Security Survey Finds Nearly Half Still Rely on Passwords

0
A new survey from Yubico and Okta reveals a major disconnect between security awareness and daily behavior. Although most security leaders recognize that phishing-resistant passkeys offer stronger protection than passwords, nearly half continue to use vulnerable login methods in their everyday work.

Conducted by Talker Research, the annual 2026 Global State of Authentication* report surveyed nearly 2,000 cybersecurity and IT professionals across nine countries. The report highlights that cybersecurity’s primary vulnerability is no longer a lack of education or awareness, but a structural problem driven by operational friction and outdated onboarding defaults. Organizations cannot rely solely on additional security awareness training to resolve this gap. Rather, real progress starts with what employees are handed on their first day.

Key Findings Include:

  • 43% rely on passwords at work – despite many knowing passkeys are more secure. 31% cited hardware passkeys as the gold standard, 27% voted synced passkeys as most secure and 23% said device-bound passkeys through a mobile device are best.
  • 52% inherited passwords on day one, proving that legacy onboarding defaults dictate long-term security habits.
  • 44% suffered an AI-driven attackin the last 12 months with Singapore experiencing the highest rate globally (58%), contrasting sharply with Japan (30%) and Germany (38%).
  • 39% of security pros failed to distinguish AI-generated text from human writing.
  • India (68%), Australia (60%), and the U.S. (56%) show the highest proportion of workers who are “very familiar” with passkeys.
  • 91% would like a “human-in-the-loop” approval step before autonomous AI agents execute critical actions.
  • Indian professionals lead global markets in willingness to delegate client/colleague communications to AI agents (41% “very comfortable”), compared to just 4% in Japan and 12% in France.
  • 50% of U.S. security pros use passwords at work, leading all surveyed global markets in legacy password dependency despite having the highest technical awareness.

 

“Enterprise cybersecurity has a critical execution gap,” said Poupak Enbom, Chief Market and Growth Officer at Yubico. “Security leaders know hardware-backed passkeys – specifically hardware security keys – offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn’t expertise; it’s overcoming the friction to user adoption.”

This operational disconnect begins early: over 50% of security professionals inherit legacy credentials on day one, establishing password dependency by default and perpetuating unsafe habits. Generative AI worsens this risk, as seasoned cybersecurity experts struggle to spot synthetic messaging, making user vigilance unreliable.

Furthermore, deploying autonomous AI agents compounds these issues, as the 91% who want a human approval step will need a reliable way to confirm a real person is behind it.

“Bridging this gap requires organizations to build security directly into the onboarding experience,” said Charlotte Wylie, SVP Deputy CSO at Okta. “When legacy login habits persist, enterprises remain vulnerable to modern attack vectors. Together with Yubico, we are providing a unified approach that ensures every employee is protected by zero-trust, phishing-resistant authentication from their first day on the job.”

To overcome these structural hurdles, Yubico and Okta are partnering to streamline how enterprise identity systems issue, manage, and enforce hardware-backed credentials. By embedding phishing resistance directly into modern access management platforms, the companies aim to help IT teams eliminate password dependencies without creating operational friction for employees.

Learn more about how organizations can strengthen identity security and reduce their reliance on passwords here.

Related News:

Commvault Extends Protection for Identity Systems with Okta Support

Zimperium MTD Teams Up with Okta to Enhance Identity Threat Protection

Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.