Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementSecurity & Business ResilienceCybersecurity News

48% of Cybersecurity Professionals Rely on Passwords for Personal Accounts

By Jordyn Alger, Managing Editor
Keys on yellow background
Alp Duran via Unsplash
October 7, 2026

A new study by Yubico and Okta found that almost half (48%) of cybersecurity professionals depend on usernames and passwords to authenticate personal accounts, and 43% depend on this method to log in to work accounts — in spite of the fact these professionals view it as one of the least secure methods of authentication. 

  • 24% deployed password managers for work accounts, 30% for personal 
  • 52% were issued traditional credentials when starting 
  • 76% report their organization depends on fragmented authentication methods spanning a range of internal applications 

Below, security leaders are sharing their concerns, insights and suggestions. 

Security Leaders Weigh In

Shane Barney, Chief Information Security Officer at Keeper Security: 

Complex passwords may look secure on paper, but in practice, they’re reused, stored in spreadsheets, or shared over email because humans aren’t wired to remember dozens of combinations. Attackers know that, and they exploit it every day.

The good news is that this shift is accelerating. Recent global research found that 80% of organizations are either adopting or planning to adopt passkeys and hybrid authentication models. As organizations modernize their infrastructure and identity systems, the move toward passwordless, phishing-resistant authentication is going to become the standard, not the exception.

Modern password management and authentication solutions remove many traditional roadblocks by integrating directly with existing identity providers, supporting passkeys, and automating strong password practices across the organization. Security modernization doesn’t have to mean disruption — it can start with small, high-impact wins such as eliminating password reuse, enforcing Multi-Factor Authentication (MFA) and adopting password managers that provide visibility to IT teams and convenience for users. Each step reduces risk and builds momentum toward ubiquitous passwordless access.

Matt Dunham, Vice President of Platform Security at Pax8:

Distribution from traditional to modern to frictionless password security will change as adoption of password managers and passkey-based authentication continue to gain traction. Improving authentication hygiene is low-hanging fruit for most businesses, and organizations that haven’t solved for this have bigger problems of getting executive leadership engaged with cyber risk. Currently, the technical solutions to strong authentication are vast and well-understood, so the journey really begins with engaging the business on the importance of adopting cybersecurity fundamentals.

James Maude, Field CTO at BeyondTrust:

The continued rise of identity threats and botnets is presenting a real challenge when it comes to enterprise security as many of their traditional defenses are simply not able to detect and prevent them in time. This is why is important to take an identity centric approach to security and focus on reducing your identity attack surface with least privilege and a holistic approach. Identity threats are here to stay, and with the rise of AI, we can only expect them to increase in scale.

Randolph Barr, Chief Information Security Officer at Cequence Security:

Organizations should always check to ensure that they have strong identity and access management for agents and skills, enforce strict least-privilege rules, set up guardrails and policy engines to manage agent actions, use sandboxing and segmentation for execution environments, monitor and log all API and agent interactions thoroughly, and be able to quickly disable or revoke skills if needed.

Bottom line: visibility, behavior-based detection, and least privilege for AI agents is working. Legacy tooling, unverified isolation, and an ungoverned agent supply chain are the gaps.

Jason Soroko, Senior Fellow at Sectigo:

Moving forward, I expect that we will steadily move toward SSO with passkeys as platforms ship passkeys by default and as real time phishing continues to erode confidence in passwords and one-time codes. 

Start the journey to phishing resistant and hack resistant authentication by setting passwordless as the north star and moving in waves. The key to understanding this is to move towards non-shared secrets. Shared secrets such as passwords are the heart of the problem.  Any secret that is shared is an inferior secret and is the basis for the underlying weakness in the authentication mechanism.

I recommend the following:

  • Put every app behind SSO
  • Enable passkeys with platform authenticators for the broad population
  • Issue hardware security keys for admins and high value users
  • Retire SMS and voice
  • Limit TOTP to narrow exceptions with a clear sunset
  • Harden recovery
  • Add conditional access with step up only when risk warrants it
  • Monitor enrollment and failure rates
  • Keep a break glass path
  • Migrate app by app until passwords are gone

Any form of shared secret is an inferior form of authentication because it can be phished, replayed or harvested. Better forms exist that cannot be harvested, including passkeys and digital certificates where the private key never leaves the device and the login is bound to the site you are visiting. We must move away from passwords for all new systems and for any existing system that can be refactored.

Chris Radkowski, GRC Expert at Pathlock:

The rise of AI agents and machine identities has outpaced traditional identity security. MFA and legacy access controls were built for a world of human users, not autonomous agents, service accounts, and AI-driven workflows that now outnumber people across the enterprise by more than 20 times. Making matters more complex, the productivity promise of AI is too compelling for employees to wait on IT, workers are signing up for AI-powered tools, copilots, and automation platforms using their enterprise credentials, connecting them directly to corporate email, productivity suites, and business applications, often without security’s knowledge.

As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren’t prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human, or machine. 

In the AI era, identity isn’t just an IT problem. It’s the foundation of trust itself.

Mika Aalto, Co-Founder and CEO at Hoxhunt:

The biggest mistake companies can make in the AI era is believing technology alone will solve social engineering. Attackers are targeting human behavior. That means the defense must strengthen human behavior as well. The advantage will go to whoever understands that technology is a lever, not a replacement, for influencing human psychology.

Attackers are moving beyond email. Mobile phishing, callback attacks, and malicious calendar invites are examples of how social engineering is expanding into the everyday tools and workflows employees use outside of email. It’s key that our technical and training protections are equally expansive.

We’ve expected AI to reshape cybercrime for years, so the answer isn’t panic, it’s preparation. Right now, there’s a wave of alarmist messaging around AI threats that almost resembles social engineering itself. Deepfakes are real, but they’re still rare and highly targeted. If companies focus training on exotic attacks instead of the common social engineering tactics people face every day, they’re not optimally managing human risk.

KEYWORDS: authentication password password management password protection password security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Stressed woman

Ransomware Doesn’t Just Break Systems. It Breaks People.

Thomas Bock

Thomas “TJ” Bock — Most Influential People in Security 2026

Jennifer Moore

Jennifer Moore — Most Influential People in Security 2026

Eric Clay

Eric Sean Clay — Most Influential People in Security 2026


AlertMedia sponsored webinar

Events

October 7, 2026

Modernizing Travel Risk Management: How Security Teams are Strengthening Duty of Care

LIVE: October 7, 2026 at 2 PM EDT Learn how security teams have strengthened travel risk management for a global workforce. Move beyond manual monitoring to earlier, verified awareness and a more defensible approach to security operations.

October 20, 2026

Beyond the Camera: How AI Is Transforming Physical Security

LIVE: October 20, 2026 at 2 PM EDT AI can connect security systems to detect threats earlier, validate incidents in real time, & accelerate response. Move from passive monitoring to proactive, intelligence-led security while maximizing existing tech investments.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • students-freepik-(1).jpg

    A back-to-school plan for reaching the next generation of cybersecurity professionals

    See More
  • several people looking at their cell phones

    90% of cybersecurity professionals work on vacation

    See More
  • cybersecurity

    22% of cybersecurity professionals have ignored an alert

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • The Database Hacker's Handboo

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing