Bay Street Wire
Tech & BusinessOpinion

The Identity Illusion: Why Your 'Modern' Security is Still a Sieve

Portrait of Ivan Petrov
Ivan Petrovcrypto & web3Oct 7AI
The Identity Illusion: Why Your 'Modern' Security is Still a Sieve

AI-generated image · Bay Street Wire

A new report reveals a staggering gap between security knowledge and actual practice, proving that fancy passkeys can't fix a broken onboarding culture.

Q: The industry keeps talking about 'modern identity controls.' Is there actually any progress being made in the trenches?

A: Not really. As the Financial Post first reported, we are seeing a massive "execution gap," as described by Poupak Enbom, Chief Market and Growth Officer at Yubico. According to a 2026 Global State of Authentication report from Yubico and Okta, nearly half of security professionals are still using passwords at work, even though they know passkeys are the superior, phishing-resistant alternative. It is the same old story: the marketing says one thing, but the actual infrastructure is lagging behind.

Q: If the technology exists, why are security pros—the very people who should be leading the charge—still using passwords?

A: It is a structural failure, not an education problem. Reporting from the Financial Post indicates that the issue is driven by outdated onboarding defaults and operational friction. Specifically, 52% of professionals inherited passwords on their first day of work. This proves that long-term security habits are dictated by whatever legacy system a company hands a new hire on day one, rather than the "gold standard" tools the industry promotes.

Q: Which regions are the worst offenders when it comes to this legacy dependency?

A: The United States is leading the pack in failure. Financial Post reporting shows that 50% of U.S. security professionals use passwords at work, which is the highest rate of legacy dependency among all surveyed global markets. The irony is that the U.S. is also one of the regions with the highest technical awareness; 56% of workers there say they are "very familiar" with passkeys.

Q: Beyond passwords, what other threats are making this "security theater" dangerous?

A: AI-driven attacks are hitting hard while the humans in charge are struggling to keep up. The report, conducted by Talker Research, found that 44% of security professionals suffered an AI-driven attack in the last 12 months. Singapore had the highest global rate of these attacks at 58%, followed by Germany at 38% and Japan at 30%. Even worse, 39% of security pros couldn't even tell the difference between human writing and AI-generated text.

Q: Is there any consensus on what actually works, or is it just more vendor shouting?

A: There is a split in opinion on the "best" tool. The survey found that 31% of respondents view hardware passkeys as the gold standard, while 27% prefer synced passkeys and 23% favor device-bound passkeys via mobile devices. But none of that matters if the onboarding process remains a sieve. As the report suggests, you cannot train your way out of a structural problem; you have to change what employees are given on their first day.

Sources

More from Ivan Petrov