48% of Cybersecurity Professionals Rely on Passwords for Personal Accounts

A new study by Yubico and Okta found that almost half (48%) of cybersecurity professionals depend on usernames and passwords to authenticate personal accounts, and 43% depend on this method to log in to work accounts — in spite of the fact these professionals view it as one of the least secure methods of authentication.
- 24% deployed password managers for work accounts, 30% for personal
- 52% were issued traditional credentials when starting
- 76% report their organization depends on fragmented authentication methods spanning a range of internal applications
Below, security leaders are sharing their concerns, insights and suggestions.
Security Leaders Weigh In
Shane Barney, Chief Information Security Officer at Keeper Security:
Complex passwords may look secure on paper, but in practice, they’re reused, stored in spreadsheets, or shared over email because humans aren’t wired to remember dozens of combinations. Attackers know that, and they exploit it every day.
The good news is that this shift is accelerating. Recent global research found that 80% of organizations are either adopting or planning to adopt passkeys and hybrid authentication models. As organizations modernize their infrastructure and identity systems, the move toward passwordless, phishing-resistant authentication is going to become the standard, not the exception.
Modern password management and authentication solutions remove many traditional roadblocks by integrating directly with existing identity providers, supporting passkeys, and automating strong password practices across the organization. Security modernization doesn’t have to mean disruption — it can start with small, high-impact wins such as eliminating password reuse, enforcing Multi-Factor Authentication (MFA) and adopting password managers that provide visibility to IT teams and convenience for users. Each step reduces risk and builds momentum toward ubiquitous passwordless access.
Matt Dunham, Vice President of Platform Security at Pax8:
Distribution from traditional to modern to frictionless password security will change as adoption of password managers and passkey-based authentication continue to gain traction. Improving authentication hygiene is low-hanging fruit for most businesses, and organizations that haven’t solved for this have bigger problems of getting executive leadership engaged with cyber risk. Currently, the technical solutions to strong authentication are vast and well-understood, so the journey really begins with engaging the business on the importance of adopting cybersecurity fundamentals.
James Maude, Field CTO at BeyondTrust:
The continued rise of identity threats and botnets is presenting a real challenge when it comes to enterprise security as many of their traditional defenses are simply not able to detect and prevent them in time. This is why is important to take an identity centric approach to security and focus on reducing your identity attack surface with least privilege and a holistic approach. Identity threats are here to stay, and with the rise of AI, we can only expect them to increase in scale.
Randolph Barr, Chief Information Security Officer at Cequence Security:
Organizations should always check to ensure that they have strong identity and access management for agents and skills, enforce strict least-privilege rules, set up guardrails and policy engines to manage agent actions, use sandboxing and segmentation for execution environments, monitor and log all API and agent interactions thoroughly, and be able to quickly disable or revoke skills if needed.
Bottom line: visibility, behavior-based detection, and least privilege for AI agents is working. Legacy tooling, unverified isolation, and an ungoverned agent supply chain are the gaps.
Jason Soroko, Senior Fellow at Sectigo:
Moving forward, I expect that we will steadily move toward SSO with passkeys as platforms ship passkeys by default and as real time phishing continues to erode confidence in passwords and one-time codes.
Start the journey to phishing resistant and hack resistant authentication by setting passwordless as the north star and moving in waves. The key to understanding this is to move towards non-shared secrets. Shared secrets such as passwords are the heart of the problem. Any secret that is shared is an inferior secret and is the basis for the underlying weakness in the authentication mechanism.
I recommend the following:
- Put every app behind SSO
- Enable passkeys with platform authenticators for the broad population
- Issue hardware security keys for admins and high value users
- Retire SMS and voice
- Limit TOTP to narrow exceptions with a clear sunset
- Harden recovery
- Add conditional access with step up only when risk warrants it
- Monitor enrollment and failure rates
- Keep a break glass path
- Migrate app by app until passwords are gone
Any form of shared secret is an inferior form of authentication because it can be phished, replayed or harvested. Better forms exist that cannot be harvested, including passkeys and digital certificates where the private key never leaves the device and the login is bound to the site you are visiting. We must move away from passwords for all new systems and for any existing system that can be refactored.
Chris Radkowski, GRC Expert at Pathlock:
The rise of AI agents and machine identities has outpaced traditional identity security. MFA and legacy access controls were built for a world of human users, not autonomous agents, service accounts, and AI-driven workflows that now outnumber people across the enterprise by more than 20 times. Making matters more complex, the productivity promise of AI is too compelling for employees to wait on IT, workers are signing up for AI-powered tools, copilots, and automation platforms using their enterprise credentials, connecting them directly to corporate email, productivity suites, and business applications, often without security’s knowledge.
As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren’t prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human, or machine.
In the AI era, identity isn’t just an IT problem. It’s the foundation of trust itself.
Mika Aalto, Co-Founder and CEO at Hoxhunt:
The biggest mistake companies can make in the AI era is believing technology alone will solve social engineering. Attackers are targeting human behavior. That means the defense must strengthen human behavior as well. The advantage will go to whoever understands that technology is a lever, not a replacement, for influencing human psychology.
Attackers are moving beyond email. Mobile phishing, callback attacks, and malicious calendar invites are examples of how social engineering is expanding into the everyday tools and workflows employees use outside of email. It’s key that our technical and training protections are equally expansive.
We’ve expected AI to reshape cybercrime for years, so the answer isn’t panic, it’s preparation. Right now, there’s a wave of alarmist messaging around AI threats that almost resembles social engineering itself. Deepfakes are real, but they’re still rare and highly targeted. If companies focus training on exotic attacks instead of the common social engineering tactics people face every day, they’re not optimally managing human risk.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!




.webp?height=200&t=1630084048&width=200)


