2026 State of Identity Security in Financial Organizations: Key Findings
A survey of 200 IAM leaders and stakeholders at US and Canadian financial organizations reveals a confidence gap: 82% are confident their current authentication controls can mitigate account takeover risk, yet on average only 28% of the MFA they use for workforce authentication is phishing-resistant, and 94% report that phishing attacks increased compared to the previous year.
The identity security confidence gap
Confidence combines respondents who are very confident (30%) and somewhat confident (52%). The phishing-resistant figure is the average share of MFA used for workforce authentication.
Key findings
-
94%
Phishing attacks are rising at almost every financial organization
94% of respondents report that phishing attacks against their organization increased over the past 12 months compared to the previous year: 20% say they increased significantly and 74% say they increased. Only 4% report no change and 2% report a decrease.
-
28%
Most workforce MFA is not phishing-resistant
On average, only 28% of the MFA used for workforce authentication in financial organizations is phishing-resistant. Phishing-resistant MFA typically relies on cryptographic devices or the elimination of phishable credentials; SMS or email one-time passwords and mobile push verifications are not considered phishing-resistant.
-
15%
Only 15% of workforce authentication flows are passwordless
On average, only 15% of workforce authentication flows at financial organizations are passwordless, meaning no user-managed password is required. 75% of respondents say fewer than a quarter of their flows are passwordless, and 10% have none.
-
50%
Legacy apps have far less MFA coverage than SaaS apps
On average, only 50% of legacy apps at financial organizations are protected by MFA, compared to 74% of SaaS apps. In this survey, legacy refers to systems that are not primarily cloud or SaaS based, such as on-premises applications, AD-joined Windows or Mac devices, VPNs, virtualization tools, RDP, and shared accounts.
-
52%
More than half of the financial IT estate is legacy
On average, 52% of financial organizations’ applications and infrastructure are legacy, and 54% of organizations report that 50% to 74% of their apps and infrastructure are legacy. Among respondents who named meeting regulatory or compliance requirements as a top motivation to modernize workforce MFA, that share rises to 79%.
-
77%
Weak and strong authentication methods are used side by side
The most widely used workforce authentication methods are password plus OTP (77%), password plus push notification (76%), and hardware security keys or FIDO2 (72%). Password plus OTP is used by 90% of organizations with 100 to 500 employees, compared to 66% of organizations with more than 5,000 employees.
-
79%
Complexity is the top barrier to phishing-resistant MFA
The top challenges preventing universal phishing-resistant MFA are technical or architectural complexity (79%), cost and budget constraints (53%), inability to support legacy apps and infrastructure (51%), and multiple IAM solutions and directories (51%). The legacy challenge is cited by 62% of team leads and managers and 56% of directors, but only 19% of VP and C-level respondents.
-
82%
Confidence outpaces actual protection
82% of respondents are confident their current authentication controls can effectively mitigate account takeover risk (30% very confident, 52% somewhat confident), despite partial MFA coverage and limited phishing resistance. Only 7% say they are not very confident.
Methodology
- Respondents
- 200 IAM leaders and stakeholders: influencers and decision makers in IT, cybersecurity, and identity security who are responsible for IT security procurement in their departments
- Seniority
- Team lead 11%, manager 36%, director 32%, VP 11%, C-level 10%
- Industry
- Banks 33%, credit unions 23%, investment firms 23%, loan providers and lenders 21%
- Geography
- United States 80%, Canada 20%
- Company size
- Split evenly, 25% each: 100 to 500, 501 to 1,000, 1,001 to 5,000, and 5,001 or more employees
- Administered by
- Global Surveyz Research, an independent global research firm, on behalf of Secret Double Octopus
- Method
- Online survey; respondents recruited through a global B2B research panel and invited by email
- Fieldwork
- April 2026
Frequently asked questions
What percentage of MFA in financial services is phishing-resistant?
According to the 2026 State of Identity Security in Financial Organizations survey by Secret Double Octopus, on average only 28% of the MFA used for workforce authentication in US and Canadian financial organizations is phishing-resistant.
Are phishing attacks on financial organizations increasing?
Yes. In the 2026 survey of 200 IAM leaders and stakeholders at US and Canadian financial organizations, 94% reported that phishing attacks increased over the past 12 months compared to the previous year, and 20% said they increased significantly.
How widely is passwordless authentication used in financial services?
On average, only 15% of workforce authentication flows at financial organizations are passwordless, meaning no user-managed password is required, according to the 2026 State of Identity Security in Financial Organizations survey.
How much MFA coverage do legacy apps have in financial organizations?
The 2026 survey found that on average only 50% of legacy apps at financial organizations are protected by MFA, compared to 74% of SaaS apps. On average, 52% of these organizations’ applications and infrastructure are legacy.
What are the biggest obstacles to phishing-resistant MFA in financial services?
Respondents in the 2026 survey cited technical or architectural complexity (79%), cost and budget constraints (53%), inability to support legacy apps and infrastructure (51%), and multiple IAM solutions and directories (51%) as the top challenges.
What is the identity security confidence gap?
The confidence gap is the difference between how protected financial organizations feel and how protected they are. In the 2026 survey, 82% of respondents said they are confident their current authentication controls can mitigate account takeover risk, while on average only 28% of their workforce MFA is phishing-resistant.
Who conducted the 2026 State of Identity Security in Financial Organizations survey?
The survey was commissioned by Secret Double Octopus and administered online by Global Surveyz Research, an independent global research firm, in April 2026. It polled 200 IAM leaders and stakeholders at banks, credit unions, investment firms, and loan providers in the United States (80%) and Canada (20%).
How to cite this research
Secret Double Octopus. 2026 State of Identity Security in Financial Organizations. Administered by Global Surveyz Research, June 2026. https://doubleoctopus.com/state-of-identity-security-financial-2026/
Read the full report
The full report includes the complete survey data, charts, and takeaways for closing MFA, phishing-resistant, and passwordless coverage gaps.