October 8, 2026
Make security easy for your workforce: Take friction out of authentication
This Cybersecurity Awareness Month, make security the easy choice.
Cybersecurity Awareness Month is a reminder that security depends on the choices people make every day. For frontline workers, however, making the secure choice can be difficult when authentication repeatedly interrupts the work. A clinician signs in to access a patient record. A manufacturing worker authenticates to a production system. A law enforcement officer signs in to access sensitive criminal justice information.
Each interaction may take only a few seconds. But when secure access requires another password to remember, another credential to enter, or another prompt to complete, those interruptions add up. In some industries, workers can spend up to 45 minutes each day just logging in. That’s valuable time spent just getting access instead of doing real mission-critical work.
Authentication friction can create security problems, too. When the approved way to access a system is slower or harder than the workaround, people have more reason to find a faster path. Shared credentials, unattended sessions, and other shortcuts can undermine the controls designed to protect an organization.
So, if we want workers to make the secure choice, we need to make that choice easier. Authentication is a practical place to start. Passwordless authentication can replace repetitive password entry with faster, more intuitive ways to authenticate, reducing friction without asking security teams to compromise on protection.
Take traditional passwords out of the workflow
Passwords place the burden of security on the person trying to get work done. Workers have to create them, remember them, enter them correctly, change them, and keep them secure. And increasingly, pass “words” are becoming much longer, more complex pass “phrases,” often eclipsing 16 characters or more. Enter one incorrectly too many times, and a worker may be locked out entirely, requiring them to make a help desk call and reset their password before they can get back to work. Multiply those requirements across applications and repeated authentication events, and passwords become a persistent source of friction that can ultimately encourage workarounds, such as sharing or borrowing credentials.
Passwordless authentication changes that experience by allowing people to authenticate using methods such as biometrics, badges, passkeys, PINs, and other authenticators suited to the workflow. Phishing-resistant methods such as FIDO-based passkeys can also make stolen or phished credentials less useful to an attacker.
The key is to make the secure action feel like a natural part of the work. If a worker can authenticate with a badge, biometric, or passkey instead of stopping to type a password, security no longer has to compete with the faster path. The faster path is the most secure one.
Build authentication methods around the way people work
Going passwordless doesn’t mean choosing one authenticator and applying it everywhere. The right approach depends on the worker, device, environment, and task.
A clinician moving between shared workstations might benefit from fast badge-based or biometric authentication. A frontline worker in a manufacturing plant using a personal device may be better served by a passkey. Other environments may require different authenticators based on the devices available or the conditions of the workspace.
That flexibility matters because frontline technology environments rarely follow a simple one-person, one-device model. Shared workstations and mobile devices may sit alongside personal devices and specialized systems. Authentication must work within those realities.
Before selecting an authentication method, security and IT leaders should look closely at the workflow and ask:
- How often does someone authenticate?
- Is the device shared?
- How quickly do workers need to switch?
- Are workers wearing gloves, masks, or other protective equipment that may make certain authentication methods less practical?
- Which authentication steps cause delays, lockouts, or service desk calls?
- Where are people already finding workarounds?
Those answers can reveal where passwordless authentication will remove meaningful friction rather than simply replace one authentication method with another.
Add assurance when the situation calls for it
Removing passwords from routine access doesn’t mean reducing security. Organizations still need confidence that the person requesting access is who they claim to be, and that the access is appropriate for the situation. That level of confidence is often referred to as identity assurance.
Not every interaction requires the same level of assurance. A worker accessing a familiar application from a known device during a normal shift presents a different level of risk than someone enrolling a new credential, recovering an account, or requesting access to sensitive information.
For those higher-risk moments, organizations may need additional evidence before granting trust. Identity verification can help confirm that the person receiving, resetting, or recovering a credential is the person authorized to use it. Establishing greater confidence at these important points in the identity lifecycle can help organizations avoid repeatedly placing the same burden on workers during routine access.
Adaptive authentication can apply a similar principle to ongoing access. Signals such as the device being used, location, behavior, or sensitivity of the requested resource can help determine whether the existing authentication is sufficient or another step is warranted.
This allows security teams to increase assurance when risk changes without making every worker complete the strongest possible authentication process every time they need access.
Resolve existing friction before adding another access control
Cybersecurity Awareness Month often focuses on what people can do to improve security. It’s also an opportunity for security leaders to examine what their security processes ask of the workforce. If secure behavior requires repeated interruptions or processes that don’t fit the way people work, awareness alone won’t solve the problem.
Start where authentication interrupts work. Look at repeated password entry, frequent resets and lockouts, shared credentials, abandoned sessions, and service desk demand. These can reveal where authentication isn’t working for the workflow. Then ask whether passwordless authentication could make the secure path easier to follow. For higher-risk moments, consider where identity verification or adaptive authentication could add confidence without imposing another step on everyone.
Making security the easy choice means designing controls around the realities of the work they protect. For frontline workers, that starts with making authentication faster and more natural than the workaround.
But authentication is only the beginning. In the next installment of this Cybersecurity Awareness Month blog series, we’ll look at what happens when risk levels change, and why stronger security doesn’t have to mean adding more friction for everyone.