From facial and fingerprint recognition to behavioral identification: the future forms of passwords
Are passwords about to become obsolete? Biometrics and behavioral analysis are driving passwordless authentication toward reality, but enterprise adoption still faces challenges in ecosystem integration and user habits.

When users are off guard, the system always pops up that familiar prompt: "Your password has expired and must be changed." To meet the requirements for updating login credentials, users are often forced to hastily create new passwords—sometimes only changing one or two characters from the original password.
Modern password guidelines can be traced back to a 2003 recommendation from the U.S. National Institute of Standards and Technology (NIST): passwords should mix uppercase and lowercase letters, numbers, and special characters, and be changed regularly. This recommendation is the root of much user frustration—employees often complain about policies requiring them to change passwords every 90 days. To ease the burden of creating unique identities for multiple accounts, users have turned to password management tools.
However, for every tool adopter, there are several users who still rely on handwritten passwords or reuse the same credentials across multiple accounts. Even the person who set the password rules back then,partly regrets the original advice。
Although NIST has sinceintroduced a new framework—recommending passphrases and requiring changes only when there are signs of malicious activity—the security industry is working to eliminate passwords altogether. A passwordless future would place the responsibility of authentication on biometrics and behavioral insights rather than words, numbers, characters, or phrases.
Self-service shifts to personal identifiers
Traditional password management models rely on user self-service. If an account is locked, knowledge-based questions can verify identity and reset credentials. But users have numerous accounts in personal and work environments, forming a complex set of credentials that is difficult to navigate and remember.
Adding to the complexity, a simple search on the "Have I been pwned?" website can reveal whether personal credentials have been compromised. If compromised, users must reset passwords and create new unique ones.
"Our passwords are already out there, on the black market, on the dark web," says Ayan Roy, Principal at EY Advisory and head of Identity and Access Management Services. "No matter how often we reset passwords or how complex we make them, the reality is that most bad actors already have our passwords."
Passwordless models rely on different factors—such as touch and facial recognition—or continuous authentication to simplify how users interact with systems. Veridium CEO James Stickland predicts that passwords should be completely eliminated within the next five years. A mix of implicit and explicit authentication will more effectively protect people's identities.
Apple's introduction of Touch ID has already accustomed users to using biometrics to access core applications. Roy notes that biometrics has long faced adoption challenges, "but now with smartphones and smart devices, it's much easier to get users to use biometrics." Biometrics introduces an additional security layer that is harder to breach and allows vendors to conduct more behavioral analysis in the background.
For example, a user typically logs into the system at the same time each morning and accesses six applications. But if one morning he accesses ten systems, the identity and access management system can flag that behavior and challenge the user by sending a one-time PIN to the device. If the user logs in from a new geographic location, it may also trigger the same additional verification. Multiple authentication factors support more granular step-up authentication, which can dynamically adjust based on anomalies or transaction sensitivity.
Biometrics are already common in the consumer space, but enterprise adoption has been slower, with part of the challenge being integration with existing ecosystems. Stickland says enterprises already have identity access management systems and manage employee identities through user IDs and passwords. If vendors can introduce biometrics as a platform overlay without requiring additional hardware, adoption resistance will be lower.
"If users are essentially the same kind of people they've always been, their mental capacity hasn't expanded to remember more passwords," Stickland says. "You're increasing the complexity of storage and policies. How do you merge these two worlds? Simplify, but make it more secure."
The possibility of portable identities
One of the challenges of identity management is that almost all systems require creating an account. To address this, some organizations are introducing the concept of "verified identity." This is similar to social login in the consumer space—users can log into internet services with their Facebook, Google, Amazon, or Twitter accounts. Similarly, a verified identity could be used across organizations within a specific industry.
As part of cybersecurity efforts for life sciences organizations, a biopharmaceutical and healthcare industry alliance is working to create portable identities that can be used across the industry. According to Roy, the National Health Information Sharing and Analysis Center (NH-ISAC) is gathering requirements from members such as Aetna and Merck to build an identity solution that meets the needs of all parties and drives adoption.
The idea is to create a one-time verified identity that users can use with healthcare providers, pharmacies, or health insurance companies. Verified users can approve or deny any account activity, and the solution relies on built-in security controls. The passwordless approach would build an industry "ecosystem made up of different companies willing to adopt the technology—because if you don't build the ecosystem, I don't think it will succeed," Roy says. "Adoption will still be a challenge."