Yubico and Okta surveyed 1,890 technology and security professionals across nine countries for their 2026 Global State of Authentication Report. Despite 87% of respondents saying they are familiar with passkeys, the most common way they sign in to work accounts remains a username and password, at 43%. Half of respondents were issued a password when they started their current role, and the report's authors argue that whatever IT hands out on day one is what people keep using.
The same professionals show signs of optimism bias: most describe their employer as secure even as password use persists. Forty-four percent said their organization suffered at least one successful AI-driven phishing attack in the past year, though the authors note this is what respondents believe happened, not a measured breach rate. In a separate test, only 36% correctly identified which of two HR emails was written by a person rather than AI, underscoring how little a careful reader can learn from text alone.
On personal accounts, respondents lean on passwords first and text-message codes second, a method that carries SIM-swapping risk. The report's authors want phishing-resistant authenticators issued to new hires during onboarding, enforced through application sign-on policies, along with device health checks before sessions open and ongoing risk checks after. They also call for a key touch or biometric scan before an AI agent carries out work on a person's behalf.