Report by Secret Double Octopus
2026 State of Identity Security in Financial Organizations
Key Findings
51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.
Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.
SaaS applications in financial organizations are protected by MFA at a rate of 74%.
Legacy systems in financial organizations are protected by MFA at a rate of 50%.
54% of financial organizations report that at least half their applications and infrastructure are legacy.
Only 15% of workforce authentication flows in financial services are passwordless.
79% of IAM leaders and stakeholders cite technical or architectural complexity as an obstacle to universal phishing-resistant MFA.
53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.
Among organizations that cite regulatory compliance as a top driver to modernize, 79% report that at least half their applications and infrastructure are legacy.
94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.
82% of IAM leaders and stakeholders at financial services firms are confident their current controls can mitigate account takeover risk.