News and updates from Maple

Passkeys: what "going passwordless" actually means image

Passkeys: what "going passwordless" actually means

Passwordless login has been promised for years without quite arriving. The data from 2026 suggests it's finally happened, at least in part, and it's worth understanding what that actually means for a hybrid team rather than treating it as background technology news.

What's actually changed

The FIDO Alliance's State of Passkeys 2026 report, based on research across 11,000 consumers and 1,400 enterprise decision-makers, puts a number on it: an estimated 5 billion passkeys are now in active use worldwide, and 68% of organisations are deploying, piloting or rolling out passkeys for employee sign-in. The performance case is strong too: separate FIDO data, from its Passkey Index published in October 2025, found passkey sign-ins succeeding 93% of the time against 63% for other sign-in methods such as SMS codes, email links and social login. Unlike a password or a text-message code, there's nothing for a phishing attempt to steal, because there's no shared secret being typed anywhere.

The honest gap in that data, though: 57% of organisations still rely on phishable authentication, passwords, or basic app codes, for employees' day-to-day sign-in. Passkeys have arrived. The actual transition mostly hasn't.

What a passkey actually is, in plain terms

A passkey is a cryptographic key pair generated and stored on your device, unlocked with a fingerprint, face scan or device PIN. There's no password to remember, type, reuse or have stolen. This matters directly for something we've covered before on this blog: newer phishing kits work by stealing a login session the moment someone approves an MFA prompt, code and all. A passkey has no equivalent moment to intercept, because there's nothing being typed or sent that an attacker could capture.

Why "we've got passkeys available" isn't the same as "we're protected"

This is where most businesses currently sit, and it's the gap worth closing. Offering passkeys as an option alongside a password that still works is useful for convenience, but it doesn't remove the underlying risk, because the password is still sitting there as a valid way in. The security benefit only really lands once passkeys become the actual primary method, not an optional extra most people never get round to setting up.

What rollout actually looks like for a hybrid team

A few things are worth planning for properly, rather than assuming a passkey rollout is a simple toggle:

● Multi-device enrolment: someone working from home, the office and a phone on the train needs their passkey to work cleanly across all of them, not just the device it was first set up on

● A real recovery process: what happens when someone loses their device or gets a new phone matters more for a hybrid team than an office-based one, since there isn't always someone physically nearby to help sort it out

● Compatibility gaps: roughly 48% of the world's top 100 websites now support passkeys, more than double a few years ago, but that still leaves plenty that don't, so passwords aren't disappearing everywhere at once

● A staged rollout: starting with the people who have the most sensitive access, finance, leadership, anyone handling client data, rather than trying to switch everyone over on the same day

Where we come in

We help clients roll out passkeys properly across a hybrid team, sorted around the actual pain points, enrolment, recovery, and picking where to start, rather than switching on a feature and hoping it sticks.