This article first appeared in Digital Edge, The Edge Malaysia Weekly on February 9, 2026 - February 15, 2026
Asia-Pacific is one of the most attacked regions globally, accounting for 34% of incidents in 2024, with valid-account abuse as the leading entry vector, according to the IBM X-Force 2025 Threat Intelligence Index. This makes strong identity protection a business imperative.
Across business process outsourcing (BPO) operations, manufacturing floors, healthcare environments and both small and medium enterprises (SMEs) and large companies, workers rely heavily on continuous access to applications and sensitive digital data, meaning the digital identity of every employee has effectively become the new perimeter.
For more than six decades, passwords have served as the primary mechanism for digital access, yet they have now become one of the most significant liabilities in cybersecurity. Credential reuse, social engineering and increasingly sophisticated phishing and malware campaigns have pushed password-based authentication beyond its limits.
As identity becomes the new security perimeter, relying on passwords is no longer viable for organisations that must protect high-value data and distributed workforces. Passkeys are therefore far from being just a technical improvement but a strategic shift towards a phishing-resistant, interoperable and user-centric model of digital trust.
Passkeys strengthen the enterprise perimeter by replacing passwords with phishing-resistant credentials. Phishing remains the main cause of scams and data breaches, with attackers increasingly targeting individuals rather than systems.
Once a password is phished, it can be reused to access corporate data, financial accounts or critical services with little resistance. Eliminating passwords removes this single point of failure and stops phishing-led compromises before they begin.
So, what again are passkeys? Passkeys are FIDO credentials — on your smartphone, security key or smart card — that enable you to log in securely without ever typing a password.
A common misconception is that passkeys are simply a modernised form of one-time passwords (OTPs). They are not. OTP-based two-factor authentication remains vulnerable to real-time phishing, man-in-the-middle (MITM) attacks and social engineering because users can still be tricked into sharing a six-digit code an attacker can immediately reuse. Passkeys, in contrast, are phishing-resistant by design.
Passkeys also reduce cost by eliminating the most expensive parts of authentication: password resets, account lockouts and help desk support, which typically consume the majority of identity and access management (IAM) operational spend.
They also lower breach risk by removing credentials that attackers can phish or reuse, reducing the downstream costs of incident response, fraud and service disruption. In short, fewer passwords mean fewer support tickets, fewer compromises and a leaner, more efficient security operation.
Passkeys are easier to adopt than OTP and other forms of authentication methods because they follow open FIDO2/Web Authentication (WebAuthn) standards that are already built into modern browsers, devices and operating systems. This removes the need to integrate separate OTP generators, SMS gateways or proprietary application programming interfaces (APIs).
But the unfortunate reality is that many parts of Asia-Pacific still rely heavily on SMS OTP. While several markets are pushing to adopt stronger authentication, these efforts often stall because these new systems are proprietary, costly to operate or slow to integrate.
Passkeys avoid these barriers and use open standards based on FIDO, which is already built into devices and browsers, making them cheaper, faster and more consistent to deploy across the region.
National initiatives across Asia-Pacific include:
● The Monetary Authority of Singapore (MAS), under its technology risk and cyber-resilience framework (as updated in 2024/25), expects financial institutions in the city state to adopt phishing-resistant and multi-factor authentication (MFA) and discourages vulnerable credentials, which aligns with using FIDO-based methods.
● In the Philippines, the AntiFinancial Account Scamming Act (AFASA), together with BSP Circular 1213 (June 2025), requires banks and financial institutions to phase out SMS- or email-based OTPs and adopt “strong, phishing-resistant authentication methods” such as passwordless logins, biometrics or FIDO-compliant passkeys by June 2026.
● In Australia, the cyber-resilience guidance for regulated institutions under the Australian Prudential Regulation Authority (APRA) and the broader national guidance from Australian Cyber Security Centre (ACSC) declare that phishing-resistant MFA — which includes FIDO/WebAuthn and security-key based authentication — is a preferred control, replacing weaker factors such as SMS or simple OTPs.
● Japan’s Financial Services Agency (FSA) already sets strong authentication and risk-appropriate security controls as baseline requirements in its cybersecurity guidelines for financial institutions. The agency is now moving further by proposing supervisory guideline amendments that would mandate phishing-resistant MFA, explicitly noting that passwords and SMS/email OTPs are no longer effective. This direction aligns directly with FIDO2 passkey-based approaches as practical, compliant methods for achieving phishing-resistant authentication.
● More broadly, the FIDO Alliance — the global standards body for phishing-resistant authentication — now lists many Asia-Pacific governments and enterprises among its participants, signalling growing public- and private-sector support for FIDO standards in the region.
According to a joint study by HID and the FIDO Alliance, 87% of businesses surveyed reported successful adoption of passkeys, a 14% year-on-year increase.
Organisations that deploy passkeys experience 81% fewer login issues, 73% faster access and 77% fewer help desk calls, according to the FIDO Alliance.
However, one size doesn’t fit all. Deployment challenges usually have less to do with security architecture and more to do with usability and change management.
Users push back when authentication becomes harder — and in many environments, such as healthcare, government facilities, trading floors or data centres, mobile phones cannot be used at all. This is why flexibility is essential.
Passwordless adoption in the enterprise is best approached step by step, starting with high-impact workforce use cases like securing access to corporate systems, remote work, critical infrastructure and operational technology.
Enterprises need choice, not mandates. And with regulators across Asia-Pacific promoting phishing-resistant authentication, passkeys provide a clear, practical path forward.
Some argue that passkeys bring back the inconvenience the industry worked hard to eliminate. In reality, the goal is not more steps, it is smarter steps that fit naturally into how people work.
A well-designed passwordless experience keeps authentication in the flow of work and gives users secure options that fit their needs, reducing lockouts and support overhead.
In practice, this can take many forms. Organisations can start with what they have by using existing ID badges or smartphones as FIDO credentials. This causes minimal friction as it is something employees are already used to.
For high-risk and tech-savvy groups, they can use converged FIDO credentials, where a single authenticator can support both physical and digital access, adding an additional layer of certainty without increasing friction.
In the enterprise, an employee badge that unlocks a building door and can also be used to log into a workstation demonstrates how authentication is becoming more integrated, secure and intuitive. These developments reflect where passwordless is broadly heading towards simpler user experiences grounded in stronger proof of identity.
Driving passwordless projects across Asia-Pacific and beyond requires a coordinated, standards-based approach that aligns technology, policy and user experience.
Success depends on delivering enterprise-ready passkey solutions that work across diverse environments, offering interoperable FIDO authenticators like smart cards and security keys, so users have choice without compromising security.
It can also include unifying access to physical spaces and digital applications, an approach that streamlines how users authenticate across environments without adding friction.
Achieving this will demand coordinated action across government, financial institutions and the private sector, supported by clear standards and practical implementation guidance. These pillars form the core of a resilient, user-centric passwordless ecosystem — and unlock the full advantages of phishing-resistant authentication at scale.
Edwardcher Monreal is principal solutions architect for identity and access management (IAM) consumer authentication solutions at HID, a global identity management solutions firm
Save by subscribing to us for your print and/or digital copy.
P/S: The Edge is also available on Apple's App Store and Android's Google Play.