Identity Security at Financial Institutions

Analytics2026-07-30, 02:08
Identity Security at Financial Institutions
Analysts at Secret Double Octopus have released a study on authentication in the financial sector. The report is based on a survey of 200 IAM, IT, and cybersecurity leaders and professionals from financial organizations in the United States and Canada, accounting for 80% and 20% of the sample, respectively.
Key figures and findings:
The primary authentication methods used by organizations are password + OTP (77%), password + push notification (76%), and hardware keys/FIDO2 (72%). The least popular options were password-only authentication and magic links (both were cited in 1% of responses). Password + OTP is most popular among relatively small organizations with 100–500 employees. This method was cited in 90% of responses from organizations of this size, then gradually declined to 66% among organizations with more than 5,001 employees.
On average, approximately 74% of SaaS applications are protected by MFA. Among legacy applications that are not cloud- or SaaS-based, the figure was 50%. Most respondents (54%) reported that legacy applications and infrastructure account for 50–74% of their IT environment. Notably, the most common motivation for modernizing MFA among this group was compliance with regulatory and compliance requirements.
On average, only 28% of the MFA methods used by organizations are phishing-resistant. The main obstacles to deploying more phishing-resistant tools are technical or architectural challenges (79%), financial constraints (53%), inability to support legacy applications and architecture (51%), and the presence of multiple IAM solutions (51%). The last of these concerns managers and team leads (62%) and directors (56%) more than top executives (19%).
This study highlights the challenge of account security in the financial sector. The relatively low adoption of phishing-resistant MFA methods leaves organizations at elevated risk of account compromise through phishing. At the same time, the findings show that authentication practices vary by organization size, with larger organizations shifting from the most popular methods to other approaches—potentially indicating broader opportunities to strengthen security.
Vendors
Secret Double Octopus