Survey: 39 Percent of IT Professionals Say Phishing is the Most Feared Cyberattack

Axiad, a provider of organization-wide passwordless orchestration, today announced the results of its 2023 State of Authentication Survey. The survey investigated the types of cyberattacks respondents were most afraid of and prepared for, how their organizations held up against password-based attacks, if and why companies are still using passwords, and what cybersecurity technologies companies plan to use in 2024.

The survey, which was conducted in October 2023, collected more than 200 responses from U.S. information technology (IT) professionals, including hardware and software, across a variety of industry verticals, including financial, government, retail, manufacturing, healthcare, education, telecommunications and more.

Key findings from the survey revealed:

  • 39% indicated phishing is the most feared cyberattack, while 49% said it is the attack most likely to happen.
  • 88% felt their company was prepared to defend against a password-based cyberattack, yet 52% said their business has fallen victim to one within the last year.
  • Despite password woes, 93% of respondents are still using passwords for business, citing that the biggest reasons they still use them are fear of change (64%), the potential need to rip and replace technology (54%), time constraints (51%) and lack of staff (25%).
  • When asked whose fault they think exploited passwords are, respondents' answers varied: IT staff (35%), end users (32%), security teams (25%) and leadership (8%).
  • When asked what technologies respondents will use over the next year, 45% said they will use passwordless technology, and 27% said they will use phishing-resistant multi-factor authentication (MFA).
  • When asked which recent guidance has most impacted their organization's authentication strategy, the Cybersecurity and Infrastructure Security Agency (CISA) came out on top (41%), followed by the National Institute of Standards and Technology (NIST) (26%) and the White House Office of Management and Budget (OMB) (13%).

"Generative AI has significantly lowered the entry barrier for cybercriminals to craft highly effective phishing emails, and when you combine that with poor password management, it's no surprise that the volume of successful phishing and password-based attacks continues to skyrocket," said Bassam Al-Khalidi, co-founder and co-CEO of Axiad. "The survey results are alarming because, despite the rising number of these cyberattacks, most companies are still stuck in the status quo of using passwords as their primary method of authentication. Fear of change is no excuse. Organizations need to act now to combat advanced cybercriminals, or they will continue to be at risk. In today's threat landscape, the most effective thing they can do to bolster their cybersecurity posture is implement passwordless authentication and phishing-resistant MFA."

For more data points from the survey, download the State of Authentication Survey report.

Featured

  • Human Risk Management: A Silver Bullet for Effective Security Awareness Training

    You would think in a world where cybersecurity breaches are frequently in the news, that it wouldn’t require much to convince CEOs and C-suite leaders of the value and importance of security awareness training (SAT). Unfortunately, that’s not always the case. Read Now

  • Windsor Port Authority Strengthens U.S.-Canada Border Waterway Safety, Security

    Windsor Port Authority, one of just 17 national ports created by the 1999 Canada Marine Act, has enhanced waterway safety and security across its jurisdiction on the U.S.-Canada border with state-of-the-art cameras from Axis Communications. These cameras, combined with radar solutions from Accipiter Radar Technologies Inc., provide the port with the visibility needed to prevent collisions, better detect illegal activity, and save lives along the river. Read Now

  • Survey: 84 Percent of Healthcare Organizations Spotted Cyberattack in Last 12 Months

    Netwrix, a vendor specializing in cybersecurity solutions focused on data and identity threats, surveyed 1,309 IT and security professionals globally and recently released findings for the healthcare sector based on the data collected. It reveals that 84% of organizations in the healthcare sector spotted a cyberattack on their infrastructure within the last 12 months. Phishing was the most common type of incident experienced on premises, similar to other industries. Read Now

  • Keynote Speakers Announced for ISC West 2025

    ISC West, hosted in collaboration with premier sponsor the Security Industry Association (SIA), unveiled its 2025 Keynote Series. Featuring a powerhouse lineup of experts in cybersecurity, retail security, and leadership, each keynote will offer invaluable insights into the challenges and opportunities transforming the field of security. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3