Resources - Blog

How Passwordless Authentication Protects UAE Enterprises

The Kernel
August 7, 2026

More than 75% of cyber breaches in the UAE begin with a phishing email or a fraudulent message, and a recent CyberArk study found that 92% of UAE organisations experienced at least three successful identity-related breaches in the twelve months to April 2026, well above the EMEA average of 80%. Phishing volumes in the region rose 21.2% in a single quarter last year, according to Kaspersky.

Traditional multi-factor authentication was supposed to close this gap. Increasingly, it does not. Attackers have adapted to it directly, through MFA fatigue attacks that flood a user with approval requests until one gets accepted, and through reverse-proxy phishing kits that intercept a one-time code the moment a user types it into a spoofed Microsoft 365 login page. The credential and the second factor both end up in the attacker's hands, often without the user noticing anything was wrong.

Passwordless authentication is designed to close this specific gap, not just add another layer on top of it.

Why passwords and OTP codes are the problem, not the fix

A password is a shared secret. So is a one-time code sent by SMS or generated by an authenticator app. Both can be typed into a phishing page, both can be intercepted, and both work exactly as well for an attacker as they do for the legitimate user, because nothing about the credential itself proves who is presenting it or where they are presenting it from.

Passwordless authentication, built on the FIDO2 and WebAuthn standards, removes the shared secret entirely. Instead of a password or a code, the user proves possession of a private key that never leaves their device or hardware security key. That key is cryptographically bound to the specific website or application it was registered with. If a user is tricked into visiting a convincing fake login page, the authenticator simply will not respond, because the origin does not match. There is no code to intercept and no approval prompt to fatigue someone into accepting, because the attacker never has anything worth phishing in the first place.

This is why passwordless is described as phishing-resistant rather than just phishing-aware. The protection is structural, not behavioural.

The compliance case is catching up with the security case

For UAE organisations, this is no longer purely a risk reduction argument. NCA, NESA, and SAMA frameworks increasingly expect authentication controls that map to NIST SP800-63B assurance levels, and AAL3, the highest tier, specifically requires a hardware-based authenticator resistant to verifier impersonation. A password with an SMS code does not meet that bar. A FIDO2 hardware key or certificate-based smart card does.

Regulated sectors, financial services, government, and critical infrastructure in particular, are the ones most likely to see this shift from a recommendation to a requirement in the near term.

The momentum is already there

Passwordless is not an early, unproven technology anymore. The FIDO Alliance reports 5 billion passkeys now in active use worldwide, and 87% of enterprises are actively deploying or piloting FIDO2 passkeys, up sharply from 53% two years earlier. Passkey logins succeed roughly 93% of the time compared with 63% for passwords, and complete significantly faster.

Organisations still have real reasons to move carefully. The most commonly cited barriers are legacy system compatibility, budget approval, and questions about how account recovery works when a device is lost. None of these are reasons to avoid passwordless. They are reasons to plan the rollout properly.

What a proper rollout actually looks like

Passwordless authentication is not one product or one method. Different user populations need different approaches, and most enterprise environments need more than one running at the same time.

Hardware security keys, such as Yubico's YubiKey range, suit high-risk users: administrators, finance teams, and anyone handling sensitive data, where a device-bound physical key offers the strongest phishing resistance available.

Passkeys, through platforms like 1Password, suit general staff who need a fast, low-friction rollout across a large workforce without issuing physical hardware to everyone.

Certificate-based authentication, through Pointsharp, matters for privileged accounts and for the legacy, on-premises, and hybrid applications that most cloud-only passwordless tools cannot reach. This is often the piece organisations underestimate: most enterprises in the UAE are running at least some infrastructure that a pure SaaS passwordless platform was never built to cover.

Managing hardware keys at scale introduces its own operational problem: knowing who has been issued a key, deprovisioning it correctly when someone leaves, and keeping a clean audit trail. Appterix by EgoMind exists specifically to solve that lifecycle problem for organisations running YubiKey deployments.

Getting the combination right, and getting it to work across cloud and legacy systems at once, is the part that determines whether a passwordless rollout actually reduces risk or just becomes another tool nobody fully adopts.

Choosing the right method starts with knowing your risk

Not every user needs a hardware key, and not every application can support one yet. The organisations that get the most value from passwordless authentication start by mapping which users, applications, and compliance obligations matter most, then match the authentication method to that reality rather than picking one platform and forcing every use case through it.

The Kernel represents Yubico, 1Password, Pointsharp, and EgoMind across the Middle East, Africa and CIS, and maps every deployment to NCA, NESA, SAMA, and NIST SP800-63B as part of the engagement.

Ready to work out which passwordless approach fits your environment?

Talk to our team | Explore our Strong Authentication solution

Want these in your inbox?

We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.

First name
Last name
Email
Thank you for subscribe.
Oops! Something went wrong while submitting the form.