AI Ethics
5h ago
Survey reveals gaps in security training and MFA adoption among tech professionals
Oct 9, 2026
AI Summary
A survey of 1,890 technology and security professionals found that while 82% received security training, 23% of organizations do not mandate multifactor authentication (MFA). The findings highlight a disconnect between awareness of phishing threats and the implementation of effective security measures.

- A survey conducted by Yubico and Okta included 1,890 technology and security professionals from companies with at least 500 employees, revealing that 82% had received employer security training.
- Despite the training, 23% of respondents reported that their organizations did not require multifactor authentication (MFA) across all applications and services.
- 88% of respondents considered their enterprises secure, yet 55% had been targeted by personalized phishing attacks, and 44% reported at least one successful AI-driven phishing attack in the past year.
- The survey indicated that traditional warning signs for phishing are becoming less effective, as many messages are now generated by AI with perfect grammar and mimic corporate branding.
- Recommendations from the report include integrating stronger authentication methods during onboarding and ensuring that security training teaches practical skills relevant to different job roles.
- Experts emphasize the importance of verifying suspicious requests through alternative channels and the need for rigorous evaluation of training effectiveness.
phishingcybersecurityai-driven attacksmfasecurity awareness