Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Security pros rate their firms secure even where MFA stays optional, Yubico and Okta find

Yubico and Okta's survey of 1,890 tech and security professionals found 23% work where multifactor login is not required on every application. With 88% still rating their company secure, at least one respondent in nine gave both answers.

The Investor · Invest desk

How we use AISend a correction

What happened

  • Shown a human-written and an AI-written version of the same HR email, only 36% of respondents picked the human one, and 54% thought AI had written it.
  • Yubico, which sells hardware security keys, and Okta, which sells identity management, announced a partnership alongside the survey.
  • Talker Research ran the survey from July 2 to 16 across nine countries, among tech and security staff at companies with at least 500 employees.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure Executives who rely on their security team's own rating of the firm get an optimistic read, since many of the people calling it secure know some applications sit outside MFA.
  • decision Trained security staff did worse than guessing at spotting a human-written email, which gives budget holders grounds to fund enforced MFA on every application ahead of more awareness training.
  • constraint Passkeys only protect account access. A budget moved wholly into login controls leaves gift-card and other payment requests to unaided human judgement.

If every one of the 1,890 respondents answered both questions, the 88% who called their enterprise secure and the 23% whose employers leave MFA off some applications sum to 111% [1][4][3]. At least 11% of the sample, roughly 208 people, must therefore have given both answers [20]. Against the roughly 435 people in the optional-MFA group, that floor is 48% of them [19][21]. Run the same test on the 44% reporting a successful AI-driven phishing attack in the past year [11] and at least 32% of respondents, about 605 people, called their firm secure after a successful attack [22]. Those are minimums. Fortune's account does not include the cross-tabulations, so it cannot show whether the 44% cluster at the firms without full MFA.

"The gap was not the awareness; it was the adoption," Poupak Modirassari Enbom, Yubico's chief market and growth officer, told Fortune [5]. That diagnosis points to what the survey's two sponsors sell. Both companies get paid when a security budget moves toward authentication [7].

On one point, their own data backs the diagnosis. Asked to pick the human-written version of an HR email out of two, a guesser would be right about half the time, and respondents managed 36% [13][23]. Employers had trained 82% of these people [2], yet 23% still work where MFA is optional [3]. Lorrie Faith Cranor, director of Carnegie Mellon's CyLab, co-founded Wombat Security Technologies, an awareness-training company Proofpoint later acquired [8]. "Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding," she told Fortune [12].

Cranor's second point is about volume. Some 55% of respondents said they had been personally targeted with phishing [10]. "But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard," Cranor said [9].

The same reporting also shows the limits of moving money from training to enforcement. A passkey will not authenticate a login on an imitation site, but it does nothing when an employee buys gift cards at a scammer's request [15]. One Reddit poster described buying $800 of Target gift cards on their second day at a new job after an email impersonating the boss [16]. The type of MFA matters too. Cranor said MFA gives substantial protection, but text-message codes can be vulnerable [17], so closing the 23% gap with SMS codes buys less protection than closing it with keys. The sample is also narrow: security staff at firms of 500 or more people, and Fortune notes the results reflect that population and not workers generally [6].

The report recommends building stronger authentication into onboarding [18]. Some 52% of respondents said they were issued a username and password when they started, though Fortune notes that does not establish whether MFA came with it [14]. I think the evidence points to enforcement at the first login, with training kept for the payment requests a login control cannot see. That view is wrong if successful attacks turn up at the same rate at firms that already require MFA everywhere, or if most of the 44% were payment requests a passkey would not have stopped [11][15].

What to watch

  • Whether Yubico or Okta publishes the cross-tabulation showing if successful AI-driven phishing attacks cluster at firms without MFA on every application.
  • Which forms of MFA employers use to close the coverage gap, given Cranor's warning that text-message codes can be vulnerable.
  • What the Yubico-Okta partnership sells into onboarding, the stage the report recommends hardening first.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption55
Hype gap+15
Incentives75
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A survey from Yubico and Okta polled 1,890 technology and security professionals.

    ReportedSupportedSource: Fortune, reporting the Yubico/Okta surveyView cited source
  2. [2]

    82% of respondents had received employer security training.

    ReportedSupportedSource: Yubico/Okta survey via FortuneView cited source
  3. [3]

    23% of respondents said their organizations did not require multifactor authentication across all applications and services.

    ReportedSupportedSource: Yubico/Okta survey via FortuneView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. fortune.com

    1 article · October 9, 2026

    ‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories