"Complex passwords may look secure on paper, but in practice, they’re reused, stored in spreadsheets, or shared over email because humans aren’t wired to remember dozens of combinations," Shane Barney, Chief Information Security Officer at Keeper Security, warned.
Survey findings from Yubico and Okta
A new joint study by Yubico and Okta found that almost half of cybersecurity professionals still depend on usernames and passwords for personal accounts: 48% rely on passwords for personal accounts and 43% for work accounts — despite respondents viewing passwords as one of the least secure authentication methods. The same survey reports that 24% of respondents have deployed password managers for work accounts and 30% for personal accounts. A majority — 52% — were issued traditional credentials when they started at an organization, and 76% said their organization depends on fragmented authentication methods that span a range of internal applications.
Why passwords persist: human behavior, executive engagement, and training
Survey participants and security leaders point to human behavior and organizational dynamics as the core reasons passwords remain common. Shane Barney framed the problem simply: attackers exploit predictable human shortcuts — reuse, spreadsheets, and email sharing. Matt Dunham, Vice President of Platform Security at Pax8, pushed the argument from the boardroom: "Improving authentication hygiene is low-hanging fruit for most businesses, and organizations that haven’t solved for this have bigger problems of getting executive leadership engaged with cyber risk." Mika Aalto, Co‑Founder and CEO at Hoxhunt, cautioned that technology alone is not enough: "Attackers are targeting human behavior. That means the defense must strengthen human behavior as well."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleJason Soroko’s passkey-first blueprint
Jason Soroko, Senior Fellow at Sectigo, laid out a concrete migration path toward passwordless and phishing-resistant authentication, arguing that non-shared secrets should be the "north star." His recommendations, presented verbatim in the survey coverage, include:
- Put every app behind SSO
- Enable passkeys with platform authenticators for the broad population
- Issue hardware security keys for admins and high value users
- Retire SMS and voice
- Limit TOTP to narrow exceptions with a clear sunset
- Harden recovery
- Add conditional access with step up only when risk warrants it
- Monitor enrollment and failure rates
- Keep a break glass path
- Migrate app by app until passwords are gone
Soroko argued that shared secrets are inherently inferior because they "can be phished, replayed or harvested" and urged migration to passkeys and digital certificates where "the private key never leaves the device and the login is bound to the site you are visiting."
Identity threats, AI agents, and least‑privilege controls
Several leaders framed the problem as broader than human login behavior, citing machine identities, botnets, and AI agents as multiplying identity risk. James Maude, Field CTO at BeyondTrust, warned that "the continued rise of identity threats and botnets is presenting a real challenge" and said organizations must take "an identity centric approach to security" focused on least privilege and a holistic posture. Randolph Barr, Chief Information Security Officer at Cequence Security, emphasized operational controls: "Organizations should always check to ensure that they have strong identity and access management for agents and skills, enforce strict least-privilege rules, set up guardrails and policy engines to manage agent actions, use sandboxing and segmentation for execution environments, monitor and log all API and agent interactions thoroughly, and be able to quickly disable or revoke skills if needed."
Chris Radkowski, GRC Expert at Pathlock, described machine identities and agentic AI as outpacing traditional identity security and said that MFA and legacy access controls were "built for a world of human users, not autonomous agents, service accounts, and AI‑driven workflows that now outnumber people across the enterprise by more than 20 times." He argued that enterprises must extend governance, least‑privilege, and adaptive controls across every identity — human or machine.
How security teams, executives, and end users are likely to act
- Security teams: Expect pressure to replace fragmented authentication with centralized SSO, passkeys, and hardware keys for high‑value accounts, while tightening least‑privilege controls on agents and APIs, as recommended by Cequence Security and Pathlock.
- Executives and procurement: As Matt Dunham noted, adoption will require executive engagement; organizations that do not prioritize authentication hygiene may face broader leadership challenges on cyber risk.
- End users and training teams: Mika Aalto advised focusing training on common social engineering tactics rather than exotic threats, and leaders in the study urged practical moves such as enforcing MFA, eliminating password reuse, and using password managers where full passwordless migration is not yet possible.
Taken together, the survey and expert responses sketch a transition: security leaders recommend a steady migration to passkeys and fewer shared secrets, while warning that identity governance must widen to include machines and AI agents. As Shane Barney noted, separate research cited in the commentary found 80% of organizations are either adopting or planning to adopt passkeys and hybrid authentication models — a benchmark that highlights the gap between plans and present practice, where 48% of cyber defenders still rely on passwords for personal accounts and many organizations begin with traditional credentials. The practical challenge now is whether organizations will convert intent into the app‑by‑app migrations, hardware key issuance, and governance changes these experts prescribe.




