Online security is moving beyond passwords, but passwords have not disappeared yet. For most people and organisations in the UK, the real question is no longer “Should I use a password manager?” but “How do I combine password managers, passkeys and device-based login without creating new risks?”
The answer depends on where you are on the security maturity curve: a single personal account, a household with shared devices, a small business, or a larger organisation with compliance needs. As the stack gets more complex, the right controls change too.
Why the password era is ending slowly, not overnight
Passwords still dominate because they are familiar, cheap to deploy and supported everywhere. Walk into any office in London, and you’ll find critical systems running on credentials that haven’t changed since the pandemic. That’s not negligence — it’s the reality of legacy infrastructure. But passwords are also weak in practice: people reuse them, choose predictable ones, and fall for phishing. That is why password managers became mainstream first, and why passkeys are now the next step.
The shift is layered, and understanding the layers is what separates a resilient setup from a fragile one. Each tool addresses a different vulnerability:
– **Password managers** reduce reuse and make strong passwords practical. They solve the human memory problem — nobody can remember 200 unique, complex passwords.
– **Passkeys** remove the password from the login step in many cases. This is a structural change, not just a convenience upgrade, because it eliminates the attack surface that phishing relies on.
– **MFA and device trust** add another layer for accounts that still rely on passwords. Think of MFA as the safety net when the primary credential fails.
In other words, online security is becoming layered rather than singular. That matters because the weakest layer usually determines the outcome. An attacker doesn’t need to break your passkey if they can reset your account through an unprotected email inbox.
Stage 1: Basic password hygiene for individuals and families
If you are still using the same password across multiple sites, this is the first stage to fix. At this level, the goal is not sophistication; it is stopping the most common account takeovers. I’ve seen too many people invest time in advanced security tools while their foundations are cracked — and that’s where the breaches happen.
What to do first
– Use a **unique password** for every important account.
– Turn on **multi-factor authentication** where available.
– Secure your email account first, because it is often the recovery route for everything else.
– Check whether any passwords have already appeared in a breach.
– Keep recovery codes somewhere safe and separate from your primary device.
Why this stage matters
Most account compromise begins with credential reuse, not highly targeted attacks. If one weak login is reused across shopping, banking, email or social media, a breach elsewhere can quickly become your problem. This isn’t hypothetical — credential stuffing attacks automate exactly this pattern, testing leaked username-password pairs across dozens of services in seconds. The economics of cybercrime favour scale, and reuse is what makes that scale possible.
Common mistake
Many people think “my password is long, so I am safe.” Length helps, but reuse cancels that advantage. A strong password that appears on several sites is still a liability. I’ve spoken to security researchers who’ve traced major corporate breaches back to a single employee’s reused personal password from a compromised gaming forum. The chain of compromise doesn’t care about length.
Stage 2: Password managers become the practical upgrade
A password manager is software that stores and fills credentials securely, so you do not need to remember each one. For most users, this is the biggest real-world improvement available today. When I first started covering consumer tech, password managers were niche tools for the paranoid. Now they’re a baseline expectation — and the quality of the leading options reflects that shift.
What a good password manager should do
| Capability | Why it matters |
|---|---|
| Strong password generation | Prevents weak or recycled passwords |
| Cross-device sync | Keeps access consistent on phone, laptop and tablet |
| Autofill support | Reduces typing and phishing exposure |
| Breach monitoring | Flags reused or exposed credentials |
| Secure sharing | Useful for households and teams |
| Recovery options | Helps if a device is lost or replaced |
How to use one well
– Protect the manager with a **strong master password**. This is the single most important credential you’ll create — treat it accordingly.
– Turn on **MFA** for the password manager itself. If the vault that holds all your other keys isn’t behind an additional factor, you’ve concentrated your risk rather than distributing it.
– Review shared vaults carefully if you use family or team plans. Accidental sharing of personal credentials happens more often than you’d expect.
– Store recovery codes offline, not inside the same account ecosystem. A printed copy in a drawer beats a digital note in the same cloud storage.
– Audit old logins and delete accounts you no longer use. Every dormant account is an unmonitored entry point.
Limits to understand
A password manager is not magic. If your master password is weak, your device is infected, or you approve a fake login prompt, the manager cannot save you. It reduces friction and human error; it does not eliminate risk. The tool is only as secure as the practices around it — something I’ve seen overlooked even in well-funded startups that should know better.
Stage 3: Passkeys change the login model
Passkeys are a newer way to sign in that replaces the password with cryptographic keys stored on your device or synced securely across devices. In simple terms, your device proves it is yours without you typing a secret that can be stolen. The underlying technology — based on FIDO2 and WebAuthn standards — has been developing for years, but mainstream adoption has accelerated dramatically since Apple, Google and Microsoft began pushing it across their ecosystems.
Why passkeys matter
Passkeys are designed to resist:
– phishing,
– credential stuffing,
– password reuse attacks,
– database leaks of stored passwords.
That is a meaningful step forward because many breaches succeed not by breaking encryption, but by tricking people into handing over their login details. Think about every phishing email you’ve seen — they all depend on convincing you to type something into a fake form. Passkeys break that model because there’s nothing to type and the cryptographic handshake only works with the legitimate site.
What users notice in practice
– You may sign in with Face ID, fingerprint, PIN, or device unlock.
– You often do not need to remember a password at all.
– Logging in can be faster on mobile and desktop.
– Supported services increasingly offer passkey setup during account security settings.
The catch
Passkeys are not everywhere yet. You will still encounter older services, work systems, and niche websites that rely on passwords. Banks, government portals, and enterprise software often lag on adoption — and in heavily regulated sectors, that lag can stretch to years. That means most users need a hybrid setup for now, not a pure passkey-only world.
Password managers vs passkeys: which one is replacing which?
They are not exact substitutes. A password manager stores and creates passwords. A passkey replaces the password on supported accounts. In many setups, the two will coexist for years. I’ve heard the question framed as an either-or choice, but that misses the point: these tools address different parts of the security lifecycle.
| Feature | Password manager | Passkey |
|---|---|---|
| Stores passwords | Yes | No |
| Removes password from login flow | No | Yes |
| Works on most websites today | Yes | Growing, but not universal |
| Helps with old accounts | Yes | Limited |
| Strongly resistant to phishing | Better than manual passwords | Very strong |
| Best use case | Broad coverage across all accounts | Modern supported services |
The practical takeaway is simple: **use a password manager now, and adopt passkeys wherever they are available**. This isn’t about picking a winner — it’s about building coverage. The password manager handles the legacy world; passkeys handle the future. Together, they close more gaps than either can alone.
Stage 4: Building a modern login strategy
Once the basics are covered, the next stage is designing a system that fits your actual risk level. This is where security stops being a checklist and starts being a design problem. The right setup for a freelance journalist looks very different from what a ten-person architecture firm needs.
For personal users
A sensible setup usually looks like this:
– password manager for all credentials,
– passkeys enabled on major services,
– MFA turned on for email, banking and cloud storage,
– device lock enabled on phones, laptops and tablets,
– recovery methods checked and updated.
The key word here is “checked.” I’ve met people who set up recovery options years ago and can’t remember which email or phone number they used. A system that works in theory but fails in practice isn’t a system — it’s an assumption.
For households
Families often run into shared-device issues, especially with streaming, shopping, school portals and password resets. The friction here isn’t technical; it’s social. One person’s rushed password reset can cascade through everyone’s accounts.
– Use shared vaults for communal accounts.
– Keep personal and shared logins separate.
– Avoid sending passwords in messaging apps.
– Make sure one person’s lost device does not expose everyone else’s accounts.
For small businesses
This is where online security becomes operational rather than purely personal. I’ve consulted with small firms that had more digital assets than they realised — client data, invoicing platforms, cloud collaboration tools — and no coherent access policy for any of it.
– Use a business-grade password manager with admin controls.
– Standardise passkey adoption where supported.
– Require MFA on email, finance and admin tools.
– Remove shared credentials where possible.
– Document onboarding and offboarding steps.
A small business often has enough digital assets to be attractive to attackers, but not enough security staff to manage complexity manually. That is exactly where password managers and passkeys pay off. They automate what would otherwise require constant manual attention.
Step-by-step: how to move from passwords to passkeys
1. Audit your most important accounts.
2. Secure your email and financial accounts first.
3. Set up a trusted password manager.
4. Replace weak or reused passwords with generated ones.
5. Enable MFA everywhere it is available.
6. Turn on passkeys for major supported services.
7. Keep at least one recovery path that does not depend on a single phone.
8. Review your setup after buying a new device or changing phone numbers.
Typical mistakes that weaken the whole setup
– Using the password manager but skipping the master password security.
– Enabling passkeys on one device without checking recovery options.
– Treating SMS codes as a long-term solution for sensitive accounts.
– Storing recovery codes in the same place as the account credentials.
– Leaving old accounts active and forgotten.
– Assuming one layer of protection is enough.
What good looks like at each maturity level
| Maturity level | Main priority | Main risk | Best next move |
|---|---|---|---|
| Beginner | Stop reuse | Credential leakage | Start a password manager |
| Intermediate | Reduce phishing and weak logins | Human error | Add MFA and clean up old accounts |
| Advanced | Remove password dependence where possible | Device loss and recovery gaps | Adopt passkeys broadly |
| Mature | Standardise access management | Process failure | Formal policies, admin control and periodic review |
Security questions worth asking before you switch tools
– Can I recover access if I lose my phone?
– Does this service support passkeys on all the devices I use?
– Can I separate personal, family and work logins?
– What happens if my password manager account is unavailable?
– Are my recovery codes stored safely offline?
These are not theoretical questions. They decide whether your system is resilient or merely convenient. I’ve watched people confidently migrate to new tools only to discover, during a real incident, that their recovery path depended on assumptions they’d never tested. Don’t wait for an emergency to find the gaps.
FAQ
Are password managers still necessary if I use passkeys?
Yes. Passkeys are growing fast, but many services still rely on passwords. A password manager remains useful for older accounts, device compatibility and secure credential storage. Until passkey support becomes universal — which is years away, not months — the password manager fills the coverage gaps.
Are passkeys safer than passwords?
Yes, for supported services. Passkeys are designed to be phishing-resistant and do not rely on a reusable secret typed by the user. The cryptographic model means that even if a service’s database is breached, there are no stored passwords to leak.
Can I use passkeys on more than one device?
Usually yes, depending on the platform and service. Many ecosystems now support syncing passkeys across trusted devices, but recovery and transfer behaviour varies. Check how your specific platform handles this before committing — the experience differs meaningfully between Apple, Google, and third-party password managers that have added passkey support.
What should I secure first?
Start with your email account, then banking, cloud storage and any account that can reset others. Those are the highest-value targets. If an attacker gets into your email, they can often reset passwords for everything else. That single account is the keystone of your digital identity.
Is SMS-based two-factor authentication enough?
It is better than nothing, but it is not the strongest option. SIM-swapping attacks — where an attacker convinces a mobile carrier to transfer your number to their device — remain a real threat, especially for high-value targets. App-based or device-based authentication is generally stronger, especially for important accounts.
The next phase of online security is not about choosing one tool and declaring the problem solved. It is about building a layered setup that fits where you are today, while leaving room to move toward a passkey-first future. The tools are maturing faster than most people’s habits are changing — and that gap is where the risk lives.