SecurityReports disagree2 publishers2 min readPublished
Passwords top security professionals' work logins in a Yubico and Okta survey of 2,000
Yubico and Okta found 43% of 2,000 security professionals log in to work with passwords, while 25% use the hardware passkeys they rate most secure. The people surveyed already know which logins are weak, so closing the gap is deployment work for their employers.
The Watch · Security desk
What happened
- Three in four respondents (76%) say their organisation uses fragmented authentication methods across its internal applications.
- Nearly a quarter, 23%, say multifactor authentication is not mandated on every enterprise application and service where they work.
- On their first day in the job, 52% of the security professionals surveyed were handed a traditional username and password.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure At employers without blanket MFA, any application still behind a password alone can be opened with one phished credential.
- constraint Because login methods differ across internal applications, a passkey rollout has to happen application by application, and the uncovered ones stay reachable until it finishes.
- decision Security teams deciding where to start have a case for changing the credential issued at hire, since the companies tie the password habit to onboarding defaults.
Where a second factor is in place, it is often a code that can be intercepted. According to the Yubico and Okta report, a large proportion of respondents use one-time mobile passcodes and SMS-based authentication [4]. Infosecurity Magazine notes that both methods have been shown vulnerable to interception [4].
Respondents also say the attacks on those logins are increasing. Over half, 55%, said they had been directly targeted by personalised attacks [15]. Another 44% said their organisation had faced at least one AI-driven phishing attack in the past year [8]. The report says the rise in phishing is likely at least partly due to AI, with criminals using generative tools to increase the scale and sophistication of their campaigns [16]. Impersonation shows up too. 43% of organisations reported suspicious video, voice-memo or phone impersonations aimed at executives or clients [17], and 29% of respondents said deepfake communications had targeted them directly [18].
Respondents know which methods are weak. They rank passwords among the least secure [2], yet at work password use runs 18 percentage points ahead of hardware passkeys [20]. On personal accounts the gap is 28 points: 48% use passwords and 20% use hardware passkeys [3][9][21]. Password managers also run higher at home, at 30% for personal accounts against 24% for work [10].
In the report, published on October 7 [13], Yubico and Okta describe a structural problem, driven by operational friction and outdated onboarding defaults more than by awareness [5]. Applied to the full sample, the day-one password figure is about 1,040 of the 2,000 respondents [19]. "Both inside and outside of work, login friction and authentication fatigue consistently pulls even the most knowledgeable professionals toward the path of least resistance," the report said [7].
The survey supports the first half of that reading. People who rank passwords low still use them [1][2], so the gap is not explained by people failing to understand the risk. The causal half is the companies' inference. Infosecurity Magazine's account of the findings does not link the respondents handed passwords at hire to those still logging in with them, and it does not show that fragmented tooling is what keeps them there. The figures are self-reported answers from security staff describing their own habits and their employers' policies [22].
What to watch
- Whether Yubico and Okta publish the full methodology, including how the 2,000 respondents were recruited and which sectors they work in.
- A breakdown linking respondents issued passwords at hire to their current login method would test the onboarding explanation directly.
- If the survey is repeated, whether the 23% without MFA on every application falls.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption25
- Hype gap+10
- Incentives70
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Username and password is the single most common way security professionals log in to their work accounts, used by 43%.
- [2]
Respondents view usernames and passwords as one of the least secure methods of authentication.
- [3]
48% of cybersecurity professionals rely on usernames and passwords to authenticate their personal accounts.
- [4]
A large proportion of security professionals use one-time mobile passcodes and SMS-based authentication, methods which have been shown to be vulnerable to interception by malicious actors.
- [5]
The researchers said the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.
ReportedSupportedSource: Yubico and Okta researchers2 sources— create a free account to open themView cited source - [6]
52% of the 2,000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles.
- [7]
"Both inside and outside of work, login friction and authentication fatigue consistently pulls even the most knowledgeable professionals toward the path of least resistance."
ReportedSupportedSource: Yubico and Okta report2 sources— create a free account to open themView cited source - [8]
44% of respondents reported their organization had experienced at least one AI-driven phishing attack in the past year.
- [9]
Device-bound, hardware-backed passkeys were seen as the most secure authentication method; 25% used them to log into work accounts and 20% for personal accounts.
- [10]
Password managers were used by 24% of respondents for work accounts and 30% for personal accounts.
- [11]
76% of respondents said their organization uses fragmented authentication methods across different internal applications.
- [12]
23% of respondents said their organization does not mandate multifactor authentication across all enterprise applications and services.
- [14]
70% of security professionals experienced an increase in phishing attacks on their organization over the past year.
- [15]
55% of respondents were targeted directly by personalized attacks.
- [16]
The report noted the phishing increase is likely at least partly due to AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.
- [17]
43% of organizations reported suspicious video, voice memo or phone impersonations targeting executives or clients.
- [18]
29% of security professionals said they were directly targeted by deepfake communications.
- [19]
About 1,040 of the 2,000 respondents were issued a username and password when starting their roles.
- [20]
Password use for work logins exceeds hardware-backed passkey use by 18 percentage points.
- [21]
For personal accounts, password use exceeds hardware-backed passkey use by 28 percentage points.
- [22]
A study by Yubico and Okta surveyed 2,000 cybersecurity professionals.
Sources
2 independent publishers whose own reporting we read for this story.
- helpnetsecurity.comThe people who know passkeys best are still typing passwords
1 article · October 7, 2026
- infosecurity-magazine.comHalf of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.