A recent survey of nearly 1,900 technology and security professionals across nine countries reveals that while 87% are familiar with passkeys, 43% still rely on usernames and passwords for work accounts. This preference for traditional authentication methods persists despite the known vulnerabilities associated with passwords and the respondents' high level of expertise in the field.
The survey, conducted by Yubico and Okta, highlights a significant disconnect between awareness of modern authentication methods and their adoption. A primary factor identified is the initial onboarding process: 52% of respondents were issued a username and password when they started their current roles, and these habits tend to persist. For personal accounts, these professionals also primarily use passwords, followed by text-message codes, which themselves carry risks like SIM-swapping attacks.
This continued reliance on legacy login practices leaves enterprises vulnerable to contemporary attack vectors, according to industry experts. Despite this, a majority of respondents rated their own organizations as secure, a perception that researchers attribute to an "optimism bias," where individuals believe their expertise protects them from adverse outcomes.
The survey also touched on the prevalence of phishing attacks. Forty-four percent of respondents reported that their organization had experienced at least one successful AI-driven phishing attack in the past year. However, this figure represents self-reported beliefs rather than verified breach rates, with a similar number reporting no such attacks and others unsure.
To further investigate susceptibility to phishing, researchers presented respondents with two HR emails announcing an updated employee handbook—one written by a person and one generated by AI—and asked them to identify the human-authored version. Only 36% correctly identified it. Most believed the AI had written the human-authored email, or were unsure, indicating the difficulty even careful readers have in discerning AI-generated content.
This finding underscores the limitations of human vigilance in detecting sophisticated phishing attempts. Phishing-resistant login methods, such as passkeys, shift the security check from human judgment to cryptographic keys that verify a site's domain, preventing the transmission of valid credentials even if an employee is fooled.
To improve security posture, Yubico and Okta recommend issuing phishing-resistant authenticators to new hires during onboarding, ensuring strong authentication from the outset. They also advocate for enforcing these methods through application sign-on policies, implementing device health checks before sessions begin, and conducting ongoing risk assessments. This includes requiring a key touch or biometric scan before an AI agent performs tasks on an individual's behalf.






