Stolen credentials are among the most common causes of data breaches. Phishing-resistant methods such as FIDO2 and passkeys secure identities cryptographically and strengthen zero trust architectures.
Identity is the new perimeter
For decades, security architectures were built around fixed network boundaries. Inside meant trust, outside meant suspicion. Today that boundary barely exists: applications live in the cloud, employees reach company resources from anywhere, and machines talk to each other across organizational lines. In place of the network edge, identity takes over, and it gets checked anew at every login.
That shifts the attackers' target as well. Breaking through a wall hardly pays off as long as a valid login serves the same purpose and stays invisible. A compromised identity is the master key to a successful attack: it opens mailboxes, finance systems, and development environments without setting off an alarm, because it behaves like a legitimate user. According to the latest Verizon report, stolen credentials are behind almost four in ten data breaches, and in most cases a human element plays a role.
The shared secret is the weak point
The real weakness sits in the login process. Passwords, one-time codes, and push confirmations all rely on a shared secret that can be intercepted or relayed, no matter how well the workforce is trained. Awareness training lowers the risk but doesn't eliminate it. As long as a person types in something a third party can capture, the channel stays vulnerable. That also applies to many methods that count as multi-factor authentication yet still require a transferable secret.
Phishing-resistant methods such as FIDO2 with WebAuthn work with cryptographic key pairs instead. The private key never leaves the device, and the login is bound to the genuine domain. A cloned login page gets no usable response, and an intercepted code is worthless. According to a recent Microsoft analysis, phishing-resistant authentication stops more than 99 percent of identity-based attacks.
FIDO2 is an open standard made up of two specifications. WebAuthn, adopted by the W3C, governs how the web application and browser interact, and a second protocol connects the browser to the authenticator, such as a security key or the security chip in a device. Each service gets its own key pair. At login, the service sends a random challenge, which the authenticator signs and ties to the address of the service. The server stores only the public key, so even stealing the entire login database gives attackers nothing usable.
In practice, it's worth distinguishing between synced and hardware-bound passkeys. Synced passkeys can be distributed across several devices through a platform account and make recovery and convenience easier. Hardware-bound keys stay tied to their device for good and offer the highest level of security. For especially sensitive and privileged access, the device-bound variant is the obvious choice, while the synced passkey reaches the wider workforce with little friction.
Zero trust starts with identity
Zero trust drops the assumption that a location creates trust. Every request is checked, whether it comes from the data center or from hotel Wi-Fi. Such an architecture stands or falls with the quality of identity verification. Weak authentication turns zero trust into a mere claim, while phishing-resistant authentication makes the promise verifiable.
That leads to a strategic decision many organizations haven't made yet: authentication should count as its own layer of the security architecture rather than a feature of a single identity platform. Tie the authenticator tightly to one vendor, and you create dependencies and blind spots, for example with legacy applications or when switching platforms. A method that works from the cloud service all the way down to the legacy application shrinks the attack surface and the operating effort at the same time.
The regulatory framework points the same way. NIS2 and DORA require many companies to have reliable access control and multi-factor authentication, and Germany's BSI rates modern passwordless methods as particularly secure without prescribing a specific technology. Cyber insurers in some cases already expect phishing-resistant authentication for privileged access. The market treats it as a minimum standard before lawmakers make it an explicit requirement.
From principle to practice
In practice, the order of steps is manageable. It starts with an honest inventory of identities, access paths, and the methods in use. Privileged accounts, admin access, and remote access come first, because losing them causes the most damage. The switch can happen step by step, starting with the most valuable accounts, and doesn't have to interrupt operations.
What matters is that no back door stays open. A phishing-resistant login loses its value if a weaker method remains as a fallback, because attackers always look for the easiest route. The whole lifecycle of an identity counts too: registration and account recovery are popular entry points, because they often still run over phone, email, or one-time codes. A strong login next to unprotected recovery only secures the front door. External service providers, partners, and increasingly machine identities also reach the same systems and need the same protection.
The effort pays off once the most expensive attack path is closed. For IT decision-makers, the job shifts from sealing off the network to reliably proving every identity. Those who make that shift early gain resilience long before the next attack finally disproves the old perimeter logic.