Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Passwordless and Passkeys Explained (For Non-Techies)

In short

Passkeys are a new way to sign in that replaces the password with your device's fingerprint, face or PIN. Because there's no password to guess, leak or trick out of you, passkeys are far harder for criminals to steal and are effectively phishing-proof. This article explains what they are in plain terms, why they beat passwords, and how to start using them.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

The problem with passwords

We have all been told to use long, unique passwords for every account, never reuse them, and change them when there is a breach. It is good advice and it is also exhausting — which is exactly why almost nobody manages it. People reuse the same password, write it on a sticky note, or use something guessable.

Even when you do everything right, passwords have a deeper flaw: they are a secret you have to type in somewhere. And anything you type in can be tricked out of you, stolen in a data breach, or captured on a fake website. That is the weakness passkeys are designed to remove.

So what is a passkey?

A passkey lets you sign in to a website or app the same way you unlock your phone — with your fingerprint, your face, or a PIN. There is no password to type.

Here is the idea without the technical detail. When you create a passkey for a website, your device quietly generates a pair of matching keys. One stays locked inside your phone or laptop and never leaves it. The other is given to the website. To sign in, the website asks your device to prove it holds the matching secret, and your device does that only after you unlock it with your face, fingerprint or PIN.

From your side, it simply feels like unlocking your device. Behind the scenes, the secret that proves it is you never leaves your phone in a form anyone could copy and reuse.

Why passkeys beat passwords

The advantages are not marginal. They close off the most common ways businesses get broken into.

There is no password to steal, so there is nothing for a criminal to phish, guess, or find in a data breach.

  • They are effectively phishing-proof. The most common attack on small businesses is a fake login page that tricks staff into typing their password. With a passkey there is nothing to type, and the passkey is tied to the genuine website — so a fake page simply cannot capture it. This is why phishing becomes far less dangerous once passkeys are in place.
  • Nothing to guess or reuse. There is no word to be weak, no password reused across five sites, no sticky note on the monitor.
  • A breach elsewhere cannot hurt you. When a company you use is hacked and its passwords leak, your passkey is not among them — because the secret was never handed over in the first place.
  • They are quicker. Unlocking with a fingerprint is faster than typing a long password, so the secure option is also the easier one. That is rare and valuable.

In short, passkeys give you protection similar to good multi-factor authentication, but built in and simpler, because the sign-in itself is the strong step.

“But what if I lose my phone?”

This is the first question everyone asks, and it is a fair one. The reassuring answer is that you will not be locked out, provided you set things up sensibly.

Passkeys are not trapped on a single device. When they are stored in your Apple, Google or Microsoft account — or in a password manager — they sync securely across your devices and can be restored on a new phone once you sign back in. Lose your handset and you buy a new one, sign into your account, and your passkeys come with you.

The sensible approach is the same as with the keys to your office: keep them backed up in one of those secure places, and make sure you have a second way into your most important accounts. Set up once, thoughtfully, and losing a device is an inconvenience rather than a crisis.

Where passkeys fit with a password manager

Here is the practical reality for the next few years. Passkeys are clearly the direction of travel, and the big names — Microsoft, Google, Apple — are all pushing them hard. But plenty of websites still only offer passwords, and will for a good while yet.

So you are going to need both: passkeys where they are offered, and strong, unique passwords everywhere else. The neatest way to handle that is a password manager that also stores passkeys, so everything lives in one secure, synced place instead of being scattered across your phone, your laptop and your memory.

That is exactly what a good manager does. Proton Pass, for instance, stores both your passwords and your passkeys in one encrypted app that syncs across your devices, so you get passkeys where sites support them and strong passwords everywhere else — without juggling two systems. If you are choosing a tool, our guide to the best password manager for a small business walks through what to look for.

How to start (this week)

You do not need a big project. Start small and let it grow.

  1. Turn a passkey on for one important account. Your Microsoft, Google or Apple account is a great first choice. In the security settings you will find an option to add a passkey — follow the prompts and use your fingerprint or face when asked.
  2. Make sure it is backed up. Confirm the passkey is saved to your account or your password manager, so it will sync to your other devices and survive a lost phone.
  3. Add passkeys as you go. Each time you sign into a site and it offers a passkey, say yes. Over a few weeks your most-used accounts quietly become far harder to break into.
  4. Roll it out to the team. For a business, the biggest wins come from protecting the accounts everyone shares or that hold sensitive data — email above all. This is a natural part of tightening up your cyber-security.

The bottom line

Passwords are a secret you have to type, and anything you type can be stolen or tricked out of you. Passkeys remove that weakness by tying your sign-in to your own device and your fingerprint or face. They are more secure, effectively phishing-proof, and genuinely quicker to use.

You do not have to switch everything overnight. Turn a passkey on for one important account this week, keep your passwords in a manager that also holds passkeys, and add more as sites offer them.

If you would like help rolling passkeys and a password manager out across your team properly — backed up, secure, and easy for staff to use — get in touch. We will set it up so it is safer and simpler at the same time.

Frequently asked questions

What is a passkey, in simple terms?

A passkey is a way to sign in to a website or app using the same thing you use to unlock your phone or laptop — your fingerprint, your face, or a PIN. Behind the scenes your device holds a secret key that proves it's you, so you never type a password. From your side it just feels like unlocking your device, but it's far more secure than a password because there's nothing to type, remember or accidentally hand over.

Are passkeys really safer than a strong password?

Yes, meaningfully so. A strong password can still be phished, guessed, reused across sites, or exposed in a company's data breach. A passkey can't be any of those things because there's no secret you type in — the proof of identity never leaves your device in a form a criminal could reuse. It's the single biggest step most people can take against account takeover, and it removes the most common way businesses get broken into.

What happens if I lose the phone with my passkeys on it?

You won't be locked out, provided you set things up sensibly. Passkeys stored in Apple, Google or Microsoft accounts, or in a password manager, sync securely across your devices and can be restored on a new phone once you sign back in. The safe approach is to have your passkeys backed up in one of those places and a second way to get into your key accounts, exactly as you would keep a spare key to your office.

Do passkeys replace my password manager?

Not yet — they work alongside it. The world is moving to passkeys but plenty of sites still only offer passwords, so you'll need both for a good while. The practical answer is to use a password manager that also stores passkeys, so everything lives in one secure, synced place. You get passkeys where they're offered and strong, unique passwords everywhere else, all in one app.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.