Soon, if you want to go online and submit VAT returns, register a new business, apply for apprenticeship funding or complete any of a range of routine business or personal tasks, you won’t need a password. Why?
The UK government’s official website gov.uk is swapping passwords for passkeys. The National Cyber Security Centre (NCSC) has called this shift a “major step in strengthening the nation’s digital security”.
In the wake of the recent hacks on household-name retailers by the notorious cybercrime group ‘Scattered Spider’, increased security certainly sounds like a good idea. So, what is a passkey?
A passkey is a substitute for a password. Users log in to services using digital credentials on their devices, such as a smartphone, and cryptographic tokens. It’s simple, fast and secure.
Here’s how passkeys work. When you create an account, your device generates a secure pair of cryptographic keys, one public and one private. The public key is shared with the service, while the private key remains on your device and is protected by your chosen method, such as a password, PIN, or biometric.
Your device uses your passkey application to sign that challenge and send a value back to the site or service. Only someone with the private key can do this successfully.
The private key never leaves your device. It’s not possible for it to be stolen using a phishing email or tricked out of you by someone pretending to be technical support.
To sign in on another device, the website generates a QR code. Scan it with your original device to authenticate and gain access. Most passkeys use the FIDO2 cryptographic standard. Accepted by Microsoft, Google, Apple and Amazon, FIDO2 ensures that your passkey will work across all devices.
With Microsoft Authenticator, Windows Hello, Google Password Manager or the Apple Passwords app, using passkeys is easy. These cover most major operating systems: Android, Windows, macOS or iOS.
Passkeys solve several problems that make systems protected using passwords both less secure and more difficult to use and manage.
90% of businesses that adopt passkeys report that it has reduced the volume of helpdesk incidents, and 90% say it has improved security.
These benefits make passkeys a strong choice for a range of business uses. If your team is on-site, remote or a mix of both, passkeys can help keep your company’s data safer.
Here’s how passkeys can support your business:
In all these cases, passkeys offer a fast, secure, and user-friendly way to sign in. Of course, passkeys aren’t a security ‘fix-all’ and they aren’t the best answer in every use case. You also need a robust implementation with good contingency plans.
To create the right passkey strategy, work with a cyber security partner who understands your business needs.
With the right expertise and planning, you can overcome these limitations and benefit from the advantages of passkeys while eliminating or mitigating them.
The most important part of developing a successful passkey strategy is choosing the right type of passkey for your business or organisation. Options include:
Because they can’t be stolen, compromised or guessed in the same way a password can, passkeys offer enhanced security for businesses and public-sector organisations. With the right expertise, you can begin migrating to passkeys immediately.
This is especially relevant now. Microsoft has confirmed it's retiring SMS and voice authentication for Entra ID accounts entirely from February 2027, meaning many businesses will need to move to passkeys well before then. Read our full breakdown of the deadline and what to do about it: Microsoft's SMS authentication retirement has no opt out: Here's what businesses should do.
Texaport is one of the UK’s leading managed cyber security providers. Our experts can help you train your staff and bolster your cyber security stature.
Contact us to start your passkey migration today.