Future-proof IT security: Passkeys as protection against cyberattacks

Apr 22, 2026

The digital threat landscape for companies in German-speaking countries is constantly intensifying. Increasingly sophisticated ransomware attacks, the targeted use of artificial intelligence (AI) by cybercriminals, and the growing interconnectedness of business processes pose significant challenges to traditional password systems. Against this backdrop, the introduction of passwordless authentication methods, particularly passkeys, is gaining in importance. They mark a paradigm shift toward greater security, efficiency, and user-friendliness in digital identity management.

Current Threat Landscape: Cyberattacks on the Rise

The number of cyberattacks on companies in Germany, Austria, and Switzerland has risen sharply in recent years. According to current analyses, almost 2,000 attacks on German companies were registered weekly in the fourth quarter of 2025 alone. Ransomware attacks, which specifically target organizations in the energy and IT sectors, as well as educational institutions and critical infrastructure, are a particular focus.

The ongoing digitalization is constantly opening up new attack vectors for attackers. Modern cybercriminals are increasingly using AI-based tools to automate attacks and scale them to unprecedented levels. Managed service providers and collaboration platforms are particularly targeted, as they can act as multipliers for attacks on numerous downstream systems.

Ransomware and AI: New Threat Factors

Ransomware remains the dominant risk for businesses of all sizes. Attackers are increasingly relying on AI-powered methods to automate phishing campaigns, conduct negotiations, or launch individual social engineering attacks. The proportion of attacks on managed service providers has risen significantly worldwide in 2025, underscoring the particular vulnerability of this sector.

The threat landscape is also evident in Switzerland, albeit at a lower level than in other countries in the region. The number of compromised login credentials traded on the dark web remains high and forms the basis for further attacks – such as credential stuffing or brute-force attacks.

Financial sector in focus: AI exacerbates risks

The financial sector faces particular challenges due to the increasing use of AI-based attack tools. Forecasts for 2026 predict a significant increase in targeted attacks on banks and financial service providers. In particular, so-called “agentic AI” malware can dynamically adapt its behavior and effectively circumvent traditional defense mechanisms.

Another point of entry is provided by messenger services and deepfake technologies, which are used for social engineering campaigns. Fake job postings or manipulated communication channels serve to steal sensitive data. At the same time, demand is rising on the dark web for tools that allow users to bypass verification processes such as KYC (“Know Your Customer”). Companies that rely on desktop online banking are particularly vulnerable, while information stealers, offered as “Malware-as-a-Service,” can be deployed flexibly and scalably.

Passkeys: The Future of Authentication

In light of these developments, passwordless authentication is becoming central to modern IT security strategies. Passkeys offer an innovative and sustainable solution for strengthening the security of digital identities while simultaneously increasing user-friendliness.

What are Passkeys?

Passkeys are cryptographically generated digital keys that uniquely and securely control access to systems. They completely replace traditional passwords and are based on established standards such as FIDO2. Authentication is typically performed using biometric characteristics (e.g., fingerprint, facial recognition) or physical security tokens, significantly reducing the risk of intercepting or misusing access credentials.

Advantages of Passkeys at a Glance

  • Comprehensive protection against phishing, credential stuffing, and brute-force attacks
  • No sharing of sensitive access data with third parties
  • Easy integration into existing IT infrastructures
  • Improved user experience by eliminating password management
  • Compliance with regulatory requirements in sensitive industries
    Typical Use Cases
    Passkeys are suitable for a wide range of use cases, including access to enterprise applications and cloud services, securing internal communications, and authentication in regulated industries such as finance and healthcare.

Gradual Implementation of Passkeys: A Practical Roadmap

Implementing passkeys in companies requires a structured approach and the involvement of all relevant stakeholders. The first step is analyzing the systems and processes to be protected. This is followed by selecting suitable technologies – for example, FIDO2 tokens or mobile authentication solutions.

A pilot phase with selected user groups allows for gathering experience and making adjustments. Integration into central identity and access management systems then follows. Employee training is a crucial success factor to ensure acceptance and confidence in using the new authentication method. The rollout should be phased, accompanied by continuous monitoring and optimization of measures.

Best Practices for Secure Implementation

A comprehensive security concept goes beyond simply implementing passkeys. Combining them with multi-factor authentication further increases the level of protection. Regular review and adjustment of access rights are just as essential as integrating passkeys into emergency and recovery processes. This ensures that access to critical resources remains guaranteed even in an emergency. Conclusion: Passkeys as a sustainable shield against cyberattacks

The dynamic threat landscape posed by cybercrime and technological change necessitate innovative approaches to identity management. Passkeys offer companies a future-proof way to protect digital identities while simultaneously increasing user-friendliness. They minimize the risk of phishing and data theft, can be flexibly integrated into existing IT landscapes, and meet the highest compliance requirements.


Customers and Partners