Fidoalliance Study Reveals Disconnect in Identity Security Confidence Among Enterprises
Article Content
- •94% of organizations claim they can revoke access within 24 hours, but 35% faced failures.
- •70% of surveyed enterprises experienced at least one identity-related security incident.
- •Only 13% of organizations have deployed passkeys at scale, despite 93% on the adoption journey.
A report by FIDO Alliance and HID highlights a significant gap between enterprise confidence in identity security and operational reality. Surveying 500 IT and cybersecurity decision-makers across the US, Canada, UK, France, and Germany, it found that while 94% believe they can revoke access within 24 hours, 35% experienced failures in the past two years. Additionally, 70% reported at least one identity-related security incident. Governance is fragmented, with only 50% having unified reporting for identity management. The report indicates that complexity is increasing, with 59% managing three or more credential systems. Public sector organizations face the highest incident rates, and passkey adoption is crucial, with only 13% deployed at scale. The findings emphasize that identity security is now an enterprise governance challenge, necessitating a unified approach to manage both physical and digital identities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…