94 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-universal confidence in fast access revocation next to a real failure rate more than one in three.
FIDO Alliance and HID launched The State of Physical and Digital Identity in the Enterprise at Identiverse in Las Vegas on June 15, 2026, based on a survey of 500 IT and cybersecurity decision-makers (manager level and above) across the US, Canada, UK, France, and Germany, spanning finance, healthcare, public sector, manufacturing, and technology. The core finding: 94 percent of organizations believe they can revoke both physical and digital access within 24 hours of an employee leaving, yet 35 percent actually experienced a revocation failure in the past two years, and 70 percent had at least one identity-related security incident overall. The public sector had the worst real-world failure rate at 43 percent, with a manual revocation rate double that of the technology sector. On authentication, 93 percent of organizations are somewhere in a passkey rollout, but only 13 percent have deployed passkeys at scale.
Why it matters
The gap between believed and actual revocation speed is exactly the metric that offboarding processes are supposed to close, and self-reported confidence is a bad proxy for it: 94 percent claiming a 24-hour capability next to a 35 percent real failure rate means a third of organizations are trusting a control they haven't actually tested.
The passkey numbers tell a parallel story: rollout intent is nearly universal, but at-scale deployment sits at 13 percent, which lines up with why phishing and session-theft techniques covered elsewhere this week still work at scale. Confirm your own offboarding SLA against a real test, not a policy document, and treat "in progress" passkey rollouts as not yet providing the protection they're credited for.
Source: FIDO Alliance
Related on Start with Identity
- BlogUnit 42 finds malware can extract Google's synced passkey keys straight out of Chrome's memory
Palo Alto Networks Unit 42 disclosed three attacks, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that extract device identity keys and the master se
- BlogHID's Enterprise Attestation checks a passkey authenticator is company-issued before it can enroll
HID added a governance layer to its FIDO2 authenticators that checks for a certificate tying a device to a known company-issued authenticator before allowing pa
- BlogMalware can drive a Windows Hello key for Entra ID persistence without a PIN prompt
Dirk-jan Mollema showed that code running in a signed-in Windows session can use the victim's TPM-bound Windows Hello for Business key as a FIDO2 credential, sa
- RankingBest PAM for Enterprises: Top 5 Privileged Access Platforms
The best enterprise PAM platforms in 2026: CyberArk, BeyondTrust, Delinea, One Identity Safeguard, and WALLIX. Ranked for vaulting, session control, just-in-tim
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- ArticleAccess Review and Certification Best Practices: Preventing Rubber-Stamping and Building Effective Governance
How to design access review and certification programs that actually work, moving beyond compliance theater to meaningful governance through micro-certification