Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - World Password Day Is Thursday: 60% Of Institutions Surveyed Say It’s Time To Move Beyond Passwords
News & Analysis

World Password Day Is Thursday: 60% Of Institutions Surveyed Say It’s Time To Move Beyond Passwords

ISBuzz TeamBy ISBuzz TeamMay 1, 20193 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Security Teams
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

World Password Day is this Thursday, May 2, but everyone knows the damage that weak passwords can cause.  Why not use this day to talk about how other forms of authentication — like MFA,  biometrics and behavioral analysis– can better protect consumers against fraud?  

OneSpan recently commissioned a study of top financial institutions regarding passwords and other authentication practices. It found that:   

– 96% of organizations still rely on legacy processes tied to usernames and passwords for authentication 

– 44% are challenged by the use of legitimate credentials (exposed in data breaches) in account takeover attempts 

-60% of respondents plan to invest in new multifactor authentication technologies in 2019, including those based on biometrics and AI/machine learning  

Experts Comments: 

Will LaSala, Director of Security Solutions, Security Evangelist at OneSpan: 

“Passwords are the easiest form of keeping something private, but also one of the biggest challenges facing organizations, including financial institutions, when it comes to authenticating a user. Organizations do not need to remain beholden to usernames and passwords for authentication anymore as this is the equivalent of leaving the vault door open for fraudsters. The good news is that as fast as the threat environment is moving, there are lots of great technologies coming to bear that can help with better authentication and completely remove passwords from our daily lives. 

For example, financial institutions today can look at situations and say, “This is an odd time for this person to do a transaction,” or “It’s an odd transaction.” The landscape for authentication has changed, and the number of data points have increased dramatically. These advancements in technology allow institutions to reduce false positives, identify fraud that they weren’t catching in real time and achieve those mutual goals. 

Every transaction requires the same level of risk-based analysis. And that’s the promise of the latest innovations in adaptive authentication – that it will provide the precise level of security to the transaction at the right time. At a time when security controls have matured, and when artificial intelligence and machine learning are fueling a new era of effective analytics, banking and security leaders no longer need to choose between customer convenience and security. They can get both.”   

Michael Magrath, Director of Global Standards & Regulations at OneSpan:

“The reality is World Password Day may become extinct in the next few years.  Advancements in frictionless authentication technologies coupled with the global adoption of privacy regulations will very likely make passwords a thing of the past. In fact, a recent OneSpan survey revealed that more than 60 percent of respondents plan to invest in new multifactor authentication technologies in 2019, including those that rely on biometrics and AI/machine learning in an effort to overcome security issues face by financial institutions and their customers. 

Unlike passwords, modern authentication technologies include “privacy by design” as the foundation.  Standards-based authenticators including the FIDO Alliance balance usability with security while protecting privacy.  FIDO’s specifications use public key cryptography enabling stronger authentication.  When using a FIDO certified authentication, the user’s device creates a key pair. The private key remains secure in their device and registers the public key with the online service.  Unlike passwords, no secrets are generated on the server side with user verification occurring locally at the authenticator whether that is a token smartphone or biometric.  Moreover, unlike big databases, biometric data, if used, such as fingerprints or facial recognition never leave the device.   Adoption of strong authentication is expected to become widely adopted at the consumer level, with WebAuthn, an official web standard, currently supported in Windows 10 and Android platforms, and Chrome, Edge, Firefox, with Safari expected to support it in the near future.” 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}