Passwords and one-time passwords (OTPs) have long been the most familiar line of defense in cybersecurity, yet recent data shows they are increasingly becoming the most exploited vulnerabilities. From your perspective, what new authentication methods are gradually replacing these old habits to provide stronger security without adding friction for users?
That is a fundamental question. To frame it from a FIDO Alliance perspective, a recent study by FIDO and HID revealed that 70 per cent of organizations experienced at least one identity-related security incident in the past two years. Even routine processes, such as revoking password access for departing employees, still fail at scale.
While 94 per cent of organizations express confidence in their current processes, the report showed that 35 per cent of breaches involve significant delays and failures. Consequently, our relationship with passwords and OTPs has reached a point where it is truly time to adopt a more reliable and secure standard.
My answer is simple: passwordless authentication with passkeys. Passkeys serve as a much better alternative to passwords because they are fast, enable authentication via a PIN or biometrics directly on the user’s device, and enjoy widespread adoption across websites and mobile devices due to being built on open standards.
Digital transformation in Vietnam and the region is accelerating at breakneck speed, bringing stricter security demands from both the market and regulators. How do you assess Vietnam’s readiness and adoption speed for advanced authentication solutions compared to other ASEAN countries?
Vietnam is remarkably tech-savvy, and adoption rates for new technologies within this market consistently outpace expectations. Naturally, this momentum is most potent when backed by strong regulatory guidance steering the industry forward.
The primary precursor to accelerated adoption is for Vietnamese regulators to formally prescribe passkeys more precisely within specific industries. While we have observed progressive implementation rates across various regions, Vietnam is in an exceptionally strong position to embrace a fully passwordless future.
Vietnam has introduced its national citizen application, VNeID, which is conceptually similar to Singapore’s SingPass, though with its own unique characteristics, demonstrating that the country already possesses the infrastructure and institutional maturity to recognize the need for improved digital identity security. As long as we establish clear specifications for passwordless authentication, Vietnam will undoubtedly accelerate its adoption trajectory.
Security can no longer be treated as just a one-time login checkpoint, especially when many incidents stem from internal operational gaps or loose account management. How should businesses shift their mindset to comprehensively protect every touchpoint of the customer journey, from onboarding and transactions to account recovery?
Beyond establishing passwordless methods like passkeys, organizations must view security through the lens of comprehensive journey management. When securing touchpoints with stronger authentication measures, enterprises must also account for how these new credentials and devices will be managed lifecycle-wide.
Traditionally, organizations managing passwords dealt with routine overhead like resets and changes. Transitioning to passwordless authentication requires an equally robust operational strategy. Many organizations underestimate this shift, assuming that deployment is the final step, only to struggle during operational phases with scenarios such as lost devices or seamless replacements.
Effective credential management is crucial for a successful passwordless deployment. To handle these ongoing operational maintenance events, we at HID always recommend implementing a dedicated Credential Management System or Passkey Management System that organizations can operate seamlessly.
A constant paradox for organizations is that the tighter the security measures, the more friction customers experience. How can Vietnamese enterprises resolve this “trade-off”, successfully balancing cybersecurity, regulatory compliance, and everyday convenience for end users?
A reliable guiding principle in general is: verify the person locally, protect the credential on the device, and share only what the service needs.
Balancing privacy, security, and usability requires gathering situational context. Possessing contextual awareness enables organizations to manage risk effectively and execute precisely the right authentication procedures required for a given transaction at that specific moment.
Looking toward the future of digital identity driven by cloud technology and biometrics, what opportunities does Vietnam have to learn from more mature markets and leapfrog them? From a practical standpoint, how do unified solutions like the HID Authentication Platform help organizations tackle these challenges?
Looking ahead three to five years, we can safely bet that passkeys will become the default standard, rendering manual password creation virtually obsolete. A unified platform that supports multiple authentication factors and security protocols such as the HID Authentication Platform helps organizations prepare for this future, backed by the solid infrastructure already present in Vietnam.
Furthermore, authentication will become increasingly context-driven, factoring in the operating environment before any action is taken to optimize both usability and security. Following the FIDO Alliance blueprint will also allow Vietnam to adopt next-generation authentication solutions aligned with global best practices.
Looking even further into the future, another groundbreaking solution currently being developed by the FIDO Alliance is Verifiable Digital Credentials (VDC). Similar to initiatives like VNeID and SingPass, VDC functions as a digital wallet that allows organizations to verify factual claims about a user without over-sharing personal data, thus preserving privacy while digitally proving credentials. While still in early transition phases globally with initial steps seen in Europe, passkeys remain the immediate cornerstone of the passwordless movement today.
Google translate