Employee scanning key card

Enterprise Identity Management Flaws Expose Cyber Vulnerabilities

A joint study by the FIDO Alliance and HID reveals a sharp disconnect between perceived security readiness and actual access revocation failures.

Enterprise confidence in workforce access management does not align with operational reality, according to a joint study released by the FIDO Alliance and HID.

The report, titled "The State of Physical and Digital Identity in the Enterprise," highlights systemic vulnerabilities in how organizations revoke physical building access and digital account privileges when employees depart. While 94% of surveyed IT and cybersecurity decision-makers expressed confidence in their ability to strip all access permissions within 24 hours of an employee's departure, 35% acknowledged experiencing direct delays or system failures when attempting to do so over the past two years.

This operational lag correlates with broader security issues, as 70% of the surveyed organizations reported suffering at least one identity-related security incident.

According to the data, the gap between perception and security posture stems largely from fragmented corporate governance and infrastructure complexity. Half of all surveyed enterprises lack a unified reporting hierarchy for physical and digital identity management, and only 48% maintain consolidated budget control over these sectors.

Infrastructure management is similarly fractured, with 59% of enterprises juggling three or more distinct credential and authentication systems. Additionally, 58% of respondents noted that managing digital identities grew more complex over the last two years.

The public sector exhibited the highest rate of identity-related security incidents among the industries surveyed, with 43% of government organizations reporting access revocation failures. The sector also relies on a 20% manual credential revocation rate, doubling the rate found in the commercial technology industry.

The research also tracked corporate adoption of phishing-resistant authentication methods. Although 93% of organizations have initiated passkey adoption strategies and 65% claim high technical familiarity with the technology, only 13% have deployed passkeys at scale across their entire workforce.

Mitigating the risk of phishing and credential-based data breaches remains the primary motivator for shifting to passwordless infrastructure, cited by 45% of respondents. Reducing IT helpdesk expenditures related to password resets followed closely at 44%.

The complete findings are available in the full identity report.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.