A new Australian survey suggests plenty of IT professionals know about passkeys, but nearly half are still using passwords as their main way into work accounts. IT Brief's 8 October reporting on research commissioned by Yubico and Okta puts those Australian figures at 93% and 45% respectively. It also reports that 61% received a username and password when starting their current role, compared with 17% who received a hardware security key.
Those are reported Australian results, rather than global percentages. Yubico's original announcement confirms that Talker Research surveyed 1,890 technology and security professionals across nine countries from 2–16 July 2026, all working in organisations with at least 500 employees. The public announcement does not provide the Australian sample size or country tables. These are self-reports from people in larger organisations, not a measure of Australian small businesses or the general workforce.
Both commissioning companies sell identity-security products, so they have a commercial interest in the findings. Even with that context, the gap is worth examining. Knowing a stronger login method exists does not give an employee permission or the means to use it. And describing passwords as the primary method does not, by itself, establish that those accounts lack MFA.
The employee may have very little choice
An application might not support passkeys. The employer might support them elsewhere but still have an older payroll system that requires a password. Perhaps the technology is available and nobody has changed the onboarding instructions. A support team may be reluctant to enable something until it knows how to help someone who loses their phone.
Those are possible explanations, not causes established by these survey figures. They are also more useful starting points than assuming knowledgeable staff simply cannot be bothered.
For a business owner, “enable MFA” sounds like a setting. Replacing a familiar login method can involve deciding which devices staff may use and who can restore access when something goes wrong. Someone also needs to check whether the old login remains available afterwards. Otherwise, the business can announce a successful rollout while leaving the weaker route open.
I would want the person managing the accounts involved before buying equipment. A box of security keys is not much help if the important application cannot use them.
Take the email administrator account
Consider the account that administers a business's Microsoft 365 or Google Workspace environment. Depending on its permissions, it may be able to reset users' access or change settings affecting many mailboxes. That deserves more attention than an account used to download stationery invoices.
Passwords can be phished, reused across services or stolen from compromised devices and services. Authenticator-app codes substantially improve protection, but a real-time phishing site can capture and relay a code before it expires. SMS MFA is generally better than a password alone, with additional exposure to phone-number takeover. The Australian Cyber Security Centre's MFA guidance recommends phishing-resistant methods and explains why MFA methods provide different levels of protection.
With a passkey, your device proves to the website that you're authorised to sign in without handing over a password somebody could steal. It uses public-key cryptography, with the sign-in tied to the legitimate service so a lookalike phishing website cannot collect a reusable secret. As the FIDO Alliance's passkey guidance explains, some passkeys sync between devices through a credential provider. Device-bound passkeys stay on a particular device, which can be a dedicated security key. You don't need separate hardware for every passkey.
A hardware key that supports FIDO2 can let you sign in without a password using a passkey stored on it. Some services instead use it as a FIDO security key alongside your password. The terminology can be confusing: a YubiKey is a product, and a passkey is a credential it can hold. MFA describes using more than one type of authentication factor to sign in.
For an administrator, a hardware key may be a sensible choice. It still cannot prevent every compromise. Malware on an unlocked computer or theft of an authenticated session can create access without another normal login. The distinction between protecting sign-in and protecting an existing session remains relevant after stronger authentication is enabled.
Work out recovery before someone needs it
I would be uncomfortable making one key on one person's keyring the only practical way to administer business email. People lose things, replace phones and leave jobs. Recovery needs to survive those ordinary events without becoming an easy way around the new protection.
Where supported, register a backup authenticator and test it before relying on the primary one. Keep the spare securely in a separate location. Recovery codes need controlled storage accessible to the authorised person during a lockout, rather than an email thread or a shared document. A code stored only inside the account it recovers is unlikely to help.
Synced passkeys can make device replacement easier, but the credential provider's own account and recovery process then deserve attention. For a business, I would establish whether work credentials are being stored in an approved business arrangement or an employee's personal account.
The administrator recovery process needs equal care. Who can approve a reset, how is their identity checked, and what evidence is recorded? Test the documented process safely before removing existing access. Review fallback options too: enabling a passkey does not help much against a route that still permits password-only access. Where a weaker fallback must remain, understand its restrictions and monitoring.
When somebody leaves the business, their access needs removing properly, including any registered security keys and active sessions. If an assistant or contractor needs access, give them their own account with delegated access and appropriate permissions where the service supports it. Sharing the owner's login or recovery credentials makes it harder to see who's doing what, or to withdraw access later.
Start with accounts that can disrupt the business
My priorities would include the domain registrar and DNS account, alongside email administration. DNS control can enable service disruption or redirection; compromised email can support invoice fraud and password-reset attacks. Neither automatically hands an attacker every connected account, but both can give them considerable opportunities.
Hosting and server administration belong near the top, followed by the password manager and accounts used for recovery. Financial systems deserve attention wherever stronger authentication is supported. As with other small-business cybersecurity decisions, the order should reflect the damage losing access or control could cause.
For private clients and family-office-style arrangements, I would apply the same thinking to primary personal email, cloud documents and Apple, Google or Microsoft identities. Include financial accounts and password managers, then check what assistants and advisers can access. Financial institutions vary in what they support. Appropriate delegated access and workable recovery may require more effort than choosing a security product.
A five-person business doesn't need to buy hardware keys for every account regardless of need. I'd start with the account that could cause the most damage if somebody got into it. Set up the strongest authentication it supports, make sure there's a sensible recovery option, and then move on to the next one. If an older service cannot support the change, keep its strongest available MFA and put that limitation into the next renewal decision.
Tags: security, small-business, private-client, australia