HealthEquity’s Ajit Gaddam Discusses the Shift to Passwordless Security in Cyber Defense
In an era marked by escalating cybersecurity threats, passwords linger as a significant vulnerability within account security frameworks. Criminals wield the capability to purchase stolen credentials and exploit weak recovery workflows, leading to a rampant problem of account takeovers across numerous industries. This troubling trend is underscored by Ajit Gaddam, who serves as the head of fraud, financial crimes, and product security at HealthEquity. He emphasizes that the standard approach of relying on usernames and passwords has become insufficient, primarily due to their forgettable nature, susceptibility to theft, and frequent reuse by users.
In a video interview conducted by ISMG at the prominent Black Hat USA 2026 conference, Gaddam elucidated the limitations of traditional password systems and highlighted a forward-thinking solution: passkeys. The innovative technology of passkeys serves as a replacement for conventional username-password combinations and security questions. Instead, this method employs device-based cryptography coupled with biometric verification to enhance security. The mechanism involves retaining a private key on the user’s device, with access unlocked through biometric methods such as facial recognition.
Gaddam is adamant about the benefits this shift presents. He believes it has the potential to streamline login processes, fortify identity assurance, and diminish dependence on recovery workflows—often prime targets for cybercriminals. "The best password in the world is you. You are your own identity," Gaddam stated, encapsulating the essence of this new identity management paradigm.
The transition from traditional passwords to passkeys is not just a technological upgrade, but rather a multifaceted journey requiring organizational commitment and user education. Gaddam pointed out that employees, particularly those stationed in call centers, often represent a weak link in the cybersecurity chain, primarily due to susceptibility to social engineering schemes. He urged businesses to understand that robust cybersecurity measures must also involve training support teams to deal with potential threats effectively.
Moreover, Gaddam discussed the importance of user experience in this process. For many organizations, the adoption of passkeys hinges on providing a clear, user-friendly interface that can seamlessly integrate into existing workflows. He advocates for a comprehensive educational initiative that ensures users are not only aware of the switch from passwords to passkeys, but also trained adequately to navigate this new identity verification landscape.
Gaddam’s insights are rooted in a rich professional background that extends over two decades in the cybersecurity realm. As an expert with extensive experience in enterprise cybersecurity initiatives, he has led initiatives focused on fraud prevention, AI-driven security technologies, and security engineering. His commitment to innovative solutions is evidenced by his impressive portfolio, which includes over 120 patents spanning cybersecurity, fraud detection, and artificial intelligence.
HealthEquity’s strategic transition from traditional passwords to the more secure passkey approach exemplifies a broader trend within the cybersecurity landscape. Organizations are increasingly recognizing the inadequacy of outdated password protocols in safeguarding sensitive information. The recognition that passwords are inherently flawed is fostering urgent dialogues across various sectors about the need for advanced authentication methods.
This transition embodies a significant step toward enhancing overall cyber defense mechanisms. As organizations move to embrace passkeys, they not only fortify their security practices but also pave the way for more robust digital identities that are harder for malicious actors to compromise. Gaddam’s vision for the future of identity security revolves around leveraging cutting-edge technology and an informed user base to construct a more secure digital environment.
In this climate of cyber threats, the need for innovative solutions like passkeys is urgent. By advocating for this transition, Ajit Gaddam is not just addressing a current issue but is also offering a glimpse into the future of secure digital interactions. The emphasis on education, user experience, and effective training marks a pivotal approach vital for fostering not only corporate security but also user confidence in a world less reliant on traditional, flawed password systems.

