Passwords Are on Their Way Out — Here’s What’s Replacing Them

Passwords Are on Their Way Out — Here’s What’s Replacing Them

If you’ve been anywhere near the news this week, you might have spotted the head of GCHQ giving a fairly blunt message: stop using passwords and start using passkeys. It was part of a much bigger speech about cyber threats and national security, delivered at Bletchley Park on Tuesday, but that one line caught my attention — because it’s something that affects every single one of us, right now, at work and at home.

It’s not just GCHQ, either. The National Cyber Security Centre (the bit of GCHQ that gives practical cyber advice to the rest of us) formally changed its guidance back in April. For the first time ever, they’re telling people to use passkeys instead of passwords wherever they can. That’s a big deal. For decades, the official advice has been all about making passwords stronger — longer, more complex, different for every account. Now they’re saying: actually, passwords themselves are the problem.

So what’s changed?

The password problem

The trouble with passwords isn’t that we’re bad at choosing them (although, let’s be honest, plenty of us are). It’s that the whole concept has a built-in weakness: a password is a secret you share. You know it, and the website knows it. That means it can be stolen — from you through a phishing email, or from the company in a data breach. And once someone has it, they’re in.

The latest UK Cyber Security Breaches Survey, published just last month, found that phishing is still the most common form of attack, involved in around 85% of incidents affecting businesses. Eighty-five percent. Despite years of awareness training, despite all the warnings, phishing still works — because all it takes is one convincing email and one person typing their password into the wrong place.

Think of it like this. Imagine your front door could only be opened by saying a secret word. Anyone who overhears the word — or tricks you into saying it to the wrong person — can walk straight in. That’s what passwords are. They’ve served us well for a long time, but the people trying to get through the door have got a lot more creative.

So what is a passkey, then?

A passkey is a different kind of key altogether. Instead of a shared secret, it uses a pair of digital keys — one that stays locked inside your device (your phone, tablet, or laptop) and one that the website holds. When you log in, the website asks your device to prove it has the right key, and your device confirms it — but the actual key never leaves your device. Nobody can steal it by tricking you into handing it over, because you never hand it over.

To unlock the passkey, you just use whatever you already use to unlock your phone — your fingerprint, your face, or a PIN. That’s it. No password to remember, no password to type, no password to steal.

Going back to the front door analogy: it’s like replacing the secret word with a lock that only opens when it recognises you. You can’t be tricked into giving the key to someone else, because the key is you.

Where can you use them?

More places than you might think. Google, Microsoft, Apple, Amazon, PayPal, eBay and Visa all support passkeys now, and the list is growing fast. According to the NCSC, over half of UK Google users have already set one up. The UK government itself is planning to roll out passkey login across its own digital services.

You don’t have to switch everything overnight, and you can’t — not every service supports passkeys yet. The NCSC’s advice is straightforward: use a passkey where it’s offered, and keep using a strong, unique password with two-step verification everywhere else.

What does this mean for organisations?

If you’re responsible for information security in your organisation — or just trying to keep your team aware of the basics — this is worth paying attention to. Not because you need to rip out your existing login systems tomorrow, but because the direction of travel is clear, and it’s coming from the top.

At the very least, it’s a good prompt to have a conversation with your people about how they protect their work accounts and their personal ones. Most staff won’t have heard of passkeys yet, and those who have probably aren’t sure whether to trust them. A simple, clear explanation goes a long way — especially when you can say “this isn’t just us saying it, it’s GCHQ.”

It’s also worth thinking about your broader information security awareness programme. If your staff training still focuses heavily on password hygiene — choosing strong passwords, not reusing them, changing them regularly — that advice isn’t wrong, but it’s no longer the whole picture. The conversation needs to evolve, and passkeys are part of that evolution.

The bigger picture

The GCHQ Director’s speech wasn’t really about passkeys. It was about urgency. She described the current threat landscape as a “moment of consequence” and called for cyber security to be treated with ten times more urgency than it is today. Passkeys were just one practical example of something we can all do right now.

And that’s what I always come back to with information security. It’s easy to feel overwhelmed by the scale of the threat — nation-state actors, AI-powered attacks, supply chain compromises. But the reality is that most breaches still start with something simple: someone clicking a link and entering a password. If passkeys can take that particular door off its hinges, that’s worth doing.

My suggestion? Next time your phone offers to create a passkey when you’re logging in somewhere, say yes. See how it feels. Then think about how you might introduce the idea to the rest of your team.

Small steps. Big difference.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *