September 29, 2022ย โ In light of recent phishing-based cyberattacks and in recognition of Cybersecurity Awareness Month,ย Yubico, the leading provider of hardware authentication security keys, today shared the results of its inauguralย State of Global Enterprise Authentication Survey 2022ย at a security thought-leadership industry summit hosted by the company in its San Francisco office.
Theย survey,ย conducted for Yubico byย Censuswide, polled 16,000+ employees across a variety of enterprises in eight countries* and asked about theirย perceptions and perceived challenges of MFA, security tools and internal security practices at their organisation, and their recent experiences with cyberattacks.
While the survey revealed numerous interesting data points, these telling cybersecurity authentication and MFA trends surfaced to the top:
- 59% of employeesย still rely on username and password as their primary method to authenticate into accounts
- Nearly 54%ย of employees admit to writing down or sharing a password
- Overย 22%ย of those surveyed still think username and password is the most secure method of authentication
- 61%ย of employees think their organisation needs to upgrade to modern phishing-resistant MFA andย 79% of VP-level staffย want their organisation to upgrade to modern phishing-resistant MFAย (like hardware security keys)
- More than 54% of employeesย are not required to go through cybersecurity training on a frequent basis
- Over the last 12 months,ย nearly 57%ย admit to using a work issued device for personal use
- Within the last 2 years, nearlyย 40%ย of survey respondents admits to having broken their mobile phone andย nearlyย 30%ย have lost it (a device organisations commonly use to authenticate)
โCybersecurity Awareness Month brings global awareness for security hygiene, and is a good time for people and organisations to take action now to shore up their cybersecurity practices,โ said Stina Ehrensvรคrd, CEO and co-founder, Yubico.
โThe results from Yubicoโs global survey highlight the biggest concerns, challenges and real-world scenarios that organisations are facing globally when it comes to their cybersecurity efforts โ including the continued reliance on legacy MFA solutions like one-time passwords. Itโs a stark reminder of how far the enterprise still has to go to adopting and standardising phishing-resistant MFA tools.โ
The State of Authentication
To further foster conversations around the importance of modern authentication, Yubico brought together cybersecurity industry leaders for its inaugural YubiSummit event in San Francisco, which included leading organisations at the forefront of security, influencers and media for in-depth discussions around the top challenges facing enterprises today.
In addition to Yubico executives CEO and Co-founder Stina Ehrensvรคrd, Chief Innovation Officer and Co-founder Jakob Ehrensvรคrd, CISO Chad Thunberg, and Vice President Derek Hanson, attendees includedย Brave,ย Union Pacific Railroad,ย Defending Digital Campaigns,ย Microsoft,ย Googleย andย Rachel Tobac, ethical hacker and CEO ofย SocialProof Security.
Some of the topics discussed at the YubiSumit included:
- Move over passwords: passkeys are the new kid in town.ย After the findings of the survey were unveiled, Yubicoโs Hanson shared information on demystifying the new term ofย passkeysย including what they are, specific use cases and benefits, and what enterprises should consider between the use of passkeys and security keys.
โSeeing the results of the survey and then contrasting that data with what weโre hearing is happening to companies, it only re-emphasises what we already know โ that passwords are not enough and that not all MFA is created equal,โ said Hanson.
โWeโre excited about the arrival of passkeys to help make FIDO authentication globally accessible. It is important to understand how passkeys will impact your organisation and what type of passkey is right for you. Passkeys by definition are passwordless-enabled FIDO credentials, but YubiKeys only create hardware-bound passkeys which are not copyable โ ensuring the highest level of security for enterprises.โ
- What the hack: advice from an ethical hacker.ย Tobac debuted a video with Yubico, demonstrating how cyber criminals hack by tricking people. The video highlights an attack vector seen frequently in recent news stories in which an employee is tricked into going to a malicious link, putting in their username and password and handing their 2FA codes to the attacker โ all within a few seconds. She discussed the evolution of cyber attacks and the importance of deploying modern MFA, like a YubiKey, to stop attackers in their tracks during a hack.
โIf your threat model is elevated because you have admin access at work, are in the public eye, or being targeted/harassed, it’s essential to consider FIDO security keys to prevent the most common attacks we’re seeing in the news right now,โ said Tobac.
- Our corporate responsibility: protecting those at risk around the world.ย Mary Mangione, Yubicoโs Senior Communications and Brand Manager and lead for its philanthropic program,ย Secure it Forward, was joined by experts from Google, Microsoft and Defending Digital Campaigns to discuss protecting high risk users across journalism, civil society, and politics. The conversation focused on the importance of companies partnering to leverage joint resources to keep these vulnerable populations secure.
โCollaborating with organisations like Google, Microsoft and Defending Digital Campaigns allows us to better protect high risk users and organisations that need it most,” said Mangione.ย โAt Yubico, our Secure it Forward program provides YubiKeys on a global scale at no-cost to help equip journalists, political organisations and nonprofits with strong security.โ
To see the results of the survey and download the report, visitย here. Learn more about the YubiKey and phishing-resistant MFA, visitย here.
ย *Australia, France, Germany, New Zealand, Singapore, Sweden, United Kingdom, United States.ย
———- ENDS
Media Contact:ย
Louise Roberts and Sonia Morris – Sphere Public Relations
yubico@spherepr.com.auย
Mob: 0421 672 162
About Yubico
Yubico, the inventor of the YubiKey, makes secure login easy and available for everyone. Since the company was founded in 2007, it has been a leader in setting global standards for secure access to computers, mobile devices, servers, browsers, and internet accounts. Yubico is a creator and core contributor to the FIDO2, WebAuthn, and FIDO Universal 2nd Factor (U2F) open authentication standards, and is a pioneer in delivering modern, hardware-based authentication security at scale.
YubiKeys are the gold standard for phishing-resistant multi-factor authentication (MFA), enabling a single device to work across hundreds of consumer and enterprise applications and services. Yubicoโs technology enables secure authentication, encryption, and code signing and is used and loved by many of the worldโs largest organisations and millions of customers in more than 160 countries.
Aligned with its mission of making the internet more secure for everyone, Yubico donates YubiKeys to organisations helping at-risk individuals through the philanthropic initiative, Secure it Forward. Yubico is privately held, with presence around the globe and offices inย Santa Clara, San Francisco, Seattle area, and Stockholm. For more information, please visit:ย www.yubico.com.