Many firms still aren't using good passwords or authentication - and they're paying the price

office software
(Image credit: Photo by Headway on Unsplash)

It seems that many organizations aren't up to code when it comes to password hygiene and using authentication to safeguard themselves from the ever-present threat of phishing attacks.

What's perhaps worse is that they think they are doing a good job, with 88% of IT professionals claiming that their company is prepared for password-based cyberattacks. However, the majority also conceded to falling victim to one.  

This is according to a new report from Axiad, which surveyed over 200 IT professionals across the US from various sectors, including finance, government, retail, manufacturing, healthcare, and more.

Rise of phishing

The respondents also feared phishing the most (39%) out of any cyberattack, with nearly half believing such an attack is the most likely kind to occur.

Despite these concerns around passwords, Axiad found that 93% of businesses are still using them, with most reluctant to use alternatives out of a fear of change (64%). Other concerns included the potential need to replace technology in order to move away from passwords (54%), lack of time (51%) and staff (25%).

In terms of apportioning blame for passwords being exploited, the answers were varied. 35% blamed IT staff, 32% end users, 25% security teams, and 8% leadership. 

When asked what technologies they plan to use over the next year, the top answer from respondents was passwordless technology (45%), and 27% also said they would use multi-factor authentication (MFA). 

It also appears that the guidance from the Cybersecurity and Infrastructure Agency (CISA) was the most impactful (42%) on their authentication strategy, followed by the National Institute of Standards and Technology (NIST) (26%) and the White House Office of Management and Budget (OMB) (13%).

Bassam Al-Khalidi, co-CEO of Axiad, commented, "the survey results are alarming because, despite the rising number of these cyberattacks, most companies are still stuck in the status quo of using passwords as their primary method of authentication."

He also said that "generative AI has significantly lowered the entry barrier for cybercriminals to craft highly effective phishing emails," which makes matters worse when bad password practices are also at play, and explains why "attacks continues to skyrocket." 

Al-Khalidi believes that "the most effective thing they can do to bolster their cybersecurity posture is implement passwordless authentication and phishing-resistant MFA.”

MORE FROM TECHRADAR PRO

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
API
Businesses are being plagued by API security risks - with nearly 99% affected
A digital representation of a lock
Gen Z and Millennial social media accounts are ripe for the taking and this doesn’t surprise me
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Latest in Security
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Latest in News
Jason Sudeikis' Ted Lasso pointing at someone in Ted Lasso season 2
Believe it, baby: Ted Lasso season 4 is officially in development for Apple TV+ – and Jason Sudeikis will reprise his role as the titular soccer coach
Rainbow Six Siege X promotional art.
The Tom Clancy's Rainbow Six Siege X 6v6 mode might finally pull me away from Black Ops 6
A close up of the new web version of Apple Music Classical
Apple Music Classical is now available on the web, but its Mac app is still nowhere in sight
Silent Hill f
Silent Hill f will present players with 'a beautiful yet terrifying choice', and I can't wait to see what it is
Google Chromecast 2
Google is finally rolling out a fix for broken Chromecasts – just as new bugs appear on the Chromecast with Google TV
Garmin Instinct 3 in Neotropic Green
"I'm an idiot": Garmin user reveals how fixing one setting completely changed their training after months of making no progress