Cybersecurity professionals understand the risks of password-based authentication, but that knowledge isn't necessarily changing how they access workplace systems.
The 2026 Global State of Authentication report found that 43% of security professionals still rely on usernames and passwords for work, even though 87% are familiar with passkeys.
These findings point to a problem that security awareness training alone cannot solve. Outdated authentication policies keep password-based access in place, while legacy onboarding practices establish habits that can persist throughout an employee's tenure.
Passkey awareness outpaces workplace adoption
The report surveyed 1,890 technology and security professionals across nine countries, including the United States.
When asked which authentication methods provide the strongest protection, 31% selected hardware-backed passkeys. Mobile authenticator apps followed at 29%, while 27% selected synced passkeys.
However, only 25% reported using hardware-backed passkeys for daily workplace authentication.
Employee onboarding appears to contribute to this disconnect. More than half of respondents (52%) received traditional username and password credentials when starting their jobs, making passwords their default authentication method from day one.
Inconsistent authentication requirements create another challenge. According to the report, 76% of organizations use different authentication methods across internal applications, while 23% do not require multifactor authentication (MFA) across all enterprise applications and services.
Despite these gaps, 88% of respondents considered their organizations secure.
AI phishing makes attacks harder to detect
The report also highlights how artificial intelligence (AI) is making traditional phishing defenses less reliable.
Seventy percent of respondents reported increased phishing activity targeting their organizations over the previous year. Additionally, 44% said their organizations experienced at least one successful AI-driven attack during that period.
Attackers are also using impersonation techniques to target organizations. Approximately 43% of respondents reported suspicious video or voice-based impersonation attempts targeting executives or clients.
To examine whether security professionals could recognize AI-generated communications, researchers presented respondents with human-written and AI-generated messages.
Only 36% correctly identified the human-written question, while 39% failed to recognize the AI-generated question.
AI agent security demands human oversight
As organizations adopt autonomous AI agents, verifying nonhuman identities is becoming a greater security priority. The survey found that 91% consider verifying the identity and authenticity of AI agents essential, with 57% describing it as critical.
Separately, 91% of respondents said a human approval step should remain in place before AI agents execute actions on their behalf.
That oversight becomes particularly important when agents can perform sensitive operations, such as escalating account privileges or initiating financial transactions.
U.S. leads in password dependency
The United States showed the largest gap between authentication awareness and workplace password usage among the surveyed markets.
Although 40% of U.S. respondents identified hardware-backed passkeys as the most secure authentication method, 50% still used usernames and passwords at work.
Password dependency also extended to personal accounts, with 56% of U.S. respondents relying on usernames and passwords outside work.
What security teams should do next
Organizations should begin by reviewing how credentials are issued during onboarding.
Providing phishing-resistant authenticators from an employee's first login can help prevent password-based workflows from becoming established.
Security teams should also identify applications that still depend on passwords and require phishing-resistant authentication wherever supported.
Organizations should also verify nonhuman identities (NHIs) and maintain human approval for sensitive actions.
For organizations looking to move beyond passwords, explore our guide to the best passkey solutions for stronger authentication.





