Confidence gap: Study finds identity security falling short in practice FIDO Alliance, HID report shows access revocation failures persist despite high enterprise confidence

By SSN Staff
Updated 5:22 PM CDT, Tue June 16, 2026
LAS VEGAS—A new study from the FIDO Alliance and HID reveals a widening gap between enterprise confidence in identity security and actual performance, with more than one-third of organizations reporting failures in revoking access for departing employees despite near-universal confidence in their processes.
The report, “The State of Physical and Digital Identity in the Enterprise,” was released June 15 at Identiverse 2026 and is based on a survey of 500 IT and cybersecurity decision makers across the U.S., Canada, U.K., France and Germany.
According to the findings, 94% of organizations say they can revoke all physical and digital access within 24 hours when an employee leaves. However, 35% reported experiencing delays or failures in doing so over the past two years. Overall, 70% of respondents said they had experienced at least one identity-related security incident during that period.
The study points to fragmented governance as a key contributor to the disconnect. Just half of respondents said they have unified reporting ownership for physical and digital identity, while 48% reported consolidated budget control. The finance sector showed the greatest fragmentation, with 34% operating separate reporting structures despite strict regulatory requirements.
Complexity also continues to rise. Nearly six in 10 organizations (59%) manage three or more separate credential and authentication systems, and 58% said managing digital identity has become more complex over the past two years.
Public sector organizations reported the highest rate of identity-related issues, with 43% experiencing access revocation failures. The sector also relies more heavily on manual processes, with a 20% manual credential revocation rate - more than double that of IT and technology organizations.
The report also highlights a gap between awareness and deployment of modern authentication methods. While 93% of organizations report being at some stage of passkey adoption and 65% describe themselves as highly familiar with the technology, only 13% have deployed passkeys at scale.
“The story in this data isn’t about awareness, it’s about execution,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “Ninety-three percent of organizations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly.”
Shikiar added that partial implementation limits the effectiveness of phishing-resistant authentication. “Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective, because threat actors don’t limit themselves to the parts of the organization that are already protected,” he said.
Reducing phishing and credential-based breaches was cited as the top driver for adopting passwordless authentication (45%), followed closely by reducing IT costs associated with password resets and help desk workloads (44%).
HID emphasized that the issue extends beyond authentication technology to enterprise-wide governance and visibility.
“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge,” said Sean Dyon, vice president of the Authentication Business Unit at HID. “This research shows that fragmented governance, disconnected systems and limited visibility create real business risk.”
The report concludes that organizations need a more unified approach to managing physical and digital identity, particularly as they scale adoption of passkeys and other phishing-resistant methods.
Download the full report here.
Photo courtesy of HID
Comments