
Global study from Yubico and Okta highlights a critical execution gap in enterprise security, showing how modern identity controls can eliminate password dependency
A new survey from Yubico, the pioneer of phishing-resistant authentication and creator of the original passkey, the YubiKey, and Okta, Inc, reveals a significant gap between security knowledge and everyday practice. While security leaders overwhelmingly recognise phishing-resistant passkeys as more secure than passwords, nearly half still rely on vulnerable login methods in their daily work.
Conducted by Talker Research, the annual 2026 Global State of Authentication report surveyed nearly 2,000 cybersecurity and IT professionals across nine countries. The report highlights that cybersecurity’s primary vulnerability is no longer a lack of education or awareness, but a structural problem driven by operational friction and outdated onboarding defaults. Organisations cannot rely solely on additional security awareness training to resolve this gap. Rather, real progress starts with what employees are handed on their first day.
Key findings include:
- 43 percent rely on passwords at work – despite many knowing passkeys are more secure. 31 percent cited hardware passkeys as the gold standard, 27 percent voted synced passkeys as most secure and 23 percent said device-bound passkeys through a mobile device are best
- 52 percent inherited passwords on day one, proving that legacy onboarding defaults dictate long-term security habits
- 44 percent suffered an AI-driven attack in the last 12 months with Singapore experiencing the highest rate globally (58 percent), contrasting sharply with Japan (30 percent) and Germany (38 percent)
- 39 percent of security pros failed to distinguish AI-generated text from human writing
- India (68 percent), Australia (60 percent), and the US (56 percent) show the highest proportion of workers who are “very familiar” with passkeys
- 91 percent would like a ‘human-in-the-loop’ approval step before autonomous AI agents execute critical actions
- Indian professionals lead global markets in willingness to delegate client/colleague communications to AI agents (41 percent “very comfortable”), compared to just 4 percent in Japan and 12 percent in France
- 50 percent of US security pros use passwords at work, leading all surveyed global markets in legacy password dependency despite having the highest technical awareness
“Enterprise cybersecurity has a critical execution gap,”
said Poupak Enbom, chief market and growth officer at Yubico.
“Security leaders know hardware-backed passkeys – specifically hardware security keys – offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn’t expertise; it’s overcoming the friction to user adoption.”
This operational disconnect begins early: over 50 percent of security professionals inherit legacy credentials on day one, establishing password dependency by default and perpetuating unsafe habits. Generative AI worsens this risk, as seasoned cybersecurity experts struggle to spot synthetic messaging, making user vigilance unreliable.
Furthermore, deploying autonomous AI agents compounds these issues, as the 91 percent who want a human approval step will need a reliable way to confirm a real person is behind it.
“Bridging this gap requires organisations to build security directly into the onboarding experience,”
said Charlotte Wylie, SVP and deputy CSO at Okta.
“When legacy login habits persist, enterprises remain vulnerable to modern attack vectors. Together with Yubico, we are providing a unified approach that ensures every employee is protected by zero-trust, phishing-resistant authentication from their first day on the job.”
To overcome these structural hurdles, Yubico and Okta are partnering to streamline how enterprise identity systems issue, manage, and enforce hardware-backed credentials. By embedding phishing resistance directly into modern access management platforms, the companies aim to help IT teams eliminate password dependencies without creating operational friction for employees.



















