Passwords are now your biggest identity risk
Passwords remain one of the biggest identity risks because they rely on reusable shared secrets that attackers can steal, phish, or reuse. Password policies, complexity rules, and multi-factor authentication (MFA) reduce some risks, but they don't change the underlying authentication model.
For years, organisations have tried to strengthen password security by adding more controls. Complexity rules became longer, rotation policies became stricter, and multi-factor authentication became standard. Each change improved one aspect of password security, but none addressed the underlying weakness: passwords depend on a shared secret that both the user and the service must know. That weakness has little to do with how strong or weak any individual password is. It's built into the authentication model itself.
Identity has become the primary security perimeter
Identity now determines access to applications, data, and cloud services, making authentication the primary target for modern attackers.
Modern enterprise security no longer revolves around protecting a network boundary. Employees authenticate directly to cloud services, SaaS platforms, and identity providers from managed and unmanaged devices, often without ever touching the corporate network. As a result, authentication has become the control that determines whether someone is trusted, regardless of where they connect from.
Once attackers obtain legitimate credentials, they often bypass traditional perimeter controls altogether because authentication systems recognise the session as legitimate.
That shift has changed what attackers value. Compromising a firewall or exploiting a vulnerable server is often only the beginning of an attack. The objective is almost always to obtain an identity that allows legitimate access to additional systems, applications and data.
Credential theft remains central to modern attack chains
Credential theft is no longer always the first step in an attack, but it remains one of the most common ways attackers expand access and reach sensitive systems.
The 2026 Verizon Data Breach Investigations Report found that exploited vulnerabilities overtook credential abuse as the single most common initial access vector, the first time that's happened in the report's 19-year history. Taken on its own, that reads as good news for password security, though it only accounts for how attackers first get in.
Passwords remain central to modern attack chains once that first step is taken. While attackers increasingly gain initial access through vulnerabilities or trusted third parties, credential theft is still one of the primary techniques used to expand access, escalate privileges, and reach sensitive systems, appearing in 39% of breaches according to the same report, when the full attack chain is considered rather than just the first step. Credential-based risk hasn't declined so much as moved, from the primary entry point to the primary method attackers use to move laterally once they're already inside.
Strong passwords are still vulnerable to phishing
Strong passwords reduce guessing attacks, but they don't prevent credentials or authenticated sessions from being captured during phishing attacks.
Modern phishing campaigns no longer rely solely on persuading users to reveal passwords. Increasingly, they target the authentication process itself, capturing session tokens or approvals after a user has already logged in successfully, in ways that can bypass the specific MFA methods many organisations still rely on. The common factor across these techniques is that password-based authentication still depends on information, or a session artefact, that can be captured, intercepted or replayed.
Password rotation doesn't address the underlying risk
Password rotation shortens the lifespan of a credential, but it doesn't prevent passwords from being phished, intercepted, or reused after they're stolen.
Regular password rotation was one of the most widely adopted controls in enterprise security, and it's increasingly recognised as providing limited protection against how credentials are stolen today. Forcing a change every 90 days doesn't stop a credential from being phished or intercepted on day one. It doesn't stop a reused password from being pulled out of an unrelated third-party breach and tried against a corporate login. It adds operational friction for employees and IT teams while leaving the underlying authentication model - a reusable shared secret - unchanged.
The same applies to most of the controls layered on top of passwords over the years, which tend to manage specific symptoms without addressing the shared secret at the centre of the problem.
Passwords depend on a shared secret model
Passwords rely on information that both the user and the authentication system must know, making them inherently reusable if they're compromised.
A shared secret is information known by both the user and the authentication system, such as a password. Because the same secret must be presented at every login, an attacker who steals, intercepts, or reuses it can impersonate the user.
Passwords must be stored, transmitted, and verified by both parties in an authentication exchange. Unlike cryptographic authentication using public and private keys, where the private key never leaves the user's device, passwords rely on knowledge that exists outside the device and must travel across the network to be checked.
Anatomy of a shared secret

Figure 1: A password only works because two parties share it. Every copy of it works just as well.
Security awareness training addresses behaviour, not architecture
Security awareness training reduces the likelihood of users disclosing credentials, but it doesn't change the authentication model that attackers ultimately exploit.
Security awareness training remains an important, complementary control. It reduces the likelihood that a user discloses credentials in the first place by helping them recognise phishing attempts, suspicious login requests, and social engineering. What it can't do is change what happens after a credential is disclosed. If the underlying model still relies on a reusable shared secret, that secret can be captured, sold, or replayed by whoever obtains it, no matter how well-trained the person who disclosed it was.
Awareness training addresses human behaviour. It doesn't address the authentication architecture itself, and it was never designed to.
One credential. Five places it can be taken
-png.png?width=1920&height=592&name=Blog%201%20Images-selection%20(1)-png.png)
Figure 2: The weakness is not the string a person picked. It is that the string has to exist in five places at once, and any one of them is enough.
The question worth asking before evaluating MFA
The more important question isn't how strong your passwords are, but whether your authentication model still depends on reusable shared secrets.
Password policies, complexity rules and rotation schedules all reduce specific risks. They don't change the fact that passwords remain reusable shared secrets. In our work with Australian organisations, we've found the conversation is increasingly shifting away from password policy and towards broader identity architecture.
Before deciding whether passwordless authentication is necessary, it's worth asking another question: has multi-factor authentication solved the weaknesses of passwords, or has it simply reduced some of the risk?
Rethinking authentication starts here
That question about MFA is exactly what we tackle next: whether it has actually closed the gap passwords left open, or simply added another hurdle attackers have already learned to overcome.
Read next: Why MFA alone won't stop modern identity attacks
Frequently asked questions
A shared secret is information known by both the user and the authentication system, such as a password. Because both parties must possess the same credential, it can potentially be stolen, phished, or reused by an attacker. Passwordless authentication replaces this model with cryptographic proof instead of a reusable secret.
An adversary-in-the-middle attack is a phishing technique that inserts a relay between the user and the real login page, capturing what's exchanged during a live login rather than guessing a password.
Yes, in many common implementations. Not every form of MFA offers the same protection against phishing, and a factor that relies on a code, push notification, or one-time password can still be intercepted or bypassed by an attacker.
Credential stuffing is an attack technique where previously breached username and password combinations are automatically tried against other services, relying on the fact that many people reuse the same password across multiple accounts. It doesn't require phishing for a new credential, only reusing one already exposed elsewhere.
Password managers reduce password reuse and encourage stronger, unique passwords for each account, which lowers the risk of credential stuffing. They don't remove the underlying shared secret model. The password itself is still a piece of information that can be phished, intercepted, or extracted from the manager if it's compromised.
A longer passphrase is typically harder to guess or brute-force than a short password, so it improves resistance to guessing attacks. It's still a shared secret that can be typed into a phishing page, intercepted in transit, or reused across accounts, so it doesn't address the structural weaknesses described above.
Ready to move beyond passwords?
Passwords will remain part of many environments for years to come, but they no longer need to be the foundation of your identity strategy.
Our whitepaper, Reimagining Access: The Business Value of Passwordless Authentication at Scale, covers the business case, architectural considerations, implementation approaches, and the practical steps organisations should consider when planning a transition.
Prefer to talk it through? Contact The Missing Link to discuss your identity security roadmap.
Latest insights
Author
Ruchit Deshpande is the Security Solutions Director at The Missing Link, where he leads a team of talented Security Architects to help organisations build stronger, smarter cyber defences. With a lifelong passion for cyber security and over a decade of industry experience, Ruchit specialises in solving complex security challenges with practical, human-centred solutions. When he's not tackling emerging threats, you’ll likely find him playing or watching cricket or deep in thought over the latest cyber trends.