DKDKCISSPSearch
Threat Research

Half of Cybersecurity Pros Still Rely on Passwords Despite Security Co

Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.

DKCISSP News DeskInfosecurity Magazine7 Oct 2026, 3:45 pm
Half of Cybersecurity Pros Still Rely on Passwords Despite Security Co
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security.

Nearly half (44%) of respondents reported that their organization had experienced at least one phishing attack that was AI-driven in the past year.

The report noted that this trend is likely at least partly due to the impact of AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.

This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA,” the report read.

In addition, 70% of security professionals experienced an increase in phishing attacks on their organization over the past year, with 55% targeted by personalized attacks directly.

Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.

The researchers said that the findings suggest that the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.

While device-bound, hardware-backed passkeys were seen as the most secure authentication method by security professionals, just 25% used this method to log into work accounts and 20% for personal accounts.

Over half (52%) of the 2000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles, establishing legacy habits.

Password managers were deployed by 24% of respondents for work accounts, rising to 30% for personal accounts.

What happened

This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security.

Nearly half (44%) of respondents reported that their organization had experienced at least one phishing attack that was AI-driven in the past year.

What changed

The report noted that this trend is likely at least partly due to the impact of AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.

This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA,” the report read.

Who is affected

In addition, 70% of security professionals experienced an increase in phishing attacks on their organization over the past year, with 55% targeted by personalized attacks directly.

Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.

Technical details

The researchers said that the findings suggest that the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.

While device-bound, hardware-backed passkeys were seen as the most secure authentication method by security professionals, just 25% used this method to log into work accounts and 20% for personal accounts.

Over half (52%) of the 2000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles, establishing legacy habits.

Response

Password managers were deployed by 24% of respondents for work accounts, rising to 30% for personal accounts.

Attribution

Infosecurity Magazine: Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Microsoft Outlook to block MSIX attachments starting NovemberBleepingComputer · 7 Oct 2026, 9:14 pmChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceThe Hacker News · 7 Oct 2026, 8:28 pmLinux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanThe Hacker News · 6 Oct 2026, 11:54 pmIncident affecting ASOS customersNCSC-UK · 6 Oct 2026, 10:18 pm