By Liam Ridgill

7th May 2026

Beyond the password – how ascend and elementary are rethinking security for payroll data

Every year on the first Thursday of May, the security community marks International Password Day. This year’s theme goes further than encouraging stronger passwords. It is about moving beyond them altogether.

For those of us working with payroll data, that conversation matters more than most.

Why passwords alone are no longer enough

Passwords have served us well. But the truth is, they were never designed for a world of dozens of accounts, sophisticated phishing campaigns, and credential-stuffing attacks at scale. People reuse them. They write them down. They choose ones that are easy to remember, which usually means easy to guess.

The biggest threats facing payroll bureaus today are not technical exploits against hardened infrastructure. They are compromised credentials. An attacker who has a legitimate username and password does not need to break in. They are already in.

That is why at Ascend, our approach to security has always been about layering protections, building good habits, and using the right tools. It is also why the way employees and clients access our platforms is evolving.

Our approach to security – ISO-certified and always improving

Ascend holds ISO 27001 (Information Security), ISO 27701 (Privacy Information Management), and ISO 9001 (Quality Management) certifications. These are not badges on a website. They represent a living framework – a set of controls, risk registers, audit cycles, and continuous improvement processes that govern how we handle data.

Payroll data is among the most sensitive personal information in existence. It includes bank account details, national insurance numbers, salary information, and employment records. The organisations we serve. whether in hospitality, care, education, or the charity sector. trust us to protect it. That obligation shapes every decision we make, including how we build and secure our platforms.

What good looks like in 2026

1. Passwordless authentication

The move away from passwords is gathering real momentum. Passkeys, biometric authentication, and device-based verification are replacing the password as the primary way to prove identity. They are harder to steal, cannot be phished in the traditional sense, and remove the human error element entirely.

We are building this into Elementary. Our current authentication model uses standard username and password along with Multi-Factor Authentication (MFA), but this summer we are releasing passphrase-based login and social login. These are significant upgrades that make authentication both more secure and considerably
more convenient for users. Watch this space.

2. Password managers

Until passwordless becomes universal, a password manager is one of the most impactful things any individual or organisation can adopt. They generate long, unique, random credentials for every account and store them securely. The user only needs to remember one strong master passphrase.

For payroll teams handling multiple platforms, portals, and client logins, this is not optional hygiene. It is an essential practice.

3. Multi-factor authentication (MFA)

MFA is, right now, the single most effective defence against account compromise. Even if a password is stolen, a second factor. whether a time-based code, push notification, or hardware key. stops an attacker in their tracks.

At Ascend, MFA is not optional for our clients. Users can configure it via an authenticator app (such as Google Authenticator or Microsoft Authenticator), SMS, or email, depending on what works best for them. All three methods add the same critical layer of protection in front of your payroll data.

We made this a hard requirement deliberately. Payroll platforms hold some of the most sensitive employee data in any organisation. Leaving access dependent on a password alone was not a risk we were prepared to accept, and we do not think you should be either. We encourage every organisation we work with to enforce
MFA across their own internal systems, too.

4. Single sign-on (SSO)

SSO allows users to authenticate once and access multiple connected systems without logging in separately to each one. It reduces password fatigue, simplifies access management, and makes it far easier for organisations to enforce consistent security policies, including MFA, across their toolstack.

For payroll bureaus integrating with HR platforms, pension providers, and HMRC services, SSO is an increasingly important part of a coherent, manageable security architecture.

5. Social login

Using an existing trusted identity, such as an Apple, Microsoft or Google account, to authenticate into a platform is not just convenient. When implemented properly, it offloads credential management to major tech providers who invest heavily in account security, anomaly detection, and MFA. It is one of the new features we are bringing to Elementary this summer.

6. Security habits that actually stick

Technology alone does not make an organisation secure. People do. Some of the most important security habits require no software at all.

  • Lock your screen when you step away from your desk.
  • Do not share credentials, even temporarily.
  • Question unexpected login prompts or password reset emails.
  • Report anything that feels off. even if it turns out to be nothing.

What this means for our clients

If you are an Ascend client, you can be confident that the platform handling your payroll data is built, operated, and continuously improved against a certified security standard. Our ISO certifications are externally audited. Our controls are documented. Our risk register is live and maintained.

If you are thinking about your own organisation’s security posture, this International Password Day is a good moment to ask a few questions.

  • Are your teams using MFA on every account that supports it?
  • Are you using a password manager?
  • Do your staff know what a phishing email looks like?

If any of those answers are uncertain, we are happy to talk.

A note on what is coming

This summer, Elementary users will see meaningful changes to how they log in.

Passphrase-based authentication and social login are on their way, making access to your payroll platform both simpler and more secure. We will share more details closer to release.

In the meantime, if you have questions about how we handle security, what our ISO certifications cover, or how we can support your organisation’s own compliance requirements, get in touch with the team.

Author

Frequently asked questions related to this blog

Why aren’t passwords enough for payroll platforms anymore?

They were never built for dozens of accounts, phishing, and credential-stuffing at scale. People reuse them, write them down, or pick ones that are easy to remember (and guess). For payroll bureaux, the big risk often isn’t a technical break-in. It’s a stolen username and password. Once an attacker has those, they’re already inside. Ascend’s answer is layered protection, good habits, and better login tools, not relying on a password alone.

What security standards sit behind Ascend and Elementary?

Ascend holds ISO 27001 (information security), ISO 27701 (privacy), and ISO 9001 (quality). Those are live controls, risk registers, audit cycles, and continuous improvement, not website badges. Payroll data covers bank details, NI numbers, salaries, and employment records. That sensitivity shapes how the platforms are built and secured. Certifications are externally audited, controls are documented, and the risk register is kept current.

How do clients log in today, and what’s coming?

Today it’s username and password plus mandatory MFA. Users can set MFA via an authenticator app (Google or Microsoft Authenticator), SMS, or email. Ascend made MFA a hard requirement because payroll holds some of the most sensitive employee data around. This summer Elementary is adding passphrase-based login and social login (Apple, Microsoft, or Google). Longer term, passwordless options such as passkeys, biometrics, and device-based verification are the direction of travel. SSO also matters where payroll sits alongside HR, pensions, and HMRC systems, so people authenticate once under consistent policies.

What should teams do while passwords still exist?

Use a password manager so every account gets a long, unique, random credential and you only remember one strong master passphrase. Enforce MFA everywhere it is offered. Keep basic habits, lock screens when you step away, never share credentials even temporarily, question unexpected login or reset emails, and report anything that feels off.

What should Ascend clients take from International Password Day?

That the platform handling their payroll data is run against certified standards and kept under review. For their own organisations, sensible checks are whether MFA is on every account that supports it, whether a password manager is in use, and whether staff recognise phishing. More detail on Elementary’s login changes will follow closer to release. Get in touch if you want to talk through Ascend’s security approach or how it maps to your own compliance needs.

Love this post? why not share it...

Let’s have a chat about how we can transform your payroll

"Ready to ascend" - Badge