Passwordless authentication: strategic opportunities for CISOs

Published on 02.10.2026

Last updated on 02.10.2026

Reviewed by Aumatics IT specialists

Portrait of Antoin de Vrind.
Enterprise Consultant & RSA Specialist

Antoinde is an RSA specialist at Aumatics who helps organizations strengthen their security with smart identity and access management solutions. He combines technical depth with a pragmatic approach that delivers demonstrable value.

Summarize with AI

In short

De tijd van wachtwoorden loopt ten einde. Organisaties staan voor een fundamentele verandering in hoe toegang wordt beveiligd. Passwordless authentication, wachtwoordloos inloggen staat daarbij centraal. Waar wachtwoorden ooit de norm waren, vormen ze nu het grootste beveiligingsrisico. Voor CISO’s is het cruciaal om te begrijpen hoe passwordless past binnen een bredere identity security en Zero Trust strategie.

De uitdaging: wachtwoorden als risico én kostenpost

CISO’s weten het allang: wachtwoorden zijn kwetsbaar. Ze vormen de oorzaak van meer dan 80% van datalekken. Maar naast dit bekende feit zijn er drie minder besproken aspecten:

  • Complexiteit van beheer: elke extra toepassing betekent meer password policies en integraties.
  • Operationele kosten: helpdesks besteden 30–50% van hun tijd aan wachtwoordresets.
  • Compliance-risico’s: met NIS2, ISO27001 en GDPR wordt credential management steeds kritischer.

Hoe passwordless werkt op enterprise-niveau

Passwordless authentication vervangt het wachtwoord door sterke factoren, zoals biometrie of cryptografische sleutels. Maar voor een CISO is vooral interessant: hoe werkt dit in complexe omgevingen?

  • FIDO2 en WebAuthn
    Open standaarden zorgen voor interoperabiliteit en brede adoptie. Hardwaretokens en biometrie communiceren direct met applicaties zonder wachtwoordoverdracht.
  • Risk-based authenticatie
    RSA gebruikt machine learning om contextuele signalen (locatie, device, gedrag) te analyseren. Afwijkingen leiden tot extra controles.
  • Hybrid failover
    RSA biedt een unieke hybride aanpak: passwordless werkt in de cloud én on-premise. Dit is cruciaal voor organisaties met legacy-applicaties of strikte data residency-eisen.

Compliance en frameworks

CISO’s sturen hun securitystrategie vaak op basis van frameworks. Passwordless helpt bij:

  • NIS2: verhoogt identity assurance en vermindert kans op credential-aanvallen.
  • NIST 800-63: ondersteunt de hoogste assurance levels (AAL3) met FIDO2.
  • ISO27001: draagt bij aan identity & access controls (Annex A.9).
  • Zero Trust: passwordless maakt continue verificatie gebruiksvriendelijk en schaalbaar.

RSA versus de concurrentie

Op de markt zijn meerdere spelers actief (Okta, Ping, Microsoft, SailPoint). Waarom RSA onderscheidend is:

  1. Cloud én on-premise support – waar concurrenten vaak enkel cloud-first zijn.
  2. Risk AI – RSA’s risk-based authenticatie-engine gebruikt AI voor real-time risicodetectie.
  3. Brede portfolio – naast passwordless ook IGA (Governance & Lifecycle) en hardwaretokens.
  4. Integraties – bestaande infra en applicaties kunnen mee in de transitie, zonder big bang.

Businesscases

  • Financiële sector
    Een Europese bank verminderde het aantal wachtwoord-gerelateerde helpdesk-calls met 65% door de implementatie van RSA passwordless. Tegelijkertijd verbeterde de audit-rapportage.
  • Gezondheidszorg
    In een ziekenhuis kregen artsen via biometrie sneller toegang tot patiëntendossiers, terwijl de NEN7510- en GDPR-compliance werd versterkt.
  • Overheid
    Bij een ministerie in Europa werd passwordless ingezet om VPN-toegang zonder wachtwoorden te realiseren, in lijn met Zero Trust-eisen.

De rol van de CISO

Passwordless is niet alleen een IT-project. Voor CISO’s zijn er strategische keuzes:

  • Roadmap: kies een gefaseerde aanpak. Start met kritieke systemen en breid uit.
  • Adoptie: communicatie en training zijn cruciaal om weerstand bij medewerkers te minimaliseren.
  • Integratie: passwordless moet aansluiten op IAM en IGA-processen.
  • Risicomanagement: passwordless is geen silver bullet. Combineer het met governance, monitoring en threat intelligence.

How Aumatics and RSA bring this together

As a Gold Partner of RSA, Aumatics supports organizations in implementing passwordless authentication as part of a broader security and compliance strategy. Our added value for CISOs:

  • Advice and roadmap tailored to your sector and compliance frameworks.
  • Implementation and integration within existing IAM/IGA landscapes.
  • 24/7 managed services for monitoring, support, and continuous improvement.
  • Sector-specific expertise (finance, government, energy, healthcare).

Conclusion

For CISOs, passwordless authentication is more than just convenience: it is a strategic investment in identity security. It reduces risks, lowers operational costs, and supports compliance with new laws and regulations.

RSA offers a unique combination of cloud and on-premise solutions, risk-based authentication, and a proven portfolio. Together with Aumatics, we provide an approach that goes beyond implementing technology to help organizations successfully operationalize passwordless authentication.

Always have visibility into threats. Even outside office hours.

Security alerts often come from multiple systems at once. But without proper follow-up, alerts are mostly just noise. With Managed SOC, Aumatics helps you monitor, prioritize, and follow up on threats 24/7. This way, you know faster what is important, where action is needed, and how to manage incidents before they escalate.

Frequently asked questions about this topic

Passwordless authentication is a method of logging in without a password. Instead, you use biometrics, a hardware token, or a mobile push notification. This increases security and improves the user experience.

Passwordless can include MFA, but it goes a step further. It removes the password entirely, eliminating risks such as phishing and credential stuffing. RSA often combines passwordless login with risk-based policies and multiple factors for maximum security.

The transition usually begins in phases: first with critical systems or a specific user group, followed by the wider organization. With RSA solutions and Aumatics' implementation and management services, passwordless can be easily integrated into existing IAM and Zero Trust strategies.

Contents

Need a SOC without an in-house night shift?

Have threats monitored, analyzed, and addressed 24/7 by security specialists who understand your environment.

Discover Managed SOC

Read more

Check out our other resources

SOC

2/10/2026

What is a SOC (Security Operations Center)? Explanation, how it works, and outsourcing

Discover what a Security Operations Center does, how monitoring and incident response work, and when it is better to build your own SOC or outsource it to experts.

IAM

2/10/2026

Low-hanging fruit for hackers: Why Identity Lifecycle Management is a necessity.

Identity Lifecycle Management automates identity administration in large hybrid environments, prevents permission sprawl, and ensures audit-ready compliance.

IAM

2/10/2026

Why Identity Governance & Administration (IGA) is essential in 2025

IGA helps organizations mitigate risks, manage access, and support compliance. Learn how to implement identity governance in a practical way.

Neem contact op

Benieuwd hoe we jouw organisatie verder kunnen helpen?

24/7 monitoring of your IT environment
Detect and monitor cyber threats
Secure cloud and network environments
Control over identities and access rights
Protecting critical IT and OT systems
Discover vulnerabilities before attackers do.
Workspaces that are safe and seamless
Personal support for IT questions
Secure backups for business-critical data
Gain better control over your cloud costs
24/7 monitoring of your IT environment
Detect and monitor cyber threats
Secure cloud and network environments
Control over identities and access rights
Protecting critical IT and OT systems
Discover vulnerabilities before attackers do.
Workspaces that are safe and seamless
Personal support for IT questions
Secure backups for business-critical data
Gain better control over your cloud costs