespread and are integrated into numerous browsers. These have also driven down the problem of password reuse whereby the same password is used for multiple accounts. But our dependency on these password managers does of course run the risk of them being attacked so it’s important to safeguard access. In addition to a strong master password, the password manager should also therefore be protected using a secondary measure such as two factor authentication (2FA).

What many businesses often neglect is the password protection afforded to their peripherals, instead focusing on the usual endpoints i.e. desktop, laptop and mobile phone. External hard disk drives or even USB sticks should be encrypted and password protected and, where users are allowed to use their own personal peripheral devices, these requirements should be specified in the acceptable use policy. Protecting these devices in this way ensures that if they do get lost or fall into the wrong hands they will remain unreadable.

The imminent death of the password has been predicted on numerous occasions with passkeys and biometrics attempting to usurp it. But the humble password continues to be the primary way many of us protect our data and is likely to remain so for years to come, bolstered by additional security such as multi-factor authentication and zero trust.

++

Brian Pontarelli, CEO of FusionAuth

The teams building the future of passwords are the teams that are building and managing the login pages of their apps. Some of them are getting rid of passwords entirely, others are not familiar enough with the alternatives to make the move; a recent survey of teams building auth on their own showed that passkeys (a replacement for passwords) were the feature that teams were both most familiar with AND least familiar. In short, passkeys are the most polarizing feature for the teams building the future of login so the future of passwords is certainly not certain.

++

Ashley Rose, CEO of Living Security

Password misuse is a business/security alignment issue. We need to understand the business friction (visibility) around authentication and think with a secure by design mindset, implementing SSO/passwordless logins, allowing for use of password managers at work and at home etc. Where Human Risk Management (HRM) comes in is visibility and prioritization of efforts. For instance, if you see a segment of higher risk users with a lot of access, we will want to start here to develop a policy around passwords (i.e. implement password manager or reset policies), or train, or change authentication processes versus trying to boil the ocean.

++

Nicolas Fort, Director of Product Management at One Identity

Passwords have come a long way, from punch-tape reels in 1961 to the world of multi-factor authentication and fingerprint identification we inhabit today. The next leap is already happening – passkeys tied to devices, one-time AI-generated tokens, and even blockchain-backed session receipts. It’s no accident that password technology is constantly evolving. Cyberattacks are more frequent, threat actors have more sophisticated tools at their disposal, and as businesses continue to store more and more sensitive data online, regulators are rightly demanding that they keep up.

HIPAA, the EU’s NIS2, the UK’s Cyber Resilience Act, DORA and countless other rules and regulations all now demand rock-solid control over user accounts at every single touchpoint. That means audited sessions, behavioral analytics, rotating passwords, and just-in-time credentials – so that no matter how hard attackers try, there’s simply nothing there to steal.

++

Michela Resta, Data Privacy and Cyber Security Solicitor at CyXcel

Everyone knows they shouldn’t use their child’s name or their date of birth as a password. But the real habitual change comes when people understand why. We live our lives online. A quick scroll through social media can reveal your children’s names, your football allegiances, or the street you grew up on. This data, while seemingly innocent, can become the building blocks of a hacker’s social engineering playbook. It’s therefore advised that passwords steer clear of anything that can be gleaned from your social media feed and instead adopts a mix of upper- and lower-case letters, numbers, and special characters.
 
World Password Day is not just important for individuals, organisations also have a role to play. For organisations, good password hygiene is not just having a password policy but enforcing it. If a policy mandates ten-character passwords with a mix of symbols, numbers, and uppercase letters it is fundamental that your systems back this up and does not let users bypass the rules or recycle their old passwords.
 
However, we must all remember, passwords, no matter how strong, aren’t “hacker” proof. Even with Multi-Factor Authentication, risks like device compromise and social engineering can lead to a breach. This underscores the importance of organisational resilience. It is essential that organization not only implement strong cyber security measures but also maintain a well-developed and regularly tested incident response plan. Conducting tabletop exercises can ensure that in the event of a breach, organisations are equipped to respond effectively and minimize impact.

++

Patrick Harding, Chief Product Architect, Ping Identity

Passwords have long been a security crutch and in today’s digital landscape, they’re quickly becoming a liability. Users continue to rely on weak, repurposed credentials, making them easy targets for sophisticated cyberattacks fueled by AI. Recent data shows that 87% of consumers are concerned about identity fraud, yet many still depend on outdated methods to secure their most sensitive data. Even worse, 48% of IT leaders admit they’re not confident their current defenses can withstand AI-driven attacks. That should be a wake-up call. With the rise in phishing, credential stuffing, and deepfake scams, it’s time for organizations to retire traditional passwords altogether.

In the spirit of World Password Day, we must double down on access solutions that eliminate the guesswork and the risk. Passwordless authentication, like biometrically protected passkeys and secure device-based login, not only strengthens security but also improves the user experience. Organizations must embrace a future where identity is both frictionless and fundamentally more secure.

++

Denny LeCompte, CEO of Portnox

World Password Day underscores the persistent vulnerabilities of password-based authentication, from prevalent reuse to susceptibility to social engineering. Despite the added security of Multi-Factor Authentication (MFA), a significant majority of security leaders, particularly in younger companies, are increasingly concerned that MFA alone isn’t sufficient against evolving threats. This reality fuels the growing interest in passwordless authentication methods, driven by the fact that compromised passwords are implicated in a large percentage of security breaches.

While only a small fraction of organizations have fully adopted passwordless solutions, a substantial number are in the process of implementation or actively planning to do so. CISOs anticipate significant benefits, including stronger access control and improved employee experience. However, challenges such as cost, complexity, and potential user resistance need careful consideration for widespread adoption.

The transition to a more secure, passwordless future necessitates a strategic approach. Organizations must prioritize robust identity verification methods, like certificate-based authentication, and embrace a zero trust security model. Continuous risk assessment, employee education, and fostering a strong security culture are also critical.

Although passwords may not disappear immediately, the momentum towards passwordless authentication is undeniable. World Password Day provides a valuable opportunity to not only acknowledge the frustrations with passwords but also to actively explore and implement promising alternatives that can lead to a more seamless and secure digital experience.

++

Thomas Richards, Director of Infrastructure Security, Black Duck

Using passwords to authenticate users will continue to be the main way to authenticate for the foreseeable future.  Authentication mechanisms are further strengthened by the use of multi-factor authentication as a way to validate that the intended user, and not an imposter, is trying to access the system.  What we’re seeing lately is organizations shifting to identity management systems to reduce the instances where a user will need to re-enter their password so long as they are authenticated properly.

Password managers offer a convenient and secure way for people to store their passwords.  Following good password hygiene, it is best to use a different and complex password whenever possible.  It’s just not feasible for most people to remember all these passwords so the password manager is a great resource. However, now password managers are becoming the target for malicious actors since they store all the sensitive information needed to compromise an account.  Password manager developers should perform targeted penetration tests and red team activities against the software along with any supporting infrastructure.  Threat modeling activities should also be performed so these developers can get an understanding of how their platform or software can be attacked.  Users should also enable MFA whenever and wherever possible to add an additional layer of security to their accounts.

++

Chad Cragle, CISO, Deepwatch

Every year, World Password Day serves as a timely reminder to take control of our personal password strategies. In today’s digital culture, we use passwords for everything – from simply accessing your smartphone, to signing into your remote workspace or checking your bank statements. Research shows that the average person manages around 255 passwords, between personal and workplace apps, websites, and services. Strong password habits are more important than ever.

To better safeguard your personal and professional data, a few simple best practices can make a big difference. Always use complex passwords that include a combination of upper and lowercase letters, numbers, and symbols, and avoid storing them on paper or in plain sight on your desktop. Consider using a password manager to securely store and encrypt your credentials. And for an added layer of protection, enable multi-factor authentication whenever possible. These small steps may seem tedious, but they are essential to defending against data breaches and keeping your most sensitive information secure.

++

Kern Smith, VP of Global Solutions, Zimperium

World Password Day is a timely reminder: passwords are only as strong as the device they’re stored on. As cybercriminals adopt a mobile-first attack strategy, mobile devices have become the front door to corporate access and a primary target. Through mishing (mobile-targeted phishing), malware, and other tactics, attackers are stealing credentials by compromising the mobile endpoint. Strong passwords matter, but without securing the device, they’re not enough. Organizations need mobile-specific protection that can detect and stop threats before credentials and critical data are exposed.

++

Ashish Jain, CTO at OneSpan

World Password Day is a reminder that the future of authentication is here and it’s passwordless. Passwords have long been a point of vulnerability, often leading to breaches and user frustration. Passkeys, on the other hand, represent a meaningful step toward improving both security and usability, moving us closer to a more resilient digital infrastructure. They’re especially valuable in securing high-risk interactions like financial transactions, where strong, phishing-resistant authentication is critical.

FIDO passkeys take traditional authentication a step further by using cryptographic credentials stored on a user’s device, ensuring both identity verification and security. This method strengthens authentication across desktops and mobile devices, creating a more secure digital environment. As the adoption of passkeys grows, I’m confident they will be key to transforming how we protect our most sensitive online interactions.

++

Bojan Simic, CEO, HYPR

On this World Password Day, we’re at a pivotal juncture in identity management and IT security. For the first time, we’re witnessing an actual turning point in the fight against identity-based attacks. A recent report reveals some sobering truths about the risks of outdated authentication. Nearly 49% of organizations experienced breaches last year, with 87% linked to identity vulnerabilities. These breaches resulted in an average financial loss of $2.5 million per incident and operational and reputational fallout.

These vulnerabilities are amplified by the rapid rise of generative AI threats, with 40% of organizations encountering a GenAI-related security incident and a staggering 95% reporting deepfake attacks. Traditional methods, such as passwords and legacy multi-factor authentication (MFA), cannot combat these sophisticated threats. Yet, organizations continue to rely on outdated practices, exposing themselves to escalating risks.

The good news? We are entering The Identity Renaissance. For the first time, passwordless, phishing-resistant authentication methods, such as FIDO passkeys, are gaining significant traction. Nearly half (46%) of organizations have adopted these innovative solutions and are poised to become the gold standard in authentication by 2027. This marks a profound shift in how we approach security, moving beyond reactive measures and embracing proactive, user-friendly, and resilient solutions.

A transformation is taking place. By eliminating passwords and empowering organizations with modern identity verification tools, we are enhancing security and laying the foundation for growth, innovation, and improved user experiences.

Today, I challenge leaders across industries to break free from outdated methods and join us in redefining identity security. The stakes have never been higher, but the opportunities to innovate and safeguard our digital future have never been greater.

++

Tyler Moffitt, Sr. Security Analyst, OpenText Cybersecurity

World Password Day highlights a critical truth: while traditional passwords are fading, securing digital identities has never been more urgent. As we move toward a passwordless future, passkeys, backed by device-based biometrics and public key cryptography, are poised to reshape authentication. By the end of 2025, 25% of the world’s top 1,000 websites are expected to support passkeys, a shift driven by their ability to prevent phishing attacks and data breaches while simplifying user experiences.

However, no solution is flawless. Passkeys, though promising, are still emerging. They face adoption hurdles, including limited support across platforms and challenges for users unfamiliar with biometric security or cryptographic keys. Transitioning to passwordless authentication demands more than just new technology, it requires layered defenses, strong recovery mechanisms, and continuous user education.

As authentication evolves, fundamentals still matter. Staying vigilant, practicing good security hygiene, and embracing modern tools like passkeys with eyes wide open is the best way forward.

++

Melissa Bischoping, Head of Security Research at Tanium

On this World Password Day, it’s worth reflecting on how far we’ve come, and how far we still need to go in securing our digital identities. The humble password has been a cornerstone of how we access data and technology since 1961 when MIT’s Compatible Time-Sharing System (CTSS) became the first system to leverage modern passwords for safeguarding access to private files. In the 64 years since, passwords have evolved in length, complexity, and character requirements, but despite these advancements, they’ve also introduced layers of complexity to the user experience resulting in a more burdensome method of securing identity and file access.

Today, the average user manages 80-100 passwords more than most of us can possibly keep track of. As a result, we’ve entered the era of password managers, in other words one “super password” to secure all the others. On the surface, this is a major step forward in usability (and an essential method to encourage users to use complex, unique passwords for every account) but we’re still not getting it quite right when it comes to password security.   

Here are a few key tips to strengthen password security:  

For software providers:

  • MFA should be mandatory and not locked behind a premium subscription tier.
  • All apps should enable single-sign-on (SSO) by default for easier management of secure accounts.
  • Don’t make it unnecessarily difficult to update or change credentials, this will make the user more likely to stick to the outdated, weaker password.
  • Software providers should spend more time on meaningful user experience research and design for password management.

For technology users:  

  • Secure your primary password with additional levels of protection like robust, phishing-resistant MFA
  • Use at least one form of MFA, and for most users, any MFA is better than none. 
  • For better security, use passkeys or hardware tokens (like Yubikeys) over passwords paired with SMS-based MFA. 
  • Take advantage of password manager features like password audits, reuse detection, and breach alerts. 
  • Review your cell phone provider’s offerings for additional layers of security to prevent a SIM-swapping attack. 
  • Review your email provider’s additional security features that can be enabled; this is especially important since email accounts are often used as a password recovery option for OTHER accounts.
  • Using more secure alternatives, like passkeys, in modern operating systems and apps can help less-technical family and friends adopt stronger protections for their data.
  • Regularly check the security for SSO accounts used for logging into platforms like Google, Facebook, and AppleID. These individual accounts can be the “keys to the kingdom” for an attacker, so they warrant additional protections.

++

Gerald Beuchelt, CISO, Acronis

While the shift toward Passkeys and password-less authentication is gaining momentum, passwords remain a critical part of our digital security. To reduce the risk of compromise, use long, complex passwords think at least 16 characters or a short sentence without spaces. Avoid common or predictable choices like ‘1234567890’ or ‘qwertyuiop,’ and never reuse passwords across sites. Enabling multi-factor authentication is one of the most effective defenses available, and a trusted password manager can simplify it all while keeping you protected.

++

David Morimanno, Director of Identity & Access Management Technologies, Xalient

This World Password Day is an essential reminder to all of the importance of regularly updating passwords and enabling multiple-factor authentication where possible. However, as we become an increasingly digital society facing constant cyber threats, the number of passwords we require in our daily lives is increasing to the point that it’s unsustainable to change every single one.

For enterprise IT environments this is a key challenge as hybrid work strategies blur the lines between employees’ personal and professional lives. With individuals juggling potentially hundreds of passwords, the risks multiply. At worst, employees may reuse passwords across personal and professional accounts or become fatigued by frequent prompts to change them. That leads to shortcuts such as reusing a single strong password across multiple accounts or making only minor variations. Furthermore, if an employee were to forget their credentials, this can be a considerable cost to the company. As stated by Forrester Research, the average help desk labour cost for a single password reset is about $70. Whilst passwords are often viewed as an essential cybersecurity measure across both personal and company accounts, the truth is that they are one of the weakest links in cybersecurity defense. Though they are necessary in some areas, over-reliance on passwords is unsustainable, unsafe, and a potential financial drain to companies.

However, the growing adoption of FIDO2 (a protocol for secure, passwordless authentication) offers a valid alternative by demonstrating that passwordless authentication can securely validate user identities. 2025 is predicted to mark a shift towards passwordless authentication, building on the momentum already seen in 2024. While it is unlikely that passwords will disappear entirely, the reliance on them will diminish as companies move to verification methods like tokens and biometrics. This transition will result in tighter enterprise security, reduced costs associated with password resets, and mitigation of the risks posed by human error. A move toward fewer, more secure password systems is also an opportunity to redefine how passwords are managed. With less passwords to remember, companies and individuals alike will find it easier to maintain complex, regularly updated credentials, leaving little room for excuses when it comes to good password hygiene.

As cybersecurity leaders reimagine the future of passwords in today’s digital landscape, companies should prioritize exploring alternative employee verification methods and shifting their focus toward robust identity management solutions rather than traditional credentials. This proactive approach will not only minimize attack vectors but also enhance security, streamline user experiences, and reduce productivity loss caused by tech-related issues.

++

Prashant Kumar, Forcepoint’s X-Labs Research Team

In light of World Password Day, organisations must remember that one of the most important parts of its defence is its people. Employees must be aware of their role in organisational security. This includes the basics such as maintaining strong passwords and leveraging technologies like MFA, but should also include their ability to be constantly cyberaware. This means organisations have a role to play in ensuring employees know how to identify and act when faced with an attack. Human error can be the weakest link in the security chain, so it is important that staff are educated.

++

Chandramouli Dorai, Chief Evangelist, Security Solutions and Digital Signature at Zoho

Passkeys are a modern alternative to traditional passwords, providing better security and convenience. With the rapid growth of digital usage, many first-time internet users are vulnerable to cyberattacks. Unfortunately, most users rely solely on passwords for protection, often creating easily guessable combinations or reusing them across multiple accounts. In the workplace, poor password sharing practices within the team further increase the risk of attacks, leading to potential data loss and financial damage. Passkeys offer a more secure solution, with a unique and auto-generated private key that only works on the associated device and authentic websites. They also eliminate the need to remember complex passwords and can serve as both a login and two-factor authentication method. Additionally, passkeys can be synced across devices and are supported by secure components like Trusted Platform Module and Secure Enclave. Password Day or Passkey Day- the core idea is to protect our online accounts with improved security.Stay secure online! Be vigilant!

++

Art Gilliland, CEO at Delinea

Passwords still are the gatekeepers of our digital identities, but relying on traditional passwords are simply not enough. Cybercriminals are getting smarter when attacking passwords – especially those tied to privilege accounts – to breach networks and access sensitive data. With 80% of security breaches involve misuse of privileged credentials, it’s clear that organizations must adopt a Privileged Access Management (PAM) approach, combined with Zero Trust principles for data protection.

It’s essential to use World Password Day as a reminder that password security alone isn’t enough. We must never assume trust – especially privileged accounts – and always verify every access request.

By taking control of who has access to what, when and how, organizations can significantly reduce the risk of breaches. Smart identity security starts with Zero Trust and PAM – because data safety begins with stronger, verified access.

++

Josh Weinick, Sales Engineer at BlinkOps

For security and IT teams, World Password Day is a reminder to educate and enable their organizations, while also forcing a critical look at incident response rates. Businesses cannot risk the inability to stop suspicious cybercriminals at all hours, and with threat actors logging in instead of breaking in, automating your tech stack to mount a real-time response is non-negotiable.

While automating across all domains, identity, cloud, IT, and beyond, is essential to minimizing the blast radius of credential-based attacks, many organizations are challenged to do so in a timely manner. According to BlinkOps’ 2025 State of Security Automation report, 45% of organizations took up to three months to implement their most recent automation, a lag that significantly increases exposure. Teams must prioritize time to automation and go beyond strong password best practices to actually protect their data.

++

Drew Perry, Chief Innovation Officer, Ontinue

As positive a day as World Password Day is, I look forward to the day it no longer exists or is at least renamed! With the rise of passkey support across major platforms and devices, we’re finally seeing a shift towards more secure and user-friendly authentication. Passkeys are cryptographic credentials that eliminate the need for passwords entirely, offering phishing-resistant, biometric-based access. It’s time we moved beyond passwords, which are too often reused, weak, or compromised. Simpler identity protection is needed so we, as humans, don’t just pick a random string of characters that we will never remember!

We have come a long way. Password manager adoption is rising, multi-factor authentication is available for most critical online services, and people are reusing the same passwords less. But still, hackers are succeeding in their attacks. We have been saying since the early 2010s that “hackers don’t hack in, they log in”, and as time goes on it becomes even more true.

Stolen credentials overtook email phishing as the second most frequently observed initial infection vector in 2024 during intrusions into businesses. At Ontinue, we have witnessed first-hand the rise of sophisticated infostealer malware, which captures passwords as they are entered by users during login. This enables attackers to simply log in if no other secondary authentication methods are enabled which, sadly, is often the case.

Awareness is key. Enable passkeys where possible.

I suggest we lay the password to rest and embrace the passwordless future.

++

Chase Doelling, Principal Strategist and Director at JumpCloud

World Password Day is an important reminder that the basics matter in cybersecurity. The threat landscape is more tumultuous than ever, and human error is still our greatest weakness. While we try to throw as much technology as possible at this nagging problem, the reality of the situation is that MFA continues to be the easiest, and most efficient, resource in secure access management.
 
We’ve long heard about “MFA fatigue” when employees just click “yes” when they see an approval request come through because they are sick of seeing them come up and assume it is from a legitimate source. It has also become the catalyst for questions around the efficacy of MFA long-term. While a valid concern, the truth is that MFA is still our best option to safeguard access control. The real issue lies with educating employees and incentivizing them to take cyber hygiene seriously.
 
A recent study found that 83% of organizations use password-based authentication for most IT resources and also require MFA, and over two-thirds require biometrics. However, 67% of IT professionals agree that adding additional security measures means a more cumbersome experience for users. Personally, I think it’s amazing to see that organizations are continuing to invest in MFA – and that investment doesn’t just go away. Organizations need to capitalize on those investments further by regularly explaining to employees the consequences of a security breach and encouraging positive reinforcement when hygiene best practices are followed. MFA isn’t going away, nor should it, so IT security teams need to change the way MFA is communicated rather than finding alternatives to accommodate its fatigue. 

++

Tim Eades, CEO & Co-Founder at Anetac

As we recognize World Password Day, it’s time to acknowledge a fundamental matter in identity security. Credentials are the keys to the castle. Passwords alone cannot safeguard our digital identities in today’s complex, hybrid environments. Identity-based vulnerabilities have become the primary attack vector for modern breaches.

Our research reveals alarming statistics across industries: passwords unchanged for 15+ years in financial institutions, 74% of healthcare credentials remain unchanged for over 90+ days and widespread credential sharing in critical infrastructure. The basics are critical. Without proper cyber hygiene, enterprises across the globe will continue to be victims of bad actors. Weak or unchanged passwords across human and non-human identities create a dangerous, and often overlooked, security gap which can quickly go from a headache for security teams to a full blown breach. A dormant service account or an orphaned human account with an old or weak password are a bad actor’s most exciting find. Utilizing complex passwords, refreshing them every 3 months, using multi factor authentication when available, and investing in modern identity security solutions are necessary to minimize the likelihood of a breach.

That’s why password hygiene remains a cornerstone of effective identity security. The ability to detect and assess credential age, behavioral anomalies, and lifecycle blind spots across all identities is critical. Identity security isn’t just about who has access, it’s about how that access is managed, monitored, and secured over time. Not only this, you need the tools to actually know the identity behind the account and that they are who they say they are.

Passwords aren’t disappearing, but their importance in our security strategies must be properly acknowledged within the broader identity ecosystem. It may be an aging technology, but they remain a top attack vector and we need to treat them, and the accounts they protect, with the same seriousness we give to any other security asset.

##