Employee scanning key card

Enterprise Identity Management Flaws Expose Cyber Vulnerabilities

A joint study by the FIDO Alliance and HID reveals a sharp disconnect between perceived security readiness and actual access revocation failures.

Enterprise confidence in workforce access management does not align with operational reality, according to a joint study released by the FIDO Alliance and HID.

The report, titled "The State of Physical and Digital Identity in the Enterprise," highlights systemic vulnerabilities in how organizations revoke physical building access and digital account privileges when employees depart. While 94% of surveyed IT and cybersecurity decision-makers expressed confidence in their ability to strip all access permissions within 24 hours of an employee's departure, 35% acknowledged experiencing direct delays or system failures when attempting to do so over the past two years.

This operational lag correlates with broader security issues, as 70% of the surveyed organizations reported suffering at least one identity-related security incident.

According to the data, the gap between perception and security posture stems largely from fragmented corporate governance and infrastructure complexity. Half of all surveyed enterprises lack a unified reporting hierarchy for physical and digital identity management, and only 48% maintain consolidated budget control over these sectors.

Infrastructure management is similarly fractured, with 59% of enterprises juggling three or more distinct credential and authentication systems. Additionally, 58% of respondents noted that managing digital identities grew more complex over the last two years.

The public sector exhibited the highest rate of identity-related security incidents among the industries surveyed, with 43% of government organizations reporting access revocation failures. The sector also relies on a 20% manual credential revocation rate, doubling the rate found in the commercial technology industry.

The research also tracked corporate adoption of phishing-resistant authentication methods. Although 93% of organizations have initiated passkey adoption strategies and 65% claim high technical familiarity with the technology, only 13% have deployed passkeys at scale across their entire workforce.

Mitigating the risk of phishing and credential-based data breaches remains the primary motivator for shifting to passwordless infrastructure, cited by 45% of respondents. Reducing IT helpdesk expenditures related to password resets followed closely at 44%.

The complete findings are available in the full identity report.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”