Widespread reliance on weak authentication puts organizations at risk
Many organizations continue to depend heavily on weak authentication methods, such as passwords and SMS codes, despite their vulnerability to phishing and credential theft. A significant portion of employees—40%—have never received cybersecurity training, and those who have often rely on outdated policies, leaving them unprepared to face current threats. Personal and work security habits frequently overlap, with employees mixing device usage and accounts, often without enabling multi-factor authentication (MFA) on personal accounts. This creates weak points that attackers exploit to infiltrate corporate systems indirectly. Although stronger and more secure options like device-bound passkeys exist, their adoption remains limited. The threat landscape is further complicated by AI, which attackers use to create convincing phishing campaigns and fake content, making it increasingly difficult for users to distinguish between legitimate and malicious communications. Younger generations appear more open to adopting newer authentication technologies, but a substantial gap remains between awareness and implementation across the workforce.
