FIDO Alliance And HID Report Reveals Gap Between Identity Security Confidence And Reality

Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years

Organizations report high confidence in their ability to manage employee access, but a new study from the FIDO Alliance and HID shows that operational challenges continue to expose enterprises to identity-related security risks.

Released at the Identiverse 2026 in Las Vegas, The State of Physical and Digital Identity in the Enterprise surveyed 500 IT and cybersecurity decision-makers across the United States, Canada, the United Kingdom, France, and Germany. The findings reveal a significant disconnect between confidence in identity security programs and real-world execution.

Security Incidents Persist Despite High Confidence

The report found that 94% of organizations are confident they can revoke all physical and logical access within 24 hours when an employee leaves.

However, 35% of organizations experienced delays or failures in access revocation during the past two years. Additionally, 70% reported experiencing at least one identity-related security incident during that period.

Identity Governance Remains Fragmented

Many enterprises continue to manage physical and digital identity separately.

Key findings include:

  • Only 50% of organizations have unified reporting ownership for physical and digital identity.
  • Just 48% have consolidated budget control across identity functions.
  • The finance sector showed the highest level of governance fragmentation, with 34% operating separate reporting structures despite strict regulatory requirements.

Enterprises Manage Multiple Identity Systems

The study highlights increasing complexity in identity management environments.

  • 59% of enterprises manage three or more credential and authentication systems.
  • 58% say digital identity management has become more complex over the past two years.

The growing number of disconnected systems contributes to operational inefficiencies and increased security risks.

Public Sector Faces The Highest Incident Rates

Among all industries surveyed, the public sector reported the highest rate of identity security incidents.

Key findings include:

  • 43% experienced access revocation failures.
  • Manual credential revocation rates reached 20%, more than double the rate reported by the IT and technology sector.

These figures indicate that manual processes continue to create challenges for secure identity lifecycle management.

Passkey Adoption Continues To Grow

The report shows strong interest in passkeys and phishing-resistant authentication technologies.

  • 93% of organizations are at some stage of passkey adoption.
  • 65% report high or expert technical familiarity with passkeys.
  • Only 13% have deployed passkeys at scale across their organizations.

Researchers suggest this deployment gap contributes to the continued prevalence of identity-related security incidents.

Phishing Resistance Drives Passwordless Adoption

Organizations cite security as the primary motivation for transitioning away from traditional passwords.

The leading reasons for adopting passwordless authentication include:

  • Reducing phishing and credential-based breach risks (45%).
  • Lowering IT costs associated with password resets and help desk support (44%).

Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, said:

“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organizations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly. Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organization that are already protected.”

Sean Dyon, Vice President of the Authentication Business Unit at HID, said:

“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions”.

The full report was launched at Identiverse 2026, where attendees can visit FIDO Alliance at Booth 252 and HID at Booth 800 from June 15-17.

The FIDO Alliance enables identity technologies that place trust and simplicity at the center of interactions between people, services, and devices. The organization develops open authentication standards, certifies interoperable products, and promotes secure identity adoption worldwide.

HID provides trusted identity solutions that enable secure access to physical and digital environments. Its technologies help organizations manage identities, credentials, access rights, and connected assets across government, education, healthcare, finance, and enterprise sectors.

Internal Links URLs
https://security.world/category/access-control/

https://security.world/category/cyber-security

External Links URLs
https://www.fidoalliance.org

https://www.hidglobal.com


Frequently Asked Questions (FAQs)

1. What is the main finding of the FIDO Alliance and HID report?

The report found that while 94% of organizations believe they can revoke employee access within 24 hours, 35% have experienced delays or failures in doing so.

2. How many organizations have adopted passkeys?

According to the study, 93% of organizations are at some stage of passkey adoption.

3. How many enterprises have deployed passkeys at scale?

Only 13% of surveyed organizations reported deploying passkeys broadly across their environments.

4. Which industry reported the highest identity security incident rate?

The public sector reported the highest incident rate, with 43% experiencing access revocation failures.

5. Why are organizations moving toward passwordless authentication?

The primary drivers are reducing phishing and credential-based attacks and lowering password-related IT support costs.

Source: fidoalliance.org
0 Comments