Security News

Even Cybersecurity Professionals Struggle to Move Beyond Passwords, Study Finds

Infosecurity Magazine · 7 Oct 2026
Key Takeaway Make MFA mandatory across every business application and move towards stronger options such as passkeys, rather than relying on passwords or SMS codes alone.

A study by Yubico and Okta has found a gap between what security professionals believe and what they do. Of 2000 cybersecurity professionals surveyed, 48% use usernames and passwords for personal accounts, and 43% use them to log into work accounts, making it the most common work login method. Yet respondents viewed passwords as one of the least secure options. Hardware-backed passkeys were rated the most secure, but only 25% used them for work accounts and 20% for personal accounts. Password managers were used by 24% for work and 30% for personal accounts.

The report points to structural causes rather than a lack of awareness. Some 52% of respondents were issued traditional username and password credentials when they started their roles, which set legacy habits. Three-quarters said their organisation uses fragmented authentication methods across internal applications, and 23% said multifactor authentication (MFA) is not required across all enterprise applications and services. Many also use one-time mobile passcodes and SMS-based authentication, which can be intercepted by malicious actors. The researchers say login friction and fatigue pull even knowledgeable people toward the easiest option.

The report also highlighted rising social engineering. Nearly half (44%) said their organisation had faced at least one AI-driven phishing attack in the past year, 70% saw phishing increase, and 55% were personally targeted by tailored attacks.

passwords MFA passkeys phishing authentication

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.