‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional
Your first few weeks at work probably look something like this: figuring out who’s who on Slack, which floor has the best snacks, and navigating the hundreds of emails piling up in the inbox.
Then one catches your eye.
It says “Congratulations!” You click, and a new message appears: “You failed the test,” along with an attached invitation to security training.
Ladies and gentlemen, welcome to the decidedly forgettable experience of falling for a phishing scam—or in this case, the simulation of one.
The lesson is to be more careful next time.
But what happens when the next message looks like it came from the boss, lands during a busy afternoon, and asks for something that sounds perfectly reasonable? A new survey from Yubico and Okta highlights why employers need an answer beyond another training session.
Of 1,890 technology and security professionals, 82% had received employer security training.
Still, 23% said their organizations did not require multifactor authentication (MFA)—a login step beyond a password—across all applications and services.
Despite this, 88% described their enterprise as secure.
For employers, the question is what stands between a convincing scam and a compromised account when a worker misses the warning signs.
“The gap was not the awareness; it was the adoption,” Poupak Modirassari Enbom, Yubico’s chief market and growth officer, told Fortune .
Talker Research conducted the survey July 2–16 across nine countries, polling professionals in technology and security roles at companies with at least 500 employees.
The results , released Oct.
7, reflect that population, rather than workers generally.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on fortune.com — the content belongs to Fortune.