Holberton & Co

The NCSC to begin recommending use of passkeys

Talk to an expert

The National Cyber Security Centre (NCSC) announced at CYBERUK 2026 in Glasgow that it will begin recommending the use of passkeys wherever a service supports them, and two-step verification (2SV) where it does not.


A passkey is a way to sign in that does not use a password. Instead, your account is linked to a device you own, such as a phone or computer. When you log in, the service asks your device to confirm it is you, and you approve this by unlocking the device with a fingerprint, face scan or PIN.


Based on analysis carried out by the NCSC, it has been concluded that passkeys provide stronger protection for users than traditional 2SV, which can be vulnerable to phishing. According to the NCSC, phishing is one of the most persistent causes of cyber compromise.


The NCSC point out that, as with any security control, passkeys need to be implemented and used sensibly to be most effective. Users will still depend on the security of their devices and credential managers.


See: https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in

August 6, 2026
Getting a shareholders’ agreement right

A shareholder’s agreement can be one of the most valuable documents a business ever puts in place. It allows a company’s owners to set out, in detail, how they will work together, make decisions, deal with disputes and manage future changes in ownership.

Read article
August 5, 2026
Employment Rights Act 2025: Employers concerned about new unfair dismissal protections

Acas, the workplace expert, have carried out research to find out which changes in the Employments Right Act 2025 are the hardest for businesses to adopt.

Read article