- In a Yubico and Okta survey of 1,890 tech and security professionals, 87% knew passkeys, yet 43% still signed in to work with a password.
- Half were issued a password at hire, and the authors argue that first credential sticks. Respondents also could not reliably tell AI-written email from human-written.
- Issue phishing-resistant sign-in during onboarding and enforce it by policy, rather than relying on staff awareness.
Knowing about strong login is not the same as using it
Security teams are supposed to be the people who have already moved on from passwords. A new survey suggests many have not. Yubico and Okta surveyed 1,890 people who work in technology and security, across nine countries, about how they get into their work accounts. Typing a password was the leading method.
Within that same group, 87% said they were familiar with passkeys. Passkeys are a newer sign-in method that replaces the typed password. The gap between those two numbers is the story. For these respondents, knowing about the stronger option did not translate into using it.
The day-one credential is the authors' explanation
One in two respondents said their current employer gave them a username and password when they joined. Among respondents, 52% said the IT desk that prepared their laptop made that first call, and it chose a password. The authors' view is that the credential issued on the first day becomes the one people stay with.
The survey does not prove that link. If the authors are right, though, the lever is onboarding. Awareness training asks each person to choose the harder path. Onboarding policy can make the stronger path the only one on offer.
The habit extends beyond the office. For their private accounts, the same people most often choose a password, and the next most common choice is a code sent by text message. Text codes have a weakness of their own. An attacker who persuades a mobile carrier to move a victim's phone number receives those codes too.
Confidence runs ahead of evidence
Most respondents described their own employer as secure. That verdict sits beside the 43% still using passwords. The researchers give the gap a name: optimism bias, meaning the assumption that expertise protects you from harm.
The phishing figures also came from the respondents. Asked about the past year, 44% believed a successful AI-driven phishing attack had reached their organization. A similar share said none had, and the rest were unsure. This is what people believe happened, not a measured breach rate.
Why a key beats a careful eye
The survey also included a quiz. Each person saw a pair of emails announcing an updated employee handbook. A human wrote one and an AI generated the other. The task was to say which was which.
Most of the others guessed that a machine had written the human's message. A few did not know. The lesson here is that reading carefully is a weak defence against a well-written message, even for people who work in security.
Phishing-resistant login changes where the check happens. The key confirms the website's domain before it sends anything. The person's eye is no longer the control. An employee fooled by a convincing fake page still has no working credential to hand over.
What leaders should ask their teams
The report's recommendation starts at the first day of work. Yubico and Okta say new hires should receive a phishing-resistant authenticator during onboarding, so strong login begins with their first sign-in. Application sign-on policies should then require it. The report also asks for a check on device health before a session opens and continued risk checks afterwards. For AI agents acting on a person's behalf, it proposes a key touch or biometric scan before the work is carried out.
Questions worth putting to your identity and IT leads:
What credential does a new hire receive on day one, and does it resist phishing? Which applications still accept a password after a stronger method is set up? Do we enforce strong sign-in by policy, or only recommend it? Who approves an AI agent's actions, and what proves that person is present?
One caveat applies. This is a survey of 1,890 professionals, and the figures are self-reported. It does not measure how any single company is set up. Even so, it points at a cheap place to look first: the defaults your own IT desk hands out.
The survey cannot prove that the first login sets the habit. It is, however, the cheapest place to test the idea.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





