Summary is AI-generated, newsdesk-reviewed
  • 35% of firms fail in timely access revocation, impacting identity security in enterprises.
  • 59% of companies manage multiple credential systems, increasing digital identity complexity.
  • Phishing-resistant authentication prioritises breach risk reduction, yet only 13% use it widely.

The FIDO Alliance, alongside HID, has unveiled a comprehensive report titled "The State of Physical and Digital Identity in the Enterprise," highlighting the challenges faced by organisations in managing access across the workforce. This research, based on input from 500 IT and cybersecurity professionals in the US, Canada, UK, France, and Germany, reveals a gap between enterprise confidence in identity management and the operational realities they face.

The report indicates that although 94% of organisations express confidence in their ability to revoke access within 24 hours of an employee leaving, a substantial 35% encountered issues doing so in the past two years. Moreover, 70% reported experiencing at least one security incident related to identity management during this period.

Challenges in governance and complexity

Findings highlight that only half of the enterprises have unified reporting ownership for physical and digital identity, with just 48% having a consolidated budget for these activities. The financial sector experiences the highest fragmentation, with 34% maintaining separate reporting structures despite strict regulatory requirements.

Additionally, 59% of enterprises utilise three or more distinct authentication systems, and 58% noted increased complexity in managing digital identities over the past two years.

High incident rates in the public sector

Reducing the risk of phishing and credential breaches drives the move towards passwordless authentication

The research identifies the public sector as suffering from the highest rate of identity-related security incidents, with 43% of entities facing access revocation failures. Manual credential revocation in this sector is at 20%, significantly higher than that in the IT/Technology sector.

While 93% of organisations are progressing with passkey adoption, only 13% have achieved wide-scale deployment. This limited deployment correlates with elevated security incident rates, underscoring the necessity for comprehensive adoption to maximise protection against threats.

Reducing the risk of phishing and credential breaches drives the move towards passwordless authentication, cited by 45% of respondents. Another 44% aim to minimise IT costs related to password resets and help desk burdens.

Leadership Insights

The full report will be presented at Identiverse 2026, with FIDO Alliance and HID available

Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, stated, "The story in this data isn't about awareness, it's about execution. Ninety-three percent of organisations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly. Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective — because threat actors don't limit themselves to the parts of the organisation that are already protected."

Sean Dyon, Vice President of the Authentication Business Unit at HID, added, "Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organisations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems, and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights, and lifecycle management together to enable faster, more confident access decisions."

The full report will be presented at Identiverse 2026, with FIDO Alliance and HID available for discussions at booths 252 and 800, respectively, from June 15-17.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...