惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password
Password habits are worsening, but leaders see a path to ...
info@1password.com (Elaine Atwell) · 2025-11-13 · via Blog on 1Password Blog

Poorly managed credentials are among the most stubborn problems for security and IT teams, and authentication is one of the areas where the Access-Trust Gap is widest. But even as credential-based attacks remain a major threat to security, there are positive signs that companies are moving toward a passwordless future.

An infographic that says "89% of security and IT professionals say their company is encouraging or planning to encourage employees to shift their logins to passkeys."

This blog is part three in our series analyzing the 1Password Annual Report 2025: The Access-Trust Gap

  • To read part one, which addresses AI governance, click here.

  • To read part two, on SaaS management, click here.

  • If you haven’t had a chance to read the full report yet, download it here

In this blog, we’ll address the third section of the report, on credentials. We’ll walk through some of the report’s most eye-opening findings and how IT and security teams can translate them into actionable priorities. 

We’ll also explore how 1Password helps close these gaps via 1Password Extended Access Management, a suite of solutions that includes our Enterprise Password Manager, 1Password SaaS Manager (formerly Trelica by 1Password), and 1Password Device Trust. 

Credential risks remain high, but companies are embracing passwordless authentication

For years, weak and compromised passwords have been the most common path for bad actors to breach organizations. Yet leaders and employers alike are embracing and adopting more secure authentication methods, even as the complete elimination of passwords remains an elusive goal.

Credential and authentication statistics from the report

  • 66% of employees report having poor password hygiene (e.g., using default passwords, reusing the same password for multiple accounts).

  • 44% of CISOs report that employees using weak or compromised passwords is one of their top security challenges

  • 89% of security and IT professionals say their company is encouraging employees to shift logins to passkeys

In F1, data is everything, so we can't compromise on security, but we also can't afford tools that slow us down. Credential and secrets management was an area where we saw an opportunity to improve on both security and speed, by reducing the amount our team has to directly handle credentials.” - Mark Hazelton, CSO of Oracle Red Bull Racing

Imperative: Passwordless

As the report explains: 

'Passwordless’ authentication isn’t a binary, and passwords are unlikely to be fully deprecated anytime in the foreseeable future. With that in mind, the goal of passwordless should be to remove users as much as possible from the authentication flow, so their exposure to raw credentials is minimized.”

With that in mind, IT’s priorities include:

  1. Define your roadmap and process to replace weak passwords with unique passwords, add MFA, and transition to passwordless authentication, including passkeys.

  2. Equip employees with clear guidance and ongoing support with transitioning to strong passwords, MFA, and passwordless solutions.

  3. In the cases where passwords remain necessary, require the use of an enterprise password manager to facilitate secure storage and sharing of credentials.

How 1Password helps close the Access-Trust Gap for authentication

All three Extended Access Management solutions help companies accelerate their path to passwordless authentication, but we’ll focus on the capabilities of the Enterprise Password Manager (EPM). 

Define your roadmap and process to replace weak passwords with unique passwords, add MFA, and transition to passwordless authentication, including passkeys

EPM provides admins with a dashboard that tracks the company’s password risk exposure, surfacing issues such as weak and reused passwords and accounts without 2FA. With this complete picture of authentication, admins can triage their most urgent risks.

Equip employees with clear guidance and ongoing support with transitioning to strong passwords, MFA, and passwordless solutions

Admins can use EPM to notify users when stronger authentication options are available and guide or require them to adopt them. 

In the cases where passwords remain necessary, require the use of an enterprise password manager to facilitate secure storage and sharing of credentials

Managing passwords is the foundation of 1Password’s business. 1Password EPM encourages users to create strong, unique passwords, supports secure sharing – whether for developer secrets or social media logins – and gives admins centralized control, essential for secure onboarding and offboarding.

Meanwhile, 1Password Device Trust helps enforce policies by verifying that EPM is installed and working correctly.

Explore 1Password EPM with an interactive demo

Close your Access-Trust Gap with 1Password

The report’s data makes clear that businesses need to reconcile security with their employees’ productivity and convenience. Make it simpler to use strong credentials than it is to recycle old passwords, and make it even easier to use passwordless methods wherever possible. Only then can companies practice their Zero Trust principles and close the Access-Trust Gap.

To learn more about how 1Password can help you secure your business without slowing you down, reach out to us today.