The FIDO Alliance and HID today released The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their workforces.
Surveying 500 IT and cybersecurity decision makers across the US, Canada, UK, France and Germany, the new study uncovered a significant disconnect between enterprise confidence in identity security and operational reality.
While most organizations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third report experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise.
Key findings from the report include:
While confidence is high, so are security incidents
Governance is fragmented
Complexity is growing, and enterprises manage three separate systems on average
The Public Sector carries the highest incident rate of any industry
The passkey adoption must scale to protect businesses
Phishing-resistant authentication is a top business priority
“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organizations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance.
“Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organization that are already protected.”
Sean Dyon, Vice President of the Authentication Business Unit at HID, said: “Identity security is no longer just an authentication challenge; it is an enterprise governance challenge.
“As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical.
“This research shows that fragmented governance, disconnected systems and limited visibility create real business risk.
“HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions.”