← Back to Feed

NCSC: Leave passwords in the past - passkeys are the future

April 23, 2026 · NCSC UK · Severity: MEDIUM

NCSC: Leave passwords in the past - passkeys are the future. Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers. Defenders should review their security posture and apply relevant mitigations as needed.

Key Takeaways

  • Credential theft and authentication bypass remain top attack vectors; MFA and passkeys improve security posture.
  • Medium severity threats still pose significant risk; organizations should prioritize detection and response controls.
  • Passwordless authentication and hardware security keys significantly reduce the risk of credential theft and account takeover.
☕ Buy a Coffee