Goodbye Passwords: Why Passkeys Are the Biggest Security Shift in a Decade

Passwords have been the weak point of business security for as long as businesses have had computers. They get reused, guessed, phished and leaked, and the industry has spent decades adding patches on top: complexity rules, forced resets, password managers, two-factor codes. Passkeys take a different approach. Instead of fixing the password, they remove it. Microsoft, Google and Apple have all built passkey support into their platforms, and millions of accounts have already made the switch. For UK businesses, this is the most significant change to everyday security in at least a decade, and it is worth understanding before your staff start seeing prompts for it.

What Is a Passkey and How Does It Work?
A passkey is a way of signing in that uses your device instead of a memorised secret. When you create one, your phone or laptop generates a matched pair of cryptographic keys. One half, the public key, goes to the website or service. The other half, the private key, stays on your device and never leaves it. When you sign in, the service sends a challenge, your device signs it with the private key, and you approve the whole thing with your fingerprint, your face or your device PIN.
From the user's side, it feels like unlocking a phone. There is nothing to remember, nothing to type, and nothing to write on a sticky note. The fingerprint or face scan never leaves the device either; it only unlocks the key stored locally.
The important part is what the service holds. With a password, the service stores something that can be stolen and reused. With a passkey, the service holds only the public key, which is useless on its own. If the company suffers a breach tomorrow, there is no credential to leak. That single fact removes the main reason data breaches turn into account takeovers.
Passkeys sync across your devices through the account you already use, iCloud Keychain on Apple devices, Google Password Manager on Android and Chrome, and Microsoft's equivalent on Windows. Lose your phone and your passkeys are still there when you sign in on the replacement.
Why Can Passkeys Not Be Phished?
This is where passkeys go beyond every previous fix, including the two-factor codes most businesses rely on today.
A password can be phished because it is a secret you can be tricked into telling. A convincing fake login page asks, you type, the attacker has it. Six-digit authenticator codes only partly help, because modern phishing kits get around them. In an adversary-in-the-middle attack, often shortened to AiTM, the fake page sits between you and the real service, passing everything through in real time. You type your password and your code, the kit forwards both to the genuine site, and the attacker walks away with your logged-in session. These kits are cheap, widely sold and behind a large share of business account compromises in the UK right now.
Passkeys defeat this at a structural level. The passkey is mathematically bound to the exact website it was created for. A passkey registered to your Microsoft 365 login simply will not respond to a lookalike domain, no matter how convincing the page appears. There is no secret to type, so there is nothing for the fake page to capture, and nothing for an AiTM kit to relay. The attack does not become harder. It becomes impossible in its current form.
That is why this shift matters more than another round of security training. Training asks people to spot increasingly perfect fakes, and AI-written phishing has made the fakes very good indeed. Passkeys stop asking people to be the last line of defence.
What Should UK SMEs Ask Their IT Provider About Passkeys?
Rolling passkeys out across a business takes more thought than switching them on for a personal Google account, and this is where the conversation with your IT provider starts. A few questions worth putting to them directly:
Which of our systems support passkeys today, starting with Microsoft 365 or Google Workspace, and what is the plan for the ones that do not yet?
How will we handle account recovery if someone loses every device holding their passkeys?
Can we enforce passkeys for high-risk accounts first, such as directors, finance staff and anyone with admin access?
The answers tell you a lot about the provider. Passkey support is now built into the platforms most UK SMEs already pay for, so implementation is largely a matter of policy, rollout planning and user support rather than new spending. A provider who treats phishing-resistant sign-in as a chargeable extra rather than part of the core service is worth questioning, for the same reasons we covered in why managed IT should include cybersecurity by default, not as an add-on.
Expect a transition period rather than a clean cutover. Some older systems and industry-specific applications will keep passwords for a while yet, so the realistic goal for most businesses is passkeys on the accounts that matter most, with strong multi-factor authentication holding the line everywhere else.
Do Passkeys Have Any Downsides?
A few, and they are worth naming honestly. Passkeys tie your sign-ins to a device ecosystem, so account recovery planning matters more than it used to. Businesses with shared logins, which are a bad idea anyway, will need to untangle them, because passkeys belong to a person and a device, not a team. And staff will have questions during rollout, which is a communications job as much as a technical one.
None of these outweigh the gain. The gap between a business running phishing-resistant sign-in and one relying on passwords plus text-message codes is now the difference between being a hard target and an easy one.
What Should You Do Next?
Start with an audit of where your logins actually live and who can reach them. That exercise usually surfaces surprises, and if you have never mapped it, where exactly your data is and whether it is actually secure explains why the question matters more than most owners assume. From there, a phased passkey rollout is a well-trodden path: high-risk accounts first, then the wider business, with recovery procedures tested before anyone needs them.
This is exactly the kind of work a modern managed cybersecurity service should be bringing to you, not the other way round. If your current provider has never mentioned passkeys, that silence is informative. If you would like a straightforward conversation about what phishing-resistant sign-in would look like for your business, get in touch and we will walk you through it.




Comments