Australian Security Teams Know Passkeys Are Safer, But Passwords Still Dominate
Yubico and Okta’s authentication survey found Australian technical teams recognise passkey security while legacy onboarding, fragmented MFA and AI phishing keep passwords embedded in enterprise access.

Yubico and Okta’s latest authentication survey exposes an Australian security contradiction: technical workers understand that passkeys offer stronger protection, yet passwords still sit at the centre of many workplace logins, iTWire reported.
Talker Research ran the study for the two companies from July 2 to July 16, polling 1,890 technology and cybersecurity professionals in enterprise organisations across nine markets.
The Australian results show security knowledge colliding with first-day access routines and uneven controls across business applications.
Onboarding is the main fault line.
In Australia, 61% of technical workers started their current roles with only a basic username-and-password credential, and 45% continue to depend on standard passwords as their primary workplace login.
Hardware security keys reached just 17% of new hires, trailing Germany’s 29% and the 24% global average.
The access environment stays fragmented after employees join.
Seventy-three percent of Australian organisations use different authentication setups across applications, and 24% still lack MFA enforcement for every enterprise app.
That leaves staff responsible for spotting threats while the login layer remains inconsistent.
Attackers are already exploiting that weakness with AI-enhanced deception.
Over the previous 12 months, 43% of Australian enterprise organisations had one or more AI-driven phishing breaches, and 47% of technical staff encountered deepfake impersonation attempts involving suspicious videos, phone calls or voice calls that pretended to come from executives or clients.
A test inside the survey showed how unreliable human inspection has become.
Among Australian technical experts, 57% mislabelled a genuine HR email as AI-generated text, while 37% recognised it as human-written.
Another 54% identified the AI-written email.
Across the full global sample, every professional and demographic group fell below 50% accuracy when judging human-written text.
The findings also show why AI agent governance is becoming part of the same access debate.
In Australia, 72% of technical leaders rated human review and final approval for AI agent actions as very important, above the 56% global average and Japan’s 32%.
Verification of an AI agent’s identity and authenticity drew a very important rating from 70% of Australian respondents.
Operational trust is more selective than absolute.
Forty-three percent of Australian workers were prepared to let an AI agent handle low-risk operational micro-decisions, while 20% would not allow any business decision without a person in the approval loop.
Yubico and Okta frame the fix as architecture rather than awareness training.
Their blueprint starts with device health and posture checks before a session begins, then requires phishing-resistant authentication at sign-on and continuous context review after access is granted.
For autonomous AI workflows, the companies also call for proof that a person is present, using a hardware key touch or biometric authentication.
Poupak Enbom, Yubico’s chief market and growth officer, said adoption friction around hardware-backed passkeys is the barrier, not a lack of expertise.
Geoff Schomburgk, Yubico’s vice president for Asia Pacific and Japan, said generative AI has removed older phishing clues such as poor grammar.
The result is a measured control gap: 93% passkey familiarity, 17% hardware-key onboarding and a 43% recent AI-phishing breach rate.




















