A convincing fake sign-in page does not need an employee's one-time code for long. It can relay the password and fresh SMS code to the genuine service while both are still valid. Familiarity makes this method easy to underestimate: text-message authentication is inexpensive, widely supported and clearly better than a password alone, yet it was not designed to verify the website receiving the code.

That is the gap a passkey is designed to close.

That does not make SMS or authenticator-app codes useless. Multi-factor authentication is normally a meaningful improvement over a password alone. But current official guidance draws an important distinction between conventional MFA and authentication designed to resist phishing. For owners responsible for email, accounting, payroll, cloud administration or a domain name, that distinction deserves a place in the technology budget.

What phishing-resistant authentication changes

The US National Institute of Standards and Technology states in its current Digital Identity Guidelines that one-time-password authentication is not phishing-resistant. A manually entered code cannot control which website receives it. NIST describes phishing resistance as a protocol property that binds the authentication to the legitimate verifier rather than depending on a user noticing an imitation site.

CISA, the United States cybersecurity agency, identifies FIDO/WebAuthn as the only widely available phishing-resistant authentication. WebAuthn uses public-key cryptography. A service stores a public key, while the matching private key remains protected by the user's authenticator. Because the credential is created for the genuine website or application, it cannot simply be typed into another site and replayed.

A passkey is an implementation, not a magic shield

Passkeys use the FIDO2 standard and allow a person to sign in by unlocking an approved device with its PIN, fingerprint or face check. The biometric generally unlocks the credential locally; it is not the secret transmitted to the website. Passkeys may be synchronised through a credential manager so that a user can reach them on several trusted devices, or they may be device-bound, including credentials held on physical security keys.

The UK National Cyber Security Centre recommends passkeys over passwords where they are available and advises continuing to use strong, unique passwords and two-step verification where they are not. For a business, however, convenience is only one consideration. The company must decide who controls the credential manager, whether staff use company-owned or personal devices, how access is recovered, and what happens when a worker or contractor leaves.

Passkeys also do not prevent every type of account compromise. Malware on an authorised device, stolen browser sessions, weak help-desk recovery, an unlocked endpoint, excessive administrator rights and malicious insiders remain separate risks. A passkey rollout should therefore be treated as an access-control project, not as a declaration that an account is now invulnerable.

Protect the accounts that can unlock everything else

A small company does not need to migrate every low-risk service on the first day. Start with accounts whose compromise would let an attacker reset other credentials, divert money, impersonate the business or change infrastructure. These commonly include the main email administrator, cloud-platform administrators, accounting and payroll systems, the domain registrar and DNS service, password manager, source-code repository, e-commerce administration and payment accounts where the provider supports stronger authentication.

Banking and payment services have their own controls and regulatory requirements, so a business cannot assume that a passkey or external security key will be available. The useful question is not whether one technology can be forced onto every account. It is whether each critical system is using the strongest supported method, with the weakest fallback and recovery routes brought under control.

Choose between synced passkeys and security keys deliberately

Synced passkeys can reduce help-desk burden and make everyday sign-in easier across phones and computers. They suit many workforce accounts when the organisation has an approved device and credential-management policy. Yet the SME should establish whether the passkey is stored in an employee's personal account or a company-managed environment, what happens across operating systems, and whether administrators can enforce or audit its use.

Physical FIDO2 security keys can be appropriate for owners, finance staff and privileged administrators. They provide a clear device-bound factor and can work across supported services, but they must be purchased, inventoried and replaced safely. A sensible operational design gives a critical user two enrolled authenticators stored separately, rather than creating a single key whose loss locks the company out.

A controlled eight-step rollout

First, list the business's critical services, account owners and current sign-in methods. Second, remove shared administrator accounts where possible and issue named accounts so actions can be traced. Third, enable and enforce phishing-resistant methods for a small pilot group that includes an owner and a technical administrator.

Fourth, enrol a second approved authenticator for each critical user and document where the backup is held. Fifth, review recovery methods: old phone numbers, personal email addresses and easily answered help-desk questions can undermine the stronger login. Sixth, create a tightly controlled emergency account, exclude it from normal daily work and monitor any use.

Seventh, test the real lifecycle. Simulate a lost phone, a damaged key, a new laptop and the departure of an employee. Confirm that authorised staff can restore access without bypassing identity checks. Eighth, retain sign-in logs where the service provides them, review unexpected recovery events and revoke active sessions when a device or account may be compromised.

Questions to ask a software or identity provider

Before buying a new identity service, ask whether it supports FIDO2/WebAuthn and passkeys for both users and administrators; whether an administrator can require the method for selected roles; and whether legacy passwords or weaker MFA remain available as an unmonitored fallback. Request details on account recovery, audit logs, device and session revocation, single sign-on, conditional access, administrator separation and data export.

International SMEs should also ask where identity data and logs are processed, what support hours apply, and how the service handles employees in different countries. Passkey support alone does not establish compliance with privacy, employment, financial-services or sector-specific rules. Those obligations vary by jurisdiction and may require professional advice.

If a service still depends on codes

Do not switch MFA off while waiting for passkey support. Continue using a unique password generated and stored by a reputable password manager, enable the strongest MFA the service offers, train staff never to approve an unexpected prompt, and protect the email account used for recovery. CISA treats app-based codes and number matching as weaker alternatives to phishing-resistant MFA, but they can still be useful improvements over password-only access.

The practical destination is not an overnight password purge. It is a measured reduction in accounts where a reusable secret or relayable code is the final barrier between an attacker and the business. By starting with administrators and financial systems, testing recovery and retaining clear ownership records, a small firm can gain much of the value of modern authentication without creating a new operational failure point.

Research sources

Comments

Join the discussion. Please keep comments respectful and relevant to the article.

No comments yet. Be the first to comment.