How passkeys are changing authentication in large organizations

Passkeys in large organizations Examples from the financial and technology sectors

Current state of passkey deployments in large organizations: benefits, challenges and results

Why are passkeys the future of authentication?

Passkeys is a modern authentication standard that is rapidly gaining popularity among large organizations. Using public key cryptography and complying with FIDO standards, passkeys offer security, resistance to phishing and simplify the login process for users. Unlike traditional passwords or one-time passcodes, passkeys eliminate the risk of credential theft and significantly reduce costs associated with user support.

More and more companies in various industries are introducing passkeys as an authentication standard. Below we have collected examples of organizations that have successfully implemented this solution.


Results of passkey deployments in large organizations

Aflac: rapid adoption in the insurance industry

It is one of the largest insurance companies in the US, with about 5,000 employees and millions of customers. In terms of cyber security, the insurance sector is often the target of hacking attacks, making the implementation of passkeys a key part of its strategy to protect customers and reduce the risk of fraud.

Results:

  • 32% adoption among users within a few days, far exceeding the 10% target.
  • 96% login success rate, which reduced the number of reports related to login problems.
  • No crashes or failed login attempts after deployment.

PayPal: Scaling security at global payments leader

It serves more than 400 million users worldwide and is one of the largest players in the fintech industry. Cyber security is a key aspect of PayPal’s business, especially in the context of fighting phishing and account takeover scams. The implementation of passkeys is a step toward even more effective transaction protection.

Results:

  • A 70% reduction in account takeovers, which significantly reduced fraud losses.
  • 10% higher login efficiency, which translated into greater user convenience and reduced support department interventions.

TikTok: Seamless login for millions of users

It’s a global social networking platform with more than 1.6 billion users. TikTok’s cyber-security is crucial, especially in terms of protecting personal data and authenticating users at scale. Reducing the use of SMS one-time codes reduces operational costs and the risk of SIM-swapping attacks.

Results:

  • 97% login success rate, which surpassed traditional MFA methods.
  • 14% of global adoption, a significant achievement with the introduction of the new authentication standard.
  • Reducing the use of SMS one-time codes by 2%, which significantly reduced costs for such a large scale of operations.

UBank: Meeting customer expectations in the banking sector.

Australian digital bank serving hundreds of thousands of customers. Digital banks are particularly vulnerable to identity takeover fraud, so deploying passkeys helps protect customers from phishing and login data attacks.

Results:

  • Effective integration with users’ devices for seamless and convenient login.
  • Protecting customers from impersonation scams, especially relevant in the context of the $2.7 billion in fraud losses in Australia in 2023.

Challenges of passkey implementation

The implementation of passkeys in large organizations brings with it a number of challenges that need to be addressed in order to make the process run smoothly and ensure user satisfaction.

1. cross-platform compatibility

One of the main challenges is the lack of full interoperability between ecosystems such as Apple, Google and Microsoft. Users may encounter difficulties when trying to access accounts on different devices or operating systems. For example, someone moving from an iPhone to an Android device may have trouble transferring their passkeys. The solution to this problem is to improve synchronization between ecosystems, which requires close cooperation between technology providers.

2 Compliance with laws and regulations

Data protection regulations, such as the RODO or CCPA, require organizations to ensure the security of user data, regardless of location. In some countries, there are restrictions on data storage, which can affect the authentication process. The solution is user ID mapping technology, which allows authentication methods to be adapted to regional regulatory requirements. For example, data storage regulations in different geographic regions can impede access for users traveling between countries. User ID mapping technology allows authentication processes to be tailored to regional requirements.

3. user education and adoption

Convincing users to use passkeys instead of traditional methods such as passwords or SMS one-time codes is a significant challenge. Users often prefer familiar solutions, even if they are less secure, and lack of knowledge about the advantages of passkeys can cause resistance to change. An example of an effective approach is to study user demographics and tailor educational messages to their needs, with positive results. Simplified registration processes and intuitive interfaces, as with some apps, help increase adoption.

4. solving edge cases

Managing scenarios such as handling multiple accounts or frequent switching between devices can be a challenge when implementing passkeys. To overcome this, it’s worth implementing dedicated login processes for more complex scenarios and testing edge cases regularly to avoid problems on the user side.

In conclusion, while there are some challenges to implementing passkeys in large organizations, the right approach and cooperation with technology providers can ensure a smooth and secure transition to this modern authentication method.


Why act now?

Passkeys are quickly becoming the standard for authentication in large organizations. Thanks to their advantages – such as eliminating phishing risks, reducing costs and improving the user experience – their implementation is virtually inevitable. Companies that delay too long risk falling behind, both in terms of security and customer expectations.


How can Secfense help?

Secfense makes it easy to deploy passkeys in large organizations without having to modify existing infrastructure. Our User Access Security Broker technology allows companies to move to passwordless authentication in a seamless and regulatory-compliant manner.

  • Security and compliance – Our solution supports the FIDO2 standard and ensures compliance with regulations such as DORA, NIS2 and RODO, eliminating the risks associated with phishing and user account takeover.
  • Easy integration – Secfense allows organizations to introduce passkeys without changes to application code and without interfering with existing authentication systems.
  • Reduced operational costs – By eliminating passwords, companies reduce the number of calls to IT support related to password resets and login problems.

Summary: Passkeys are the future of authentication

Examples from companies such as Aflac, PayPal, TikTok and UBank show that implementing passkeys is not only an improvement in security, but also a tangible operational and financial benefit. Companies that already invest in passwordless authentication gain a competitive advantage and increase user trust.

Want to learn how to implement passkeys in your organization?

Switch to Passkeys  Learn how to implement passkeys in your organization

Sources:

  • Secure Payments with Passkeys Is Now Available on PayPal for Google Android Devices | PayPal
  • TikTok Passkeys for Login: The more secure way to log into your TikTok account | Tiktok
  • Ubank introduces simple and secure app log in with passkeys | Ubank
  • Aflac’s shift to passkeys brings big business benefits | CSO

Antoni takes care of all the marketing content that comes from Secfense. Read More

Testimonials

We are faced with new challenges every day. We must always be one step ahead of the attackers and know what they are going to do before they do it. We are convinced that the User Access Security Broker will bring security to a new level, both for those working at the office and from home. For us, working with Secfense is an opportunity to exchange experience with developers who put great value on out-of-the-box thinking.

Krzysztof Słotwiński

Business Continuity and Computer Security Officer

BNP Paribas Bank Poland

As part of the pre-implementation analysis, we verified that users utilize a wide range of client platforms: desktop computers, laptops, tablets, smartphones, and traditional mobile phones. Each of these devices differs in technological advancement, features, and level of security. Because of this, and also due to the recommendation of the Polish Financial Supervision Authority (UKNF), we decided to introduce additional protection in the form of multi-factor authentication mechanisms based on FIDO. As a result, users of our applications can log in safely, avoiding common cyber threats such as phishing, account takeover, and theft of their own and their clients’ data.

Marcin Bobruk

CEO

Sandis

We are excited to partner with Secfense to enhance our user access security for our web apps. By integrating their User Access Security Broker, we ensure seamless and secure protection for our applications and systems, delivering superior security and convenience to our customers.

Charm Abeywardana

IT & Infrastructure

Visium Networks

Before investing in Secfense, we had the opportunity to talk to its existing clients. Their reactions were unanimous: wow, it’s so easy to use. We were particularly impressed by the fact that implementing their solution does not require the involvement of IT developers. It gives Secfense a huge advantage over the competition, and at the same time opens the door to potential customers who so far were afraid of changes related to the implementation of multi-factor authentication solutions.

Mateusz Bodio

Managing Director

RKKVC

Even when the network and infrastructure are secured enough, social engineering and passwords can be used to gain control of the system by attackers. Multifactor authentication is the current trend. Secfense addresses this and allows you to build zero trust security and upgrade your current systems to passwordless applications within minutes, solving this problem right away,” said Eduard Kučera, Partner at Presto Ventures and cybersecurity expert – former Director in hugely successful Czech multinational cyber security firm Avast.

Eduard Kučera

Partner

Presto Ventures

One of the biggest challenges the world is facing today is securing our identity online. That’s why we were so keen to have Secfense in our portfolio. They make it possible to introduce strong authentication in an automated way. Until now, organizations had to selectively protect applications because the deployment of new technology was very hard, or even impossible. With Secfense, the implementation of multi-factor authentication is no longer a problem, and all organizations can use the highest standards of authentication security.

Stanislav Ivanov

Founding Partner

Tera Ventures

Two-factor authentication is known to be one of the best ways to protect against phishing; however, its implementation has always been difficult. Secfense helped us solve that problem. With their security broker, we were able to introduce various 2FA methods on our web applications at once.

Dariusz Pitala

Head of IT

MPEC S.A.