Disconnect between confidence in identity security and operational reality

June 2026 Access Control & Identity Management, News & Events

The FIDO Alliance and HID have released The State of Physical and Digital Identity in the Enterprise, a new research report examining how organisations manage physical and logical access across their workforces.

Surveying 500 IT and cybersecurity decision-makers across the US, Canada, UK, France, and Germany, the new study uncovered a significant disconnect between enterprise confidence in identity security and operational reality. While most organisations believe they can revoke all physical and digital access within 24 hours of an employee leaving, more than one-third report failing to do so, contributing to identity-related security incidents across the enterprise.

Key findings from the report include:

● 94% of organisations claim confidence that all physical and logical access can be revoked within 24 hours of an employee leaving.

● Yet 35% experienced delays or failures doing exactly that in the past two years — and 70% experienced at least one identity-related security incident overall.

Governance is fragmented

● Only 50% of enterprises have unified ownership of reporting for physical and digital identities, and just 48% have consolidated budget control.

● Finance is the most governance-fragmented sector, with 34% maintaining fully separate reporting structures despite stringent regulatory access-control obligations.

Complexity is growing, and enterprises manage three separate systems on average

● 59% of enterprises manage three or more distinct credential and authentication systems.

● 58% say managing digital identity has become more complex over the past two years.

The Public Sector carries the highest incident rate

● The sector has the highest identity security incident rate of any industry, with 43% experiencing access revocation failures.

● It has a 20% manual credential revocation rate, which is more than double that of the IT/Technology sector.

Passkey adoption must scale to protect businesses

● 93% of organisations are at some stage of passkey adoption, and 65% report high or expert technical familiarity.

● However, only 13% have deployed passkeys at scale, which helps explain why organisations experience such high levels of security incidents.

Phishing-resistant authentication is a top business priority

● The leading driver for moving to passwordless authentication is reducing phishing and credential-based breach risk (45%), followed by reducing IT costs from password resets and help desk load (44%).

“The story in this data is not about awareness, it is about execution. Ninety-three percent of organisations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective, because threat actors do not limit themselves to the parts of the organisation that are already protected.”

“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organisations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions,’’ said Sean Dyon, vice president of the Authentication Business Unit at HID.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Dallmeier extends software maintenance up to 10 years
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier is expanding its software maintenance offering and now provides an additional maintenance package for cameras and recorders, enabling customers to keep their video security systems up to date for up to 10 years.

Read more...
Video surveillance market faces faster growth, and 2026 price shock
Surveillance News & Events
Novaira Insights has released its 2026 edition of The World Market for Video Surveillance Hardware and Software, highlighting a stronger global growth profile in 2025, tentative improvements in China’s market outlook, and unprecedented price increases in 2026.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Increase in cyberattacks on the manufacturing sector
Security Services & Risk Management News & Events Industrial (Industry)
According to a new Kaspersky ICS CERT report, in the first quarter of 2026, the percentage of industrial control systems (ICS) on which malicious objects were blocked reached 19,6% globally.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.