Five Password Management Trends Enterprises Need to Watch
Password management has always been a pain point for both enterprises and individual users. Despite continuous technological advancements, password security issues continue to trouble many organizations. Based on industry observations, this article summarizes five major trends currently shaping password management, helping enterprises understand how to address the risk of malicious account breaches.

If you have ever sat in front of a computer screen, struggling to come up with a password that is both novel, unique, and secure, you are not alone. Once the system prompts for a password change, users are often forced to quickly invent a new keyword or phrase to regain access. Frustrated by this process, many people tend to choose passwords that are easy to remember, prioritizing convenience over security.
Password management in the enterprise environment is more difficult because it must simultaneously meet the best practices of corporate IT departments and the behavioral norms of employees on the office network. Password management and security behaviors at the personal level, however, are often insufficient and lag behind the threat landscape.
Despite continuous technological improvements, password management continues to plague both enterprises and individual users. But understanding the latest developments in this field can help more effectively counter malicious account intrusions. Here are the five major trends currently shaping password management:
1. Passwords are not going away
While the adoption of alternative authentication methods is increasing, passwords themselves will persist for a long time. At least for the foreseeable future, finding ways to "coexist" with passwords is a necessary compromise.
Before advanced solutions become widespread, supplementing existing passwords with new standards such as biometrics and multi-factor authentication is an effective means of protecting critical data. Passwords alone may not be strong enough, but this does not negate their value in the security framework.
Therefore, although passwords are slowly heading toward extinction, enterprises should not neglect developing relevant strategies and ensuring that employees continuously practice good password hygiene. The key point is: ensure that password creativity goes beyond "123456".
2. Change is coming
Passwords are the foundation of technology access, but some experts are pushing to completely eliminate passwords within five years. The passwordless movement stems from a technological inflection point: technology continues to advance, and users have become familiar with biometric authentication through systems like Apple's Touch ID.
Passwordless frameworks have transcended physical forms. Users can use facial, touch, or voice recognition, and systems can also incorporate geographic indicators. Behavioral analysis is harder to breach and less intrusive to users. For example, when the system detects anomalies compared to routine transaction behavior, it may trigger step-up authentication, requiring users to enter a one-time PIN or password sent to their device.
3. Multi-factor authentication remains prevalent
Introducing new security measures always brings some friction, as users may resist unfamiliar or perceived additional burdens. But two-factor authentication and multi-factor authentication are becoming increasingly common and are yielding returns for those who implement them.
The additional security provided by MFA is too important and too easy to implement for most organizations to ignore. If pilot projects encounter complexity issues, this should not prompt IT decision-makers to abandon implementation. For example, the U.S. Social Security Administration withdrew a two-factor authentication program in 2016 due to user complaints, but achieved greater success when it tried again in 2017.
Vendors have simplified the process of enabling MFA through management controls and enterprise-wide authentication policies. Technological advances now allow additional factors to be required only when behavior or location changes after initial authentication. For example, if a user logs in daily from their office in California but travels to New York, the system will prompt the user to enter an additional authentication factor to verify identity, rather than just the initial password.
4. Authentication growth in the ecosystem
Password management is a pain point across the industry, and many vendors are working to create solutions that do not restrict user functionality. The FIDO Alliance, in particular, aims to build an authentication ecosystem across hardware, mobile devices, and biometrics for accessing applications and websites.
According to Phil Dunkelberger, CEO of Nok Nok Labs, a founding member of the FIDO Alliance, the alliance wants to reduce enterprise reliance on passwords for any application, platform, or authenticator. Dunkelberger stated that FIDO is not only a gateway to stronger cybersecurity but also a solution for individual users seeking ease of use and convenience. By eliminating the hassle of passwords, users can connect and complete tasks more easily under trusted authentication.
FIDO2 is the next phase, including the WebAuthn standard advanced by the W3C. According to Dunkelberger, WebAuthn is a "collaborative effort based on Web API specifications" that will make FIDO a built-in feature of all web platforms.
5. Enterprises are learning from past identity and access management mistakes
Many databases and enterprises have been breached because people repeatedly make the same mistakes. Fortunately, there is no shortage of worst-case scenarios that provide business leaders with lessons on "what not to do."
Using expired passwords and reusing credentials across accounts, especially between work and personal accounts, may be the most obvious and common mistakes. However, although many individuals and enterprises experience cybersecurity incidents due to inadequate security practices, far fewer actually change behavior and take action.
Some of the most obvious and easily correctable mistakes include:
- Enterprises storing sensitive or credential-related data in unencrypted form in databases
- Organizations failing to install routine updates or patches
- Individuals logging into sensitive accounts on public networks
- Failing to regularly update passwords
Complacency is far from sufficient. Keeping up with competitors and ensuring that enterprises stay ahead (or at least not behind) of trends may ultimately come down to the execution of basic endpoint security practices.