Fido Alliance and HID Release Research Report on Security Confidence

The FIDO Alliance and HID today released the The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their workforces.
The new study surveyed 500 IT and cybersecurity decision makers across the US, Canada, UK, France and Germany. The companies said that the study uncovered a significant disconnect between enterprise confidence in identity security and operational reality. While most organizations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third reported experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise.
Other key findings include that 94% of organizations claim confidence that all physical and logical access can be revoked within 24 hours of an employee leaving, while 35% experienced delays or failures doing exactly that in the past two years, and 70% experienced at least one identity-related security incident overall.
50% of enterprises have unified reporting ownership for physical and digital identity, and 48% have consolidated budget control. The report also revealed that finance is the most governance-fragmented sector, with 34% operating fully separate reporting structures despite operating under stringent regulatory access-control obligations.
The FIDO Alliance and HID said that results of the survey also revealed that complexity is growing, and enterprises manage three separate systems on average, with 43% experiencing access revocation failures. 3% of organizations are at some stage of passkey adoption, and 65% report high or expert technical familiarity, while 13% have deployed passkeys at scale, suggesting that passkey adoption must scale to protect businesses.
The organizations reported that the study suggests that phishing-resistant authentication is a top business priority, with 45% of respondents indicating that the phishing risk is a leading driver for moving to passwordless authentication.
“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions,” said Sean Dyon, vice president of the authentication business unit at HID.
The full report will launch at Identiverse 2026.




