March 16, 2018 By Shane Schick 2 min read

A new research study found 86 percent of companies said they’re either using biometric authentication or are planning to do so by 2020, despite concerns about false positives and transparency around vulnerabilities with the technology.

In the report from Spiceworks, which was based on a survey of close to 500 IT professionals across North America and Europe, 62 percent said they’re using the technology today, and 24 percent they would follow suit within the next two years. More specifically, 46 percent said they’re taking advantage of the fingerprint readers built into smartphones and using biometric authentication as a way of giving employees access to applications.

Additionally, a quarter are using it on laptops, and nearly as many (22 percent) were offering the technology on iPads or other tablets. In areas where security is at a premium, such as data centers or server rooms, 11 percent said a fingerprint or iris scan may be the only way to open the door.

Ongoing Concerns With Biometric Authentication

Despite all this traction, less than a quarter of Spiceworks survey respondents foresee biometric authentication being used over manually typed passwords within the next two to three years. In fact, 65 percent said vendors should be more forthcoming about flaws in biometric technology that could be targeted by cybercriminals or internal threats. Nearly the same number (63 percent) believe vendors aren’t being clear about how they’re collecting the data used in their biometric products and services.

One of the biggest fears — expressed by 64 percent of those surveyed — is the potential for a fingerprint or iris scanner to make a mistake and give access to the wrong person. That’s why biometric authentication may be best used as part of a multipronged approach to security, combined with passwords and other mechanisms.

The Biggest Players — So Far

Some of the most popular fingerprint scanners in use by organizations today are made by firms more associated with the consumer market rather than those that focus on safeguarding enterprise data. Apple’s Touch ID was used by 34 percent of those surveyed, whereas Lenovo and Samsung were both cited by 13 percent, followed by Dell and Microsoft at 11 percent.

Until there’s a secure enterprise option, organizations must be diligent in how they roll out — and, when necessary, roll back — biometric authentication. Consumers may appreciate the ease of access with this technology, but security must trump convenience in a business setting.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today