HID, FIDO expose enterprise identity security gap

A new report from HID and the FIDO Alliance has found that while organisations are confident in their identity security processes, many continue to experience access management failures and identity-related security incidents.

The State of Physical and Digital Identity in the Enterprise report, based on a survey of 500 IT and cybersecurity decision-makers across North America and Europe, found a clear gap between confidence and operational reality.

Although 94% of organisations believe they can revoke all physical and digital access within 24 hours when an employee leaves, 35% reported delays or failures in doing so over the past two years. Overall, 70% experienced at least one identity-related security incident.

The story in this data isn’t about awareness, it’s about execution. 93% of organisations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly.”

– Andrew Shikiar, Executive Director and CEO of the FIDO Alliance

The research also found fragmented governance, with only half of organisations having unified ownership of physical and digital identity. Nearly 60% manage three or more separate credential and authentication systems, while 58% say identity management has become more complex.

Passkey adoption continues to grow, with 93% of organisations at some stage of deployment. However, only 13% have implemented passkeys at scale. Reducing phishing and credential theft remains the main driver for passwordless authentication.

According to HID and the FIDO Alliance, the findings highlight the need for organisations to unify physical and digital identity management and accelerate enterprise-wide deployment of phishing-resistant authentication.

Related Posts