Global research from Yubico and Okta reveals that 86% of Australian tech pros know passkeys are safer, yet nearly half still rely on passwords.
61% of Australian tech pros are issued legacy passwords on Day 1, while 72% demand strict human sign-off on AI agents and 43% have suffered AI phishing breaches, according to global research from Yubico and Okta.
The study revealed a critical disconnect between cybersecurity knowledge and daily operational practice across Australian organisations.
While Australian technical professionals demonstrate high security literacy and lead the world in passkey familiarity, legacy onboarding defaults leave nearly half of technical staff relying on vulnerable usernames and passwords for work logins.
The 2026 Global State of Authentication report, conducted by Talker Research, surveyed nearly 2,000 technology and cybersecurity professionals across nine global markets, including Australia.
It found that 43% of Australian enterprise organisations suffered at least one successful AI-driven phishing attack over the past 12 months. In addition, 47% of Australian technical staff reported deepfake impersonation attempts (suspicious videos, phone calls or voice calls claiming to be executives or clients) targeting colleagues in the workplace.
The “Awareness Gap”
The report identifies a critical “Awareness Gap” in enterprise cybersecurity: 93% of Australian IT and security professionals are familiar with passkeys, and 61% explicitly recognise device-bound, hardware-backed passkeys as the single most secure authentication method available. However, this expertise fails to translate into workplace practice due to ingrained corporate defaults.
Australia ranks lowest globally in issuing hardware security keys to new hires at onboarding, with just 17% receiving them (compared to 29% in Germany and a global average of 24%). Instead, 61% of Australian technical workers were issued a basic username and password when starting their current roles and 45% still rely on standard passwords as their primary method of authenticating to work accounts.
Additionally, 73% of Australian organisations operate with fragmented authentication across different applications and 24% fail to enforce multi-factor authentication (MFA) across all enterprise apps.
“Enterprise cybersecurity has a critical execution gap,” said Poupak Enbom, Chief Market and Growth Officer, Yubico. “Security leaders know hardware-backed passkeys – specifically hardware security keys – offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn’t expertise; it’s overcoming the friction to user adoption.”
Failure of the “Human Firewall” against AI phishing and deepfakes
As generative AI accelerates digital communication and makes phishing lures indistinguishable from genuine correspondence, relying on employees as a primary line of defence has reached its limits.
In a practical identification test administered to cybersecurity and IT professionals, 57% of Australian technical experts incorrectly flagged a genuine, human-written HR email as AI-generated text, while only 37% correctly identified it as human-written. Meanwhile, 54% correctly spotted an AI-generated email.
Globally, no professional or demographic group scored above 50% accuracy in identifying human text, proving that visual inspection and employee suspicion are no longer viable security controls against modern generative AI lures.
Demanding AI agent oversight
As organisations integrate autonomous AI software agents into daily workflows, Australia has emerged as the most cautious market globally regarding non-human identity governance. 72% of Australian technical leaders say that reviewing and giving final approval for AI agent actions is ‘very important’ (compared with a 56% global average and just 32% in Japan).
70% of Australian respondents state that verifying the identity and authenticity of an AI agent is ‘very important’. While 43% of Australian workers would trust an AI agent to execute low-risk operational micro-decisions, 20% strictly refuse to trust an AI agent with any business decisions without a human-in-the-loop.
Closing the infrastructure gap
To close the gap between security knowledge and daily practice, Yubico and Okta advocate for a modernised security architecture that enforces phishing-resistant authentication across three distinct phases:
- Before authentication: Mandate device health and posture checks to verify endpoint compliance before establishing an access session. Issue phishing-resistant authenticators to new employees as part of the workforce onboarding process to support high-assurance MFA from the first login attempt.
- During authentication: Enforce the use of phishing-resistant authentication in application sign-on policies to consistently and automatically mitigate AI phishing attempts at sign-in.
- After authentication: Maintain continuous context and risk evaluation to detect session compromise. Requiring proof of human presence, either through a physical hardware interaction such as a key touch or biometric authentication, for human-in-the-loop authorisation of autonomous AI workflows.
“Generative AI has effectively eliminated traditional phishing indicators like poor grammar and awkward phrasing, rendering human detection obsolete as a security boundary,” said Geoff Schomburgk, Vice President, Asia Pacific & Japan, Yubico.
Organisations are rightly demanding strict human-in-the-loop governance for AI agents, he said, “but they are leaving the metaphorical front door unlocked by relying on legacy passwords during onboarding.”
“Security awareness training cannot fix an architectural flaw. To defend against AI-driven phishing and deepfakes, business leaders must transition to phishing-resistant, hardware-backed authentication,” he added.
“Generative AI has effectively eliminated traditional phishing indicators like poor grammar and awkward phrasing, rendering human detection obsolete as a security boundary,” said Geoff Schomburgk, Vice President, Asia Pacific & Japan, Yubico.
Organisations are rightly demanding strict human-in-the-loop governance for AI agents, he said, “but they are leaving the metaphorical front door unlocked by relying on legacy passwords during onboarding.”
“Security awareness training cannot fix an architectural flaw. To defend against AI-driven phishing and deepfakes, business leaders must transition to phishing-resistant, hardware-backed authentication,” he added.
Key data point comparisons

