Around half (48%) of cybersecurity professionals rely on usernames and passwords to authenticate their personal accounts, the report found.
Passwords remain the dominant workplace login despite distrust
Yubico and Okta surveyed 2,000 cybersecurity professionals and found that traditional usernames and passwords continue to be the single most common method for accessing work systems: 43% of respondents use passwords for their work accounts. That prevalence sits in tension with respondents’ own assessments — the report says usernames and passwords are viewed as "one of the least secure methods of authentication," highlighting a clear execution gap between what security teams prefer and what they actually use.
Passkeys and password managers underused
Device-bound, hardware-backed passkeys were rated by security professionals as the most secure authentication method, yet only 25% used passkeys to log into work accounts and 20% for personal accounts. Password managers showed higher adoption for personal use than at work: 30% of respondents use a password manager for personal accounts versus 24% for work accounts. The researchers characterize this mismatch as a symptom of operational friction and entrenched defaults rather than a lack of awareness.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFragmented authentication and legacy onboarding practices
Operational patterns inside organizations appear to reinforce weaker authentication choices. Three-quarters (76%) of respondents said their organization uses fragmented authentication methods across different internal applications, and 23% admitted they do not mandate multifactor authentication (MFA) across all enterprise applications and services. More than half (52%) of the cybersecurity professionals surveyed reported being issued traditional username-and-password credentials when they started their roles, which the report frames as establishing legacy habits.
As the report puts it: “Both inside and outside of work, login friction and authentication fatigue consistently pulls even the most knowledgeable professionals toward the path of least resistance. This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA.”
AI-driven social engineering and the rise of deepfakes
The survey also documents an increase in social engineering attacks that respondents link to the adoption of generative AI tools by cybercriminals. Nearly half (44%) of respondents reported that their organization had experienced at least one AI-driven phishing attack in the past year. Seventy percent of security professionals said phishing attacks against their organizations increased over the past year, and 55% reported being targeted by personalized attacks directly.
Deepfakes are already in the mix: 43% of organizations reported suspicious video, voice memo, or phone impersonations targeting executives or clients, and 29% of security professionals said they were directly targeted by deepfake communications. The report connects the scale and sophistication of these campaigns, at least in part, to the impact of AI-enabled tools.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The data show a mismatch between perceived security and day-to-day practice — teams that rate passkeys as most secure are still using passwords and SMS-based MFA at scale. Expect operational priorities (reducing login friction, simplifying onboarding) to drive tool selection unless defaults and integration are changed.
- Procurement and IT leaders: Fragmented authentication across internal applications (76% reporting fragmentation) and legacy credential issuance (52% given passwords at start) suggest procurement and configuration defaults materially shape employee choices; changing those defaults will be necessary to shift large-scale behavior.
- End users and executives: The increase in AI-driven phishing (44% experienced at least one) and prevalence of deepfakes (43% saw suspicious impersonations) mean personal and corporate accounts face growing risk even where security teams are knowledgeable — fatigue and fear of lockout are cited as drivers that pull users back to simpler, less secure methods.
Yubico and Okta’s findings portray a simple but stubborn dynamic: knowledge does not automatically translate into practice. Structural factors — legacy credentials issued at onboarding, fragmented authentication across apps, and defaults that favor convenience — are steering security professionals toward the same authentication choices that defenders long cautioned against. At the same time, adversaries are scaling social engineering with AI and deepfake techniques, increasing the costs of that execution gap. Whether organizations will change onboarding defaults and unify authentication across internal systems — and thereby close the gap between preferred and practiced security — is the practical question the data leave squarely on the table.
Original story: https://www.infosecurity-magazine.com/news/cybersecurity-pros-rely-passwords/




