Report by Secret Double Octopus

2026 State of Identity Security in Financial Organizations

11 FINDINGSPublished Jul 8, 2026
View Original Report →

Key Findings

51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.

Legacy SystemsPhishing-Resistant MFAMFAFinancial Services

Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.

MFAPhishingIdentity SecurityIAMFinancial Services

SaaS applications in financial organizations are protected by MFA at a rate of 74%.

SaaSMFAFinancial Services

Legacy systems in financial organizations are protected by MFA at a rate of 50%.

Legacy SystemsMFAFinancial Services

54% of financial organizations report that at least half their applications and infrastructure are legacy.

Legacy SystemsIT InfrastructureFinancial Services

Only 15% of workforce authentication flows in financial services are passwordless.

Passwordless AuthenticationIdentity SecurityFinancial Services

79% of IAM leaders and stakeholders cite technical or architectural complexity as an obstacle to universal phishing-resistant MFA.

AuthenticationPhishing-Resistant MFAMFAFinancial Services

53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.

AuthenticationPhishing-Resistant MFAMFAFinancial ServicesBudget Constraints

Among organizations that cite regulatory compliance as a top driver to modernize, 79% report that at least half their applications and infrastructure are legacy.

Regulatory ComplianceLegacy SystemsFinancial Services

94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.

PhishingIAMFinancial Services

82% of IAM leaders and stakeholders at financial services firms are confident their current controls can mitigate account takeover risk.

Identity SecurityAccount TakeoverFinancial Services