The best password is no password
Published 2026-07-12 by Woodruff Training
Almost all password advice is damage limitation. Make it long, make it different on every site, and keep it in a password manager. That is sound, and we still recommend it, but it works around the flaw rather than fixing it. A password is a secret you hand over to prove who you are, so anyone who persuades you to hand it over somewhere else now has it too.
Passkeys deal with that by getting rid of the secret.
Why the password rules kept changing
The National Cyber Security Centre, the government body that advises UK organisations on security, has spent years undoing password habits that made things worse rather than better.
It advises against forcing staff to change their password every 90 days. People respond to that with Summer2025, then Summer2026, and the account ends up weaker. It suggests three random words instead of a jumble of symbols, because length does more work than complexity and people can actually remember it. It is comfortable with password managers, including the one built into your browser, on the grounds that almost anything beats using the same password everywhere.
Sensible advice, and worth following. But it is still a password, still typed into a box, and a convincing fake login page still collects it.
What a passkey actually is
When you set up a passkey, your device creates two matched keys. One stays on your phone or laptop and never leaves. The other goes to the website, where it is useless on its own. Signing in means your device proving it holds the private half, which it does once you unlock it with a fingerprint, your face, or the PIN you already use to open the phone.
A few things follow from that:
- Phishing stops working. Your device checks the web address before it responds, so a lookalike page gets nothing even if the person is completely taken in.
- A breach at the supplier costs you little. Attackers walk away with the half of the key that does nothing without your device.
- Your fingerprint never leaves your phone. The biometric only unlocks the key sitting on the device. This is the part that worries people most, and it is the part they need not worry about.
Where to start
- Turn on passkeys for your Microsoft 365 or Google Workspace account first. Email resets every other account you own, so it deserves the strongest protection you have.
- Add them anywhere else they are offered. Banks, accounting software and the bigger online services are steadily adding support.
- Keep multi-factor authentication switched on everywhere else. Most systems will not offer passkeys yet, and MFA remains the best free thing you can do for an account.
- Work out recovery before you need it. Know how someone gets back in after a lost phone, and make sure more than one person can reach the business accounts.
Passwords are not going away this year, and you will run both side by side for a while yet. Start with the accounts that would hurt most to lose, and let the rest follow.
If you want an honest read on the passwords in your business today, our password checker will tell you in a few seconds. Get in touch if you would like a hand moving a team across.