Around half (48%) of cybersecurity professionals rely on usernames and passwords to authenticate their personal accounts, according to a study by Yubico and Okta.
Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.
This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security.
While device-bound, hardware-backed passkeys were seen as the most secure authentication method by security professionals, just 25% used this method to log into work accounts and 20% for personal accounts.
Password managers were deployed by 24% of respondents for work accounts, rising to 30% for personal accounts.
A large proportion of security professionals use one-time mobile passcodes and SMS-based authentication, methods which have been shown to be vulnerable to being intercepted by malicious actors.

Three-quarters (76%) of respondents said their organization use fragmented authentication methods across different internal applications, while 23% admitted that they do not mandate multifactor authentication (MFA) across all enterprise applications and services.
The researchers said that the findings suggest that the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.
Over half (52%) of the 2000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles, establishing legacy habits.
“Both inside and outside of work, login friction and authentication fatigue consistently pulls even the most knowledgeable professionals toward the path of least resistance. This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA,” the report read.
AI-Driven Surge in Social Engineering
The Yubico and Okta report, published on October 7, also highlighted a growth in social engineering attacks facilitated by AI.
Nearly half (44%) of respondents reported that their organization had experienced at least one phishing attack that was AI-driven in the past year.
In addition, 70% of security professionals experienced an increase in phishing attacks on their organization over the past year, with 55% targeted by personalized attacks directly.
The report noted that this trend is likely at least partly due to the impact of AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.
The use of deepfakes in social engineering campaigns is also prevalent, with 43% of organizations reporting suspicious video, voice memo or phone impersonations targeting executives or clients.
Around a third (29%) of security professionals said they were directly targeted by deepfake communications.
