New Report Finds 43% of Security Pros Still Use Passwords

The 2026 Global State of Authentication report finds 43% of security pros still use passwords at work despite passkey awareness and rising AI phishing threats.

Written By
Ken Underhill
Ken Underhill
Oct 8, 2026
3 minute read
Cybersecurity illustration showing a smartphone, laptop, and tablet connected to a glowing shield, with padlock and password symbols.

A new authentication report finds 43% of security professionals still use passwords at work despite growing passkey awareness and AI-driven phishing threats. Image: ChatGPT

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cybersecurity professionals understand the risks of password-based authentication, but that knowledge isn't necessarily changing how they access workplace systems.

The 2026 Global State of Authentication report found that 43% of security professionals still rely on usernames and passwords for work, even though 87% are familiar with passkeys.

These findings point to a problem that security awareness training alone cannot solve. Outdated authentication policies keep password-based access in place, while legacy onboarding practices establish habits that can persist throughout an employee's tenure.

Passkey awareness outpaces workplace adoption 

The report surveyed 1,890 technology and security professionals across nine countries, including the United States.

When asked which authentication methods provide the strongest protection, 31% selected hardware-backed passkeys. Mobile authenticator apps followed at 29%, while 27% selected synced passkeys.

However, only 25% reported using hardware-backed passkeys for daily workplace authentication.

Employee onboarding appears to contribute to this disconnect. More than half of respondents (52%) received traditional username and password credentials when starting their jobs, making passwords their default authentication method from day one.

Inconsistent authentication requirements create another challenge. According to the report, 76% of organizations use different authentication methods across internal applications, while 23% do not require multifactor authentication (MFA) across all enterprise applications and services.

Despite these gaps, 88% of respondents considered their organizations secure.

Advertisement

AI phishing makes attacks harder to detect 

The report also highlights how artificial intelligence (AI) is making traditional phishing defenses less reliable.

Seventy percent of respondents reported increased phishing activity targeting their organizations over the previous year. Additionally, 44% said their organizations experienced at least one successful AI-driven attack during that period.

Attackers are also using impersonation techniques to target organizations. Approximately 43% of respondents reported suspicious video or voice-based impersonation attempts targeting executives or clients.

To examine whether security professionals could recognize AI-generated communications, researchers presented respondents with human-written and AI-generated messages.

Only 36% correctly identified the human-written question, while 39% failed to recognize the AI-generated question.

AI agent security demands human oversight 

As organizations adopt autonomous AI agents, verifying nonhuman identities is becoming a greater security priority. The survey found that 91% consider verifying the identity and authenticity of AI agents essential, with 57% describing it as critical.

Separately, 91% of respondents said a human approval step should remain in place before AI agents execute actions on their behalf.

That oversight becomes particularly important when agents can perform sensitive operations, such as escalating account privileges or initiating financial transactions.

U.S. leads in password dependency 

The United States showed the largest gap between authentication awareness and workplace password usage among the surveyed markets.

Although 40% of U.S. respondents identified hardware-backed passkeys as the most secure authentication method, 50% still used usernames and passwords at work. 

Password dependency also extended to personal accounts, with 56% of U.S. respondents relying on usernames and passwords outside work.

Advertisement

What security teams should do next

Organizations should begin by reviewing how credentials are issued during onboarding. 

Providing phishing-resistant authenticators from an employee's first login can help prevent password-based workflows from becoming established.

Security teams should also identify applications that still depend on passwords and require phishing-resistant authentication wherever supported.

Organizations should also verify nonhuman identities (NHIs) and maintain human approval for sensitive actions.

For organizations looking to move beyond passwords, explore our guide to the best passkey solutions for stronger authentication.


Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.