Filed under: Cybersecurity, IT Security, Technology
October 3, 2024
By Sean Arakawa, CISSP, CISM
Phishing, the act of sending a fraudulent email pretending to be someone else in order to access sensitive data, is still one of the top threats in today’s security landscape. In fact, most security breaches are caused by the credentials stolen in such attempts. What, then, can organizations do to defend themselves?
One of the best ways to guard against phishing is implementing passwordless identity protection. The passwordless method is a relatively recent technology development, one that has seen increased adoption by the larger platforms and tech companies, e.g. Apple, Microsoft, Google, etc.
This article will cover:
- The need for passwordless identity protection.
- How passwordless identity protection addresses residual risk.
- How passwordless identity protection shifts security focus within your environment; and
- Implementing passwordless identity protection.
The Need for Passwordless Identity Protection
Many organizations have not yet adopted passwordless identity protection and still rely on a combination of traditional authentication methods such as passwords, multi-factor authentication, and one-time passcodes.
Threat actors have a lengthy history of being able to skirt around these methods to compromise corporate credentials. With so many accounts and services being hosted in the cloud, the ability to access those accounts and associated data can be just as convenient for a threat actor as it is for the authorized user.
How Passwordless Identity Protection Address Residual Risk
Passwordless identity protection bolsters your security program by addressing any residual risk left over from your other enterprise security controls.
In addition to identity protection, most organizations also use some form of email security to help filter out these malicious emails, but there are no guarantees that every malicious email will get filtered out. What happens when a phishing email makes it past all the security controls and gets to the user’s inbox? What if the user also doesn’t realize it is a malicious attempt to steal their credentials? Chances are the credentials could get stolen by the threat actor, kickstarting a chain of bad events.
These are the instances where passwordless identity protection starts to show its benefits. You cannot steal a password if a password doesn’t exist!
How Passwordless Identity Protection Shifts Security Focus Within Your Environment
Adding this new control into your environment can shift the security focus of how and where the other security controls come into play. Passwordless authentication uses a passkey instead of a password, meaning your device with the passkey installed is now replacing your password. Revisiting the earlier scenario above where all the security controls failed: with passwordless authentication in place, the threat actor could not have stolen the credentials since the passkey was tied to the user’s device.
One of the drastic ways passwordless identity protection shifts security focus is by putting more importance on the device rather than the account. If we put this in context with our scenario, the threat actor would now need access to that user’s device, which is a dramatic difference from just needing a password, phished MFA code, or an accidentally approved MFA prompt to gain unauthorized access.
By requiring device access, we now bring all the security controls that protect corporate devices like anti-virus, application-allow listing, firewalls, and least-privilege accounts into the scenario. If your organization follows best practices with device security, that becomes a strong protection and massive reduction in risk against phishing.
You can also apply traditional authentication methods in combination with passwordless identity protection, such as multi-factor authentication, to further reduce the risk of an account being phished. In addition, most passwordless identity platforms also use conditional access and a zero-trust approach. This provides important layers of security to make it that much harder for an account to be phished.
Implementing Passwordless Identity Protection
If you aren’t already sold on the benefits of passwordless identity protection, it is also often relatively easy to implement organization-wide.
Many modern passwordless platforms give you a frictionless enrollment process, making it easy to get your entire organization onto their platform and integrate with your existing identity and single sign-on provider. The best passwordless platforms also give you flexibility with staged rollouts and automated deployment, which makes the implementation easy to scale for any size organization.
In addition to all the security benefits and ease of implementation, having a passwordless sign-in experience is typically faster and more convenient for users as they no longer need to type their password.
If you aren’t already, I strongly recommend looking into and implementing passwordless identity protection and safeguard against phishing today. If you have questions, feel free to ask us.
Sean Arakawa is a senior manager in Information Technology at Clark Nuber.
© Clark Nuber PS, 2024. All Rights Reserved.

