Discussion Topics
The 2026 State of Identity Security in Financial Organizations examines the current state of workforce authentication across financial institutions, drawing on a survey of 200 IT, cybersecurity, and identity leaders in the U.S. and Canada. The report reveals a significant disconnect between rising identity-based threats and organizations’ confidence in their security posture. While 94% of respondents report an increase in phishing attacks and only 28% of deployed MFA is phishing-resistant, 82% remain confident in their ability to prevent account takeover. Legacy infrastructure continues to hinder progress, with only half of legacy applications protected by MFA and just 15% of workforce authentication flows being truly passwordless. The findings underscore the need for financial organizations to prioritize phishing-resistant, passwordless authentication and expand MFA coverage across legacy environments to reduce cyber risk and strengthen regulatory compliance.

