The NCSC to begin recommending use of passkeys

Contact us

The National Cyber Security Centre (NCSC) announced at CYBERUK 2026 in Glasgow that it will begin recommending the use of passkeys wherever a service supports them, and two-step verification (2SV) where it does not.


A passkey is a way to sign in that does not use a password. Instead, your account is linked to a device you own, such as a phone or computer. When you log in, the service asks your device to confirm it is you, and you approve this by unlocking the device with a fingerprint, face scan or PIN.


Based on analysis carried out by the NCSC, it has been concluded that passkeys provide stronger protection for users than traditional 2SV, which can be vulnerable to phishing. According to the NCSC, phishing is one of the most persistent causes of cyber compromise.


The NCSC point out that, as with any security control, passkeys need to be implemented and used sensibly to be most effective. Users will still depend on the security of their devices and credential managers.


See: https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in

July 27, 2026
Andy Burnham’s new government, a balancing act

Andy Burnham’s first days as Prime Minister have been marked by a flurry of announcements designed to show that his government intends to move quickly. Presenting himself as a leader focused on easing pressure on households and rebuilding trust in politics, Burnham has begun reshaping government while signalling the priorities that will define his administration.

Read article
July 23, 2026
Changes planned for modernising company taxation on capital distributions

HMRC have opened a consultation, ‘Modernising the taxation of distributions and repayments of capital from companies’. They are seeking views on proposals to modernise the tax framework dealing with distributions made by companies to shareholders who are individuals or trusts.

Read article