2026 State of Identity Security in Financial Organizations.
We surveyed IAM leaders in financial institutions across the U.S. and Canada to uncover how far MFA coverage and phishing-resistant authentication have progressed, and where critical identity security gaps remain.
The threat is escalating
94%
report phishing attacks are on the rise
whileonly
28%
of their MFA is phishing-resistant
and yet
82%
remain confident in their authentication controls
The confidence gap
Confident on paper. Exposed in practice.
94% of finance teams watched phishing attacks climb this year, and most still feel protected. Here is how that rise breaks down.
94%
saw a rise
74% increased
20% significantly increased
6% no change or lower
Take a look inside
A peek at what’s in the report.
SECRET DOUBLE OCTOPUSPage 05
Key Findings
01
IAM leaders are surprisingly confident, despite major identity security gaps.
02
MFA coverage is partial and fragmented across the finance space.
03
Only 15% of workforce flows are passwordless.
04
A large, unprotected legacy footprint is hard to modernize.
SECRET DOUBLE OCTOPUSPage 17
Confidence in Authentication Controls
Figure 13. Ability to mitigate account takeover risk
82%
confident
Somewhat confident — 52%
Very confident — 30%
Neutral — 11%
Not very confident — 7%
SECRET DOUBLE OCTOPUSPage 12
% of Utilized MFA Which Is Phishing-Resistant
Figure 8. Average: 28% is phishing-resistant
1%
43%
47%
7%
1%
1%
None1-24%25-49%50-74%75-99%All
Get the full 2026 report.
What the survey reveals
Exactly how your identity security posture compares with the rest of the finance industry:
The current status of identity security
The gaps in MFA coverage
Key challenges & industry trends
Download the report
Tell us where to send it.
Your report is on its way.
Check your inbox for the 2026 State of Identity Security report.