Skip to content
Phishing Training Ineffective as 23% Lack MFA Adoption

Phishing Training Ineffective as 23% Lack MFA Adoption

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 18:40 UTC
  • •82% of surveyed professionals received phishing training, but 23% lack MFA.
  • •88% of respondents believe their organizations are secure despite vulnerabilities.
  • •Phishing attacks can exploit real needs, making them harder to detect.

A recent survey by Yubico and Okta revealed that while 82% of 1,890 technology and security professionals received phishing training, 23% of their organizations do not enforce multifactor authentication (MFA). Despite this, 88% of respondents consider their enterprises secure. The survey, conducted from July 2 to 16, 2026, highlights a gap in the adoption of security measures rather than awareness of phishing threats. Experts suggest that even well-trained employees can fall victim to scams, especially when messages appear legitimate and urgent. The findings indicate a need for organizations to implement stronger security protocols beyond training sessions to mitigate phishing risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-02
Survey conducted
Yubico and Okta surveyed 1,890 technology and security professionals across nine countries.
Tech.Yahoo
2026-10-07
Survey results released
The survey results were published, revealing significant gaps in MFA adoption among organizations.
Fortune

More articles in this cluster (3)

Common questions

What percentage of organizations lack MFA?
23% of the surveyed organizations do not require multifactor authentication across all applications.
How many professionals received phishing training?
82% of the surveyed technology and security professionals reported receiving employer security training.
What is the main issue identified in the survey?
The main issue is the gap in the adoption of security measures like MFA, rather than a lack of awareness about phishing threats.