Core Memo

Memorandum

To
Anyone who needs the day in one page
Date
October 9, 2026

Memorandum

From
Caroline Mercer via Fortune | FORTUNE
Date
Filed
Business·6 min to read
Re

Survey Finds Nearly a Quarter of Security Teams Lack Mandatory MFA

ReSurvey Finds Nearly a Quarter of Security Teams Lack Mandatory MFA

A new Yubico and Okta survey of 1,890 technology and security professionals reveals that while 82% received security training, 23% said their organizations do not require multifactor authentication across all applications, leaving a critical gap in enterprise defenses against increasingly sophisticated phishing attacks.

Nearly one in four technology and security professionals say their organizations do not require multifactor authentication across all applications and services, even though the vast majority have received security awareness training, according to a new survey from Yubico and Okta. The finding points to a persistent gap between knowing the risks of phishing and adopting the technical controls that actually stop attacks.

The survey of 1,890 professionals, conducted by Talker Research between July 2 and July 16 across nine countries, found that 82% of respondents had received employer security training. Yet 23% said their organizations did not mandate MFA—a login step beyond a password—across all systems. Despite that, 88% described their enterprise as secure. The results were released Oct. 7, alongside the announcement of a partnership between Yubico, which sells hardware security keys, and Okta, which provides identity management services.

«The gap was not the awareness; it was the adoption,» Poupak Modirassari Enbom, Yubico's chief market and growth officer, said in an interview. The survey polled professionals in technology and security roles at companies with at least 500 employees, so the findings reflect that population rather than workers generally.

The disconnect matters because phishing attacks are becoming harder to spot. More than half of respondents—55%—said they had been directly targeted by personalized phishing attacks. Another 44% said their organization had experienced at least one successful AI-driven phishing attack in the previous year. Familiar warning signs such as typos and awkward phrasing are fading as AI tools generate messages with perfect grammar and corporate branding.

The survey tested that shift by showing respondents two versions of an HR email asking staff to sign off on an updated handbook—one written by a human, one by AI. Only 36% correctly identified the human-written message, while 54% thought AI had written it.

Lorrie Faith Cranor, director of Carnegie Mellon University's CyLab and a co-founder of the security awareness training company Wombat Security Technologies, said knowing the rules does not guarantee someone will catch every suspicious request. A scam can succeed because it addresses a real need, such as finding a job, resolving an immigration concern, or pleasing a boss. «But if you get a lot of phish and some of them do address a need, even if you have reasonably good habits, you might let down your guard,» she said.

One example illustrates the risk. In a November 2025 Reddit post, a person described buying $800 in Target gift cards on their second day at a new job after receiving an email impersonating their boss. The supposed assignment was to surprise office assistants. The poster said they recognized the scam before sharing the cards' redemption codes.

Cranor said a person's risk depends on how often they are targeted, their security habits, their ability to recognize suspicious messages, and whether the lure interests them. Even someone with good habits can simply be distracted, she added.

The report recommends building stronger authentication into onboarding. About 52% of respondents said they received username-and-password credentials when starting their roles, though the survey did not establish whether they also used MFA. Passkeys, which use cryptographic credentials tied to a legitimate site, can prevent authentication on an imitation website. But that protection covers account access—it will not stop someone from buying gift cards at a scammer's request.

Cranor said MFA provides substantial protection, but its forms differ. Text-message codes can be vulnerable when an attacker persuades a mobile carrier to transfer a victim's number to the attacker's phone. Even an authenticator app can be undermined by deception. A scammer posing as a help-desk employee might ask someone to read out a code, then use it to access the account. «So it is important to never give anyone these codes,» she said.

Training still matters, Cranor said, because it can raise awareness that anyone is a potential victim. «This is a good start, but to be most effective, it also needs to teach concrete skills and give people practice in using them,» she said. She added that training should address threats relevant to different jobs, and that employers should make verifying a request part of the job. If a message appears to come from the boss but something feels off, workers should confirm it through another channel before responding.

Employers also need to know whether their training works. Cranor said many efforts to educate employees and the public about scams have not been rigorously evaluated. «They celebrate the number of people who have been trained or have watched their videos, but they rarely do controlled experiments to see whether the training actually protects people,» she said.

5Views

Caroline Mercer

Author

World News Correspondent

Caroline Mercer covers public affairs, politics, business, culture and daily news for Core Memo. The role focuses on verification, context, and clear explanations for readers.

Encl.More under Business