ChannelLife Australia - Industry insider news for technology resellers
Australia
Australian firms lag on passkeys as AI phishing rises

Australian firms lag on passkeys as AI phishing rises

Thu, 8th Oct 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Yubico and Okta have published research showing a gap between security awareness and authentication practices in Australian enterprises. The study found that many technical staff still use passwords at work, despite broad recognition that passkeys are safer.

The survey of technology and cybersecurity professionals found that 61% of Australian technical workers were issued a basic username and password when they started their current roles, while 45% said passwords remain their main way of accessing work accounts. Only 17% said they received hardware security keys during onboarding, the lowest level among the countries surveyed.

The findings suggest a disconnect between what technical teams know and what employers implement. According to the study, 93% of Australian IT and security professionals are familiar with passkeys, and 61% regard device-bound, hardware-backed passkeys as the most secure form of authentication.

Australian organisations also reported uneven use of other controls. The research found that 73% operate with fragmented authentication across different applications, while 24% do not enforce multi-factor authentication across all enterprise apps.

AI attacks

The report also highlighted the effect of artificial intelligence on phishing and impersonation attempts. It found that 43% of Australian enterprise organisations suffered at least one successful AI-driven phishing attack in the past 12 months, while 47% of Australian technical staff reported deepfake impersonation attempts targeting colleagues through suspicious videos or calls.

A practical identification test in the survey suggested that technical expertise does not necessarily help staff identify AI-generated communications. Among Australian respondents, 57% wrongly classified a genuine human-written HR email as AI-generated, while 37% correctly identified it as human-written. At the same time, 54% correctly identified an AI-generated email.

Global results were similarly weak. No professional or demographic group scored above 50% accuracy in identifying human-written text, according to the study.

The findings have added to concerns about relying on employee judgement as a primary line of defence. The report argues that inspecting wording and tone is becoming less reliable as AI tools improve the quality of phishing messages.

"Enterprise cybersecurity has a critical execution gap," said Poupak Enbom, Chief Market and Growth Officer, Yubico.

"Security leaders know hardware-backed passkeys - specifically hardware security keys - offer the highest level of protection, yet nearly half still rely on basic usernames and passwords daily. The gap isn't expertise; it's overcoming the friction to user adoption," Enbom said.

Human oversight

The research found that Australian respondents were more cautious than peers in other markets about giving autonomous AI agents authority without human checks. A total of 72% of Australian technical leaders said reviewing and giving final approval for AI agent actions is very important, compared with a global average of 56%.

It also found that 70% of Australian respondents view verification of an AI agent's identity and authenticity as very important. While 43% would trust an AI agent to make low-risk operational micro-decisions, 20% said they would not trust an AI agent with any business decisions without a human in the loop.

The findings indicate that Australian organisations are taking a stricter stance on non-human identity governance even as many continue to rely on older login methods for staff access.

"Generative AI has effectively eliminated traditional phishing indicators like poor grammar and awkward phrasing, rendering human detection obsolete as a security boundary. Australian organisations are rightly demanding strict human-in-the-loop governance for AI agents, but they are leaving the metaphorical front door unlocked by relying on legacy passwords during onboarding.

"Security awareness training cannot fix an architectural flaw. To defend against AI-driven phishing and deepfakes, Australian business leaders must transition to phishing-resistant, hardware-backed authentication," said Geoff Schomburgk, Vice President, Asia Pacific & Japan, Yubico.

The study was conducted by Talker Research and surveyed 1,890 technology and security professionals in enterprise organisations with more than 500 employees across nine markets, including Australia, the United Kingdom, the United States, Germany and Japan.