70% of enterprises report identity security incidents
A FIDO Alliance and HID study finds a wide gap between enterprise confidence and the reality of managing physical and digital access.
Seven in ten organizations experienced at least one identity-related security event in the past two years, according to a new FIDO Alliance and HID report. The research examines how enterprises manage physical and logical access across their workforces.
The study surveyed 500 IT and cybersecurity decision-makers in the US, Canada, the UK, France and Germany. It covered finance, healthcare, IT and technology, manufacturing and the public sector.
The biggest gap appeared in employee offboarding. While 94% of organizations said they could revoke all physical and digital access within 24 hours after an employee leaves, 35% had experienced delays or failures in doing so.

Figure 1: Despite high confidence in access revocation, 35% of organizations experienced delays or failures, while 70% reported at least one identity-related security event.
Other incidents were also widespread. Some 32% faced phishing or social engineering attacks that bypassed existing multifactor authentication. Another 23% reported a credential-based breach or account takeover. Meanwhile, 22% experienced unauthorized access through orphaned or unrevoked credentials. Insider threats involving physical or logical access abuse affected 21%.

Figure 2: Access revocation failures were the most common identity security issue, followed by phishing or social engineering attacks that bypassed existing MFA.
Fragmented access management creates security gaps
The report links these risks to the way many organizations manage physical and digital identity. Only 50% have unified reporting ownership across the two areas, while 48% have unified budget control.
This separation matters because physical and digital access may fall under different teams, budgets and vendors. Those teams can also follow different procurement and renewal cycles. As a result, no single team may have a complete view of an employee’s access rights. A digital account could be disabled while a physical credential remains active, for example.
The study surveyed 500 IT and cybersecurity decision-makers in the US, Canada, the UK, France and Germany. It covered finance, healthcare, IT and technology, manufacturing and the public sector.
System complexity adds another layer of risk. Some 59% of enterprises manage three or more credential and authentication systems. On average, organizations manage 2.91. Each additional system can require a separate provisioning process and a separate workflow for revoking access.
Despite these gaps, many enterprises are moving toward convergence. Some 72% issue physical access credentials to most or all employees, while 95% include physical and digital identity convergence somewhere in their identity strategy.
Passkey adoption is also advancing, although deployment at scale remains limited. The report found that 93% of organizations are exploring, planning or deploying passkeys. Only 13% have deployed them at scale.
















