Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
By Limburg Cyber Group
Passwords have a fundamental problem: you can type them in the wrong place. One convincing fake site, and an employee hands over their login details themselves. Two-factor authentication makes that a lot harder, but a code can also be entered on a fake site. Passkeys take a different approach: there is nothing left to type.
What is a passkey?
A passkey is a digital key pair. When you create a passkey for a service, two keys are generated that belong together:
- a public key, which the service stores;
- a private key, which stays on your device or in your password manager.
When you log in, the service sends a kind of puzzle that can only be solved with your private key. Your device solves it as soon as you confirm with your fingerprint, face or PIN. That fingerprint or PIN never leaves your device; it only unlocks the key. Passkeys are based on an open standard from the FIDO Alliance, an industry group that includes the large technology companies.
Why passkeys stop phishing
- Tied to the real address. A passkey belongs to one website. Your device will not use it on a fake site with a slightly different address, however genuine it looks.
- Nothing to give away. There is no password or code that an employee can type in or read out to a caller.
- Nothing useful to steal from the service. The service only stores the public key. If that leaks, an attacker cannot use it to log in.
Where does it already work?
The major platforms from Apple, Google and Microsoft support passkeys, as do the mainstream browsers. More and more services, including business ones, offer it as a way to log in. Check your account’s security settings to see whether there is a passkey option.
What to watch for as a business
Lost devices. There are two kinds of passkey. Some are synced to your other devices through your Apple or Google account or your password manager; you do not lose those along with your phone. Others are fixed to a single device, such as a hardware key. For those, always register a second one, or keep another secure way to log in.
Recovery is the weak spot. If an account can also be recovered by text message or an emailed link, that is where an attacker will aim. Check which recovery options exist and secure them just as well.
Shared accounts. A passkey is personal. Where possible, give everyone their own account instead of sharing one. If that is not possible, check whether your business password manager can store passkeys in a shared vault.
The password often remains. With many services, the passkey sits alongside the password rather than replacing it. So keep that password strong and unique, and leave two-factor authentication switched on.
Combine them with your password manager. Many password managers can store passkeys. That is useful if your team works on devices from different brands, and you manage everything in one place. See also our article on a password manager for your business.
When someone leaves. Passkeys belong on your checklist for when an employee leaves: remove them from business accounts.
A sensible start in five steps
- Start with yourself. Create a passkey for an important account, such as your business email, and get a feel for how it works.
- Register at least two, for example on your phone and your laptop, or with a hardware key as a spare.
- Test it. Log out and back in, including on a different device. Many services let you log in on a computer by scanning a QR code with your phone.
- Check the recovery options for that account.
- Extend it to your team, starting with admin accounts and services holding financial or client data. Agree who looks after it.
Getting started
Want to know which of your services already support passkeys, and how to introduce them without locking anyone out? See our cybersecurity service or book a conversation.
Read more
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.
When an employee leaves: what to arrange digitally
When someone leaves, their accounts, passwords and sharing links often keep working longer than you think. A practical checklist to close them off properly.