Survey: How friction, not ignorance, is stalling enterprise security

New global study by Yubico and Okta reveals why awareness alone cannot stop AI phishing and credential risk.

About the Author

Charlotte Wylie

SVP and Deputy Chief Security Officer

Charlotte Wylie, SVP and Deputy Chief Security Officer at Okta, leads Okta’s technical cybersecurity services. This includes overseeing Okta’s global engineering teams to enhance the company’s security postures and programs that support its nearly 19,000 customers. She's a seasoned security executive with extensive global experience across financial and technology industries in Australia and the United States. Charlotte has an extensive background in delivering security transformation programs and leading global engineering teams to create value through enhancing security posture and aligning with business goals for large corporations.

07 October 2026 Time to read: ~

Every year organizations pour time and money into making their employees more security conscious. They adopt multi-factor authentication, implement new security policies, and mandate compliance training. And it feels like it's working. 

The 2026 Global State of Authentication, a joint report from Yubico and Okta, found that 88% of security leaders express confidence in their organization's current security posture. While that confidence is encouraging, the report, which is based on a survey of nearly 2,000 technology and security professionals across nine countries, reveals that organizations are attempting to solve an architectural problem with human education.

It turns out that day-to-day login friction and legacy defaults—such as passwords issued during onboarding—are often more significant barriers to security than a lack of knowledge.

Here is a look at some of the report’s key takeaways:

Legacy habits start on day one

People often assume identity security risks stem from a lack of knowledge, but the data suggests otherwise. Security professionals possess deep domain expertise: 87% are familiar with passkeys, and 31% recognize device-bound, hardware-backed passkeys as the most secure credential available. Yet, 43% of security pros still rely on passwords to log in to work.

To find out why, you have to go back to day one. More than half of respondents (52%) received username-and-password credentials when starting their roles. While legacy habits are hard to break, operational friction also doesn’t help: 76% of organizations use fragmented authentication methods across different internal applications; 45% use usernames and passwords across those systems.

This combination of insecure defaults and constant security prompts triggers authentication fatigue. Because humans naturally choose the easiest path, even the best training is no match for these structural hurdles.

Why the human firewall cannot stop AI

While many companies have invested in phishing-indicators training for their employees, AI has made visual phishing indicators like typos and awkward phrasing obsolete. In the past year, 70% of respondents noted an increase in organizational phishing, 44% reported that their organization suffered at least one successful AI-driven attack, and 43% experienced suspicious video, voice, or phone impersonations targeting executives or clients.

Even security experts are struggling to keep up. To test defenses, Okta and Yubico asked security professionals to distinguish between human-written and AI-generated messages. Only 36% correctly identified the human-written message. Because humans can no longer spot the bot, organizations cannot rely on employee vigilance to defend against AI threats. The path forward requires shifting from education-dependent defenses to architectural enforcement that secures authentication by default.

Preparing defenses for AI agents

When organizations modernize their authentication architecture, they do more than protect human employees. They also prepare their businesses to govern AI agents. Security leaders know AI agent governance matters: 91% say verifying AI agent identity is essential, with 57% calling it critical. However, adoption is outpacing security controls.

According to the report, workforces are delegating tasks to autonomous AI agents, from routine scheduling (35%) to drafting internal communications (35%). Comfort levels vary across generations: 68% of Gen Z professionals are comfortable letting an AI agent communicate with clients on their behalf, compared to just 27% of Baby Boomers. This generational trend suggests the next wave of professionals will be more likely to delegate work to AI agents.

The path forward requires balancing this delegation with the human oversight that security professionals know is essential. While the moment of authentication must remain fully automated to prevent human error, human eyes are still needed on critical actions. The majority (91%) of respondents insist on maintaining a "human-in-the-loop" approval step before an agent performs high-stakes actions (escalating privileges, executing financial transactions, etc.) on their behalf.

Modernize your authentication strategy

Building a secure infrastructure requires more than awareness. It requires protecting both human and machine identities in the AI era. 

The report outlines a modern identity framework built on phishing-resistant authentication that helps secure access across three distinct phases: before, during, and after login. By shifting from basic education to structural enforcement, organizations can automate their defenses and reduce credential risk.

Read the full 2026 Global State of Authentication report for the insights and data that enterprises need to start modernizing authentication and reduce credential risk.

About the Author

Charlotte Wylie

SVP and Deputy Chief Security Officer

Charlotte Wylie, SVP and Deputy Chief Security Officer at Okta, leads Okta’s technical cybersecurity services. This includes overseeing Okta’s global engineering teams to enhance the company’s security postures and programs that support its nearly 19,000 customers. She's a seasoned security executive with extensive global experience across financial and technology industries in Australia and the United States. Charlotte has an extensive background in delivering security transformation programs and leading global engineering teams to create value through enhancing security posture and aligning with business goals for large corporations.

Get our Identity newsletter

Access Granted Newsletter