← Back to Feed
NCSC: Leave passwords in the past - passkeys are the future
April 23, 2026 · NCSC UK · Severity: MEDIUM
NCSC: Leave passwords in the past - passkeys are the future. Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers. Defenders should review their security posture and apply relevant mitigations as needed.
Key Takeaways
- Credential theft and authentication bypass remain top attack vectors; MFA and passkeys improve security posture.
- Medium severity threats still pose significant risk; organizations should prioritize detection and response controls.
- Passwordless authentication and hardware security keys significantly reduce the risk of credential theft and account takeover.