As World Password Day is being observed today, the conversation around digital security is undergoing a major transformation. What was once centred on creating stronger passwords has now evolved into a far broader debate around identity protection in an AI-driven era. Cybersecurity experts warn that traditional passwords alone are no longer sufficient against increasingly sophisticated threats powered by artificial intelligence, automated credential theft, infostealer malware, and machine-driven cyberattacks.
The rapid expansion of digital ecosystems, cloud platforms, AI agents, APIs, and autonomous enterprise systems has significantly widened the identity attack surface. In this environment, a single compromised credential can trigger cascading breaches across financial systems, enterprise networks, telecom infrastructure, and critical digital services. India, with nearly a billion internet users and one of the highest levels of mobile data consumption globally, represents both a massive digital opportunity and a growing cybersecurity challenge.
Industry leaders increasingly believe that the future of cybersecurity lies not merely in stronger passwords, but in continuous, intelligent, and context-aware identity security. Technologies such as passkeys, biometrics, passwordless authentication, multi-factor authentication, and Zero Trust frameworks are rapidly emerging as the new standards for securing both human and machine identities.
This World Password Day, cybersecurity executives and technology leaders highlight why organisations must urgently rethink authentication strategies, strengthen identity governance, and prepare for a future where AI reshapes both cyber defence and cyber risk at unprecedented scale.
Will Passwords Defend Us against AI and Infostealer Attacks?
Sundar Balasubramanian, Managing Director - India and South Asia, Check Point Software Technologies
“World Password Day falls on every first Thursday of May, with a reminder that especially in this new AI-era, a 16-character password is ineffective if infostealer malware extracts it from a browser cache, or if an employee pastes it into an unmanaged AI chatbot.
India, home to nearly 1 billion internet users and among the highest per capita data consumption globally estimated at 36GB per user per month highlights the scale of risk. A single compromised credential is no longer isolated; it can cascade across financial systems, telecom networks, digital public infrastructure, and enterprise platforms.
The underground marketplace has undergone a structural shift. Traditional dark web forums now function primarily as reputation layers, while transactions have migrated to private Telegram channels and automated bots, significantly accelerating the monetization cycle of stolen data. In India, this is already operating at scale. Government data shows 29.44 lakh cybersecurity incidents were handled in 2025, underscoring that credential compromise is no longer episodic—it is continuous.
The effectiveness of this ecosystem is amplified by user behavior. Despite sustained awareness efforts, 94% of passwords are reused across accounts, and only 3% meet recommended complexity standards. A single breach can therefore unlock multiple services through automated credential stuffing.”
World Password Day applies to both consumers and professionals
Jeramy Kopacko, Associate Field CISO Americas, Sophos
“Despite heavy pushes from Apple, Google, Microsoft, CISA, and us (Sophos) encouraging stronger authentication methods, compromised credentials remain our most observed root cause in identity-related attacks last year. Attackers will take advantage of password breaches from popular sites and apps we use as consumers. This is low hanging fruit to obtain with a strong history of success in cyber-attacks. This allows for spray and pray attempts or building a dictionary of your password history.
Each year, these password breaches are analyzed to understand user habits and password practices. They reveal two main problems -
· Passwords are weak, lacking complexity or character length
· Passwords are reused across several sites and services
World Password Day applies to consumers and professionals - as a consumer, use the day to set up or help someone else setup a password manager. This will automate the process of creating unique passphrases, storing them, and managing the login experience. Password managers can ensure only the proper site is receiving credentials and scan emerging password breaches to see if you’re impacted.”
The shift to passwordless authentication should be a present necessity
Shakeel Khan, Regional Vice President and Country Head, Okta India
"Passwords have long been the weakest link in security: they are easy to forget, reuse, and exploit. As we mark World Password Day, the shift to passwordless authentication is no longer a future vision but a present necessity. The focus now should be on adopting modern authentication methods such as biometrics, device-based verification, and phishing-resistant standards like passkeys, which offer both stronger security and a seamless user experience. This imperative extends beyond human identities, as AI agents now operate autonomously across enterprise systems, and they cannot rely on passwords either.
A credential exposed through an agent carries the same risk as one stolen from a human, often with far less visibility. At Okta, we see going passwordless as a critical step toward building a safer, more intuitive digital world, one that must extend to every identity in it.”
The smallest step in reviewing password credentials can mitigate substantial risks
Sanjay Khera, Head - Marketing, Eventus Security
"World Password Day serves as a timely reminder of the critical role strong and unique passwords play in fortifying our defenses against cyber threats. A single weak password can serve as a gateway to massive data breach. At Eventus Security, we advocate for holistic security strategies that go beyond traditional password protection, helping people and businesses stay safe from evolving threats online. Let’s start with a small proactive step today by reviewing and reinforcing our password credentials and following best practices. Even the smallest step can mitigate substantial risks."
Enterprises must secure both Human and Machine identities
Balaji Rao, Area Vice President, India & SAARC, Commvault
“Password Day must now be seen as a wake-up call for securing every digital identity, human and non-human. We are witnessing an unprecedented expansion of digital identities, where AI agents are no longer supporting actors but autonomous participants in business processes, each requiring authentication, authorization, and oversight at scale traditional systems were never designed to handle.
In India’s rapidly digitizing economy, this shift is becoming a boardroom priority as enterprises scale AI across functions, customer touchpoints, and critical operations. Every AI agent accesses user-specific data, workflows, multiple applications, and therefore needs a unique identity and clearly defined access rights. Strong encryption, multi-factor authentication, multi-person approval, and centralized identity management remain mandatory.
Alignment with evolving frameworks such as the DPDP Act further reinforces accountability. Enterprises that enforce strict governance over AI identities will be better positioned to secure operations at scale.”
AI Workloads compelling Enterprises to rethink Identity Security
Praveen Kulkarni, Director - Security, Risk and Governance, OpenText India
“The password debate in 2026 is no longer about choosing between keeping it or removing it. The real question is how identity itself needs to evolve. Modern credentials, whether passwords, tokens, or biometrics, sit inside a much larger identity fabric that now supports both human users and AI-driven workloads. These workloads move through enterprise systems at a pace that human-designed frameworks were never meant to absorb. A phishing attack that once affected only one employee can now open the door to a credential that an AI agent can misuse at extraordinary speed. What was once a contained incident can now ripple across thousands of transactions within minutes because the scale of activity has changed.
Passwordless tools will help, but they solve only a part of the challenge. Real protection comes from understanding how every identity behaves over time and checking that behaviour continuously. It requires controls that notice the moment a trusted user or a machine begins to act in a way that does not fit its usual pattern. The organisations that are moving ahead are not debating the value of passwordless adoption. They are concentrating on how their identity architecture reacts when any credential, human or machine, suddenly behaves in a way that does not belong in their environment.”
Identity: The new attack surface in AI era
Rizwan Patel, Global Head - Cloud, Infosec and Emerging Technologies, Altimetrik
“Identity has become the primary attack surface, with passwords emerging as one of its most vulnerable links. As enterprises scale their digital business across cloud, APIs, and interconnected ecosystems, the idea of a fixed security perimeter has steadily faded, bringing authentication to the forefront of risk management and trust.
What makes this moment distinct is that the identity surface has expanded well beyond human users and now increasingly incorporates service accounts, API tokens, CI/CD pipelines and autonomous AI agents accounting for the majority of authentication events in enterprise environments. Yet most NHI operate without equivalent governance carrying standing privileges, rotating credentials infrequently, and are rarely audited with the same rigor applied to humans. As agentic AI takes on more consequential roles, this gap becomes one of the most underappreciated risks in enterprise security.
Addressing this requires a shift from static credentials to continuous, context-aware security. Password less authentication, multi-factor authentication, zero trust frameworks, and identity as code wherein credentials are ephemeral, policies are version-controlled, and access is governed as part of the engineering lifecycle must work alongside intelligent threat detection and secure engineering practices. At Altimetrik, these principles are embedded through DevSecOps and advanced security solutions. World Password Day is a timely reminder that strengthening identity and authentication, for every identity human or machine, is essential to building resilient and trusted digital businesses.”
Passkeys and Passwordless Authentication should be the new Security Standard
Andrew Spangler, Senior Director, Security & Compliance, Harness
"Security is no longer limited to better password habits, but requires us to fundamentally rethink how we approach identity in a world of AI-driven threats. While individuals can be careful, traditional passwords are steadily losing relevance, as the threat landscape has far outpaced what static credentials were ever designed to handle.
The response to this shift cannot be incremental. Passkeys and passwordless authentication need to become the default to eliminate shared secrets and reduce phishing risk at scale. In parallel, the fundamentals must be enforced—long, unique passphrases, mandatory multi-factor authentication, and password managers to eliminate reuse are table stakes for any modern security posture.
More importantly, this calls for a shift in mindset. Security needs to become continuous, embedded, and system-driven. Every access point, identity, and interaction needs to be part of an active defence model that adapts in real time.
The goal isn’t to make security more complex for users, but to make it more resilient by design. This is the moment to move from passive protection to active defence—because standing still is the biggest threat in an AI-driven landscape."
The growing issue is to secure the identity ecosystem that protects modern businesses
Parag Khurana, Country Manager, Barracuda Networks India
“World Password Day is a reminder for better individual password hygiene, but for Indian organisations it highlights only a fraction of the wider identity challenge. Today, attackers aren’t breaking in, they’re logging in. Credentials have effectively become a form of currency in the cybercrime economy, with infostealers and dark‑web marketplaces making it easier than ever for attackers to obtain valid logins. Stolen credentials, dormant accounts and unsecured third‑party access have become some of the most effective entry points for cybercriminals. Strengthening identity consistently across the organisation has to be a priority. That means moving beyond traditional passwords and adopting phishing‑resistant MFA, ideally through authentication apps rather than SMS. It also means continuously reviewing who has access, how long they’ve had it, and whether those accounts are still active or necessary. And because even strong authentication can be bypassed, organisations also need continuous monitoring through XDR to flag unusual logins, impossible travel activity and other behavioural anomalies before they escalate. World Password Day may spark the annual conversation, but the growing issue is securing the entire identity ecosystem that protects modern businesses.”
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
