InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Security pros rate their firms secure even where MFA stays optional, Yubico and Okta find
Yubico and Okta's survey of 1,890 tech and security professionals found 23% work where multifactor login is not required on every application. With 88% still rating their company secure, at least one respondent in nine gave both answers.
The Investor · Invest desk
What happened
- Shown a human-written and an AI-written version of the same HR email, only 36% of respondents picked the human one, and 54% thought AI had written it.
- Yubico, which sells hardware security keys, and Okta, which sells identity management, announced a partnership alongside the survey.
- Talker Research ran the survey from July 2 to 16 across nine countries, among tech and security staff at companies with at least 500 employees.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Executives who rely on their security team's own rating of the firm get an optimistic read, since many of the people calling it secure know some applications sit outside MFA.
- decision Trained security staff did worse than guessing at spotting a human-written email, which gives budget holders grounds to fund enforced MFA on every application ahead of more awareness training.
- constraint Passkeys only protect account access. A budget moved wholly into login controls leaves gift-card and other payment requests to unaided human judgement.
If every one of the 1,890 respondents answered both questions, the 88% who called their enterprise secure and the 23% whose employers leave MFA off some applications sum to 111% [1][4][3]. At least 11% of the sample, roughly 208 people, must therefore have given both answers [20]. Against the roughly 435 people in the optional-MFA group, that floor is 48% of them [19][21]. Run the same test on the 44% reporting a successful AI-driven phishing attack in the past year [11] and at least 32% of respondents, about 605 people, called their firm secure after a successful attack [22]. Those are minimums. Fortune's account does not include the cross-tabulations, so it cannot show whether the 44% cluster at the firms without full MFA.
"The gap was not the awareness; it was the adoption," Poupak Modirassari Enbom, Yubico's chief market and growth officer, told Fortune [5]. That diagnosis points to what the survey's two sponsors sell. Both companies get paid when a security budget moves toward authentication [7].
On one point, their own data backs the diagnosis. Asked to pick the human-written version of an HR email out of two, a guesser would be right about half the time, and respondents managed 36% [13][23]. Employers had trained 82% of these people [2], yet 23% still work where MFA is optional [3]. Lorrie Faith Cranor, director of Carnegie Mellon's CyLab, co-founded Wombat Security Technologies, an awareness-training company Proofpoint later acquired [8]. "Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding," she told Fortune [12].
Cranor's second point is about volume. Some 55% of respondents said they had been personally targeted with phishing [10]. "But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard," Cranor said [9].
The same reporting also shows the limits of moving money from training to enforcement. A passkey will not authenticate a login on an imitation site, but it does nothing when an employee buys gift cards at a scammer's request [15]. One Reddit poster described buying $800 of Target gift cards on their second day at a new job after an email impersonating the boss [16]. The type of MFA matters too. Cranor said MFA gives substantial protection, but text-message codes can be vulnerable [17], so closing the 23% gap with SMS codes buys less protection than closing it with keys. The sample is also narrow: security staff at firms of 500 or more people, and Fortune notes the results reflect that population and not workers generally [6].
The report recommends building stronger authentication into onboarding [18]. Some 52% of respondents said they were issued a username and password when they started, though Fortune notes that does not establish whether MFA came with it [14]. I think the evidence points to enforcement at the first login, with training kept for the payment requests a login control cannot see. That view is wrong if successful attacks turn up at the same rate at firms that already require MFA everywhere, or if most of the 44% were payment requests a passkey would not have stopped [11][15].
What to watch
- Whether Yubico or Okta publishes the cross-tabulation showing if successful AI-driven phishing attacks cluster at firms without MFA on every application.
- Which forms of MFA employers use to close the coverage gap, given Cranor's warning that text-message codes can be vulnerable.
- What the Yubico-Okta partnership sells into onboarding, the stage the report recommends hardening first.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption55
- Hype gap+15
- Incentives75
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A survey from Yubico and Okta polled 1,890 technology and security professionals.
- [2]
82% of respondents had received employer security training.
- [3]
23% of respondents said their organizations did not require multifactor authentication across all applications and services.
- [4]
88% of respondents described their enterprise as secure.
- [5]
"The gap was not the awareness; it was the adoption," Poupak Modirassari Enbom, Yubico's chief market and growth officer, told Fortune.
- [6]
Talker Research conducted the survey July 2-16 across nine countries, polling professionals in technology and security roles at companies with at least 500 employees; results released Oct. 7 reflect that population rather than workers generally.
- [7]
Yubico sells hardware security keys and Okta provides identity management services; the two announced a partnership alongside the survey.
- [8]
Lorrie Faith Cranor is director of Carnegie Mellon University's CyLab and a co-founder of Wombat Security Technologies, a security awareness training company later acquired by Proofpoint.
- [9]
"But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard," Cranor told Fortune.
- [10]
55% of respondents reported being directly targeted by personalized phishing attacks.
- [11]
44% of respondents said their organization had experienced at least one successful AI-driven phishing attack in the previous year.
- [12]
"Sure, there are still some simple phishing messages that you might spot by looking at typos, but a lot of phishing messages are written by AI agents with perfect grammar and spelling and they mimic corporate style and branding," Cranor said.
- [13]
Respondents were shown two versions of an HR email asking staff to sign off on an updated handbook, one written by a person and one by AI; only 36% correctly identified the human-written message, while 54% thought AI wrote it.
- [14]
52% of respondents said they received username-and-password credentials when starting their roles, though that does not establish whether they also used multifactor authentication.
- [15]
Passkeys use cryptographic credentials tied to a legitimate site, so they won't authenticate a login on an imitation website, but that protection covers account access and won't stop someone from buying gift cards at a scammer's request.
- [16]
In a November 2025 Reddit post, one person described buying $800 in Target gift cards on their second day at a new job after receiving an email impersonating their boss.
- [17]
Cranor said MFA provides substantial protection but its forms differ, and text-message codes can be vulnerable.
- [18]
The report recommends building stronger authentication into onboarding.
- [19]
About 435 respondents work at organisations that do not require MFA on every application.
- [20]
If all respondents answered both questions, at least 11% of the sample, about 208 people or roughly one in nine, both called their enterprise secure and work where MFA is not required on every application.
- [21]
At least 48% of the respondents without MFA on every application called their enterprise secure.
- [22]
If all respondents answered both questions, at least 32% of the sample, about 605 people, called their enterprise secure while reporting a successful AI-driven phishing attack in the previous year.
- [23]
The 36% correct-identification rate on a two-option choice is below the roughly 50% that random guessing would produce.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.