What Is A Passkey & Are They Replacing Passwords?

May 29, 2026 Special Alerts

Online security has never been more prevalent due to the variety of cyber threats the public and businesses need to look out for. Except, spotting most threats isn’t that seemingly obvious because attackers are finding smarter, more subtle ways to implement malware or steal personal information. Passwords have been one of the weakest points in cyber security for a while, and it’s almost become a running joke about how most people use “password1234” or their birthday as their password for multiple logins. That’s why the NCSC, the UK’s National Cyber Security Centre, is encouraging consumers and businesses to adopt passkeys…

passkeys

Online security has never been more prevalent due to the variety of cyber threats the public and businesses need to look out for. Except, spotting most threats isn’t that seemingly obvious because attackers are finding smarter, more subtle ways to implement malware or steal personal information.

Passwords have been one of the weakest points in cyber security for a while, and it’s almost become a running joke about how most people use “password1234” or their birthday as their password for multiple logins. That’s why the NCSC, the UK’s National Cyber Security Centre, is encouraging consumers and businesses to adopt passkeys as a safer alternative.

Major platforms like Apple, Google and Microsoft are already supporting the use of passkeys, and in the not too distant future they may completely replace passwords. But what is a passkey and are they safer than passwords?

What Is A Passkey?

A passkey is a more secure alternative to a password. It’s a login method that uses cryptographic authentication instead of users having to remember a combination of letters, numbers and symbols. Passkeys use a device’s existing credential software, such as Apple Passwords, Samsung Pass or Google Password Manager, to store the passkeys. Your device securely logs you in using a cryptographic key pair and the device’s built-in security features, with facial recognition, fingerprint scans or a pin being the most used options.

This key pair links a public key and a private key, with the public key being shared with the website or app a user signs into, and the private key is kept strictly on the actual device, such as a smartphone, tablet or laptop.

Why Is The NCSC Encouraging People To Use Passkeys?

The NCSC is heavily encouraging people to switch to passkeys over passwords because they are far more secure. Passkeys have been designed to reduce the risk of stolen credentials and, unlike passwords, are not vulnerable to phishing attacks.

The NCSC believes passkey technology is now reliable enough for widespread consumer use. However, not all platforms have adopted passkeys yet, but the UK government has rolled out passkey technology across digital services, replacing SMS-based verification.

passkeys replacing passwords

Passkey vs Password – What’s The Difference?

Passwords

  • Authentication basis – a memorised combination of characters (letters, numbers and symbols).
  • Security – encrypted password storage and as complex as the user makes them.
  • Vulnerability to phishing – highly vulnerable, as users can be tricked into entering passwords on fake websites or apps.
  • Cross-device usage – can be used on almost any device or browser with manual entry or password managers.
  • User verification – type out of characters and can include additional verification like fingerprint, face scan or device PIN when combined with MFA.
  • Risk of reuse – commonly reused across multiple accounts, increasing the impact of data breaches.
  • Recovery process – typically relies on password reset links, security questions or email verification.

Passkeys

  • Authentication basis – cryptographic credentials stored securely on a trusted device.
  • Security – uses public-key cryptography, meaning no shared secret is stored on the server.
  • Vulnerability to phishing – highly resistant to phishing because passkeys only work with the legitimate website or app.
  • Cross-device usage – can sync securely across devices through ecosystem providers like Apple, Google or Microsoft.
  • User verification – authenticated using fingerprint, face scan or device PIN before the passkey is used.
  • Ease of use – faster and simpler sign-in experience with little or no typing required.
  • Risk of reuse – unique to each account and cannot be reused across services.
  • Recovery process – recovery depends on device eco-system account recovery and synced credential backups.

Is a Passkey Safer Than a Password?

A passkey is far safer than a password thanks to authentication requiring device ownership and the use of secure cryptographic keys. Passkeys, unlike passwords, can’t be intercepted, stolen or reused, meaning they are resistant to phishing.

Passkeys also offer better protection than two-factor authentication (2FA). The cryptographic keys are stored on your device instead of a memorised secret. The private part of the passkey never leaves the device, and the website only receives a matching public key. Authentication is protected by a fingerprint, face scan or device PIN, adding an additional layer of security.

While more secure than passwords, it’s still important to note that no system is completely risk-free and device security still matters.

How To Create A Passkey

This is a general guide on how to create a passkey on your device.

  1. Open your account security settings – go to the website or app you want to secure, sign in, and open the account or security settings section.
  2. Select “Set up passkey” – look for Passkeys and choose to create a new one.
  3. Verify your identity on your device – your device will ask you to confirm using a fingerprint, face scan or device PIN/password.
  4. Save the passkey to your device – the passkey is securely stored on your phone, tablet, computer or synced account service.
  5. Use the passkey to sign in next time – when logging in again, simply approve the sign-in with your fingerprint, face scan or PIN/password.

creating a passkey

What Are the Benefits of Using Passkeys?

Using passkeys over passwords provides users with several benefits concerning security and convenience.

  1. Protection against phishing – passkeys only work on legitimate websites and apps, helping prevent fake login scams.
  2. Faster login – passkeys allow users to sign in almost instantly using a fingerprint, face scan or device pin.
  3. Reduced password fatigue – users no longer need to remember or manage multiple complex passwords for different accounts.
  4. Less reliance on password managers – because passkeys are securely stored on devices, users may not need separate password management tools as often.
  5. Easier account security – passkeys simplify strong account protection without requiring users to create complicated passwords.

Are Passkeys the Future of Online Security?

While there has been an increase in consumer use, the adoption of the technology for businesses is still taking time. This is because many organisations still rely on old IT systems that simply don’t support passkeys.

The complete replacement of passwords won’t happen overnight, but as security and convenience becomes more important for both the public and businesses, it’s predicted in a few years passwords will be a thing of the past.

Preparing Your Business For Passkey Adoption

Staying ahead of the curve as a business when it comes to cyber security is a must. Your business needs to prepare for the evolving authentication standards of passkeys, and implement the right cyber security strategies that focus on phishing-resistant authentication. If you’re interested in partnering with an IT provider that can implement stronger login security and account protection, contact Optimising IT for a cyber security audit and consultation.

Vector Icon
Book a Meeting

Run, Protect
and
Grow, Your Business

Vector Icon
Company News

Proven Results
Through Innovation