Half of Cybersecurity Pros Still Rely on Passwords Despite Security Co
Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.

This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security.
Nearly half (44%) of respondents reported that their organization had experienced at least one phishing attack that was AI-driven in the past year.
The report noted that this trend is likely at least partly due to the impact of AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.
This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA,” the report read.
In addition, 70% of security professionals experienced an increase in phishing attacks on their organization over the past year, with 55% targeted by personalized attacks directly.
Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.
The researchers said that the findings suggest that the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.
While device-bound, hardware-backed passkeys were seen as the most secure authentication method by security professionals, just 25% used this method to log into work accounts and 20% for personal accounts.
Over half (52%) of the 2000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles, establishing legacy habits.
Password managers were deployed by 24% of respondents for work accounts, rising to 30% for personal accounts.
What happened
This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security.
Nearly half (44%) of respondents reported that their organization had experienced at least one phishing attack that was AI-driven in the past year.
What changed
The report noted that this trend is likely at least partly due to the impact of AI, with cybercriminals known to be using generative AI tools to increase the scale and sophistication of phishing campaigns.
This may be underscored by possible concerns of being locked out of personal accounts, individuals could revert to simple passwords and familiar SMS MFA,” the report read.
Who is affected
In addition, 70% of security professionals experienced an increase in phishing attacks on their organization over the past year, with 55% targeted by personalized attacks directly.
Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.
Technical details
The researchers said that the findings suggest that the ongoing reliance on less secure authentication methods is primarily a structural problem driven by operational friction and outdated onboarding defaults rather than awareness.
While device-bound, hardware-backed passkeys were seen as the most secure authentication method by security professionals, just 25% used this method to log into work accounts and 20% for personal accounts.
Over half (52%) of the 2000 cybersecurity professionals surveyed were issued traditional username and password credentials when starting their roles, establishing legacy habits.
Response
Password managers were deployed by 24% of respondents for work accounts, rising to 30% for personal accounts.
Attribution
Infosecurity Magazine: Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%.