Skip to main content

Cybersecurity statistics / MFA

Only 23% of third-party organizations fully remediated missing or improperly secured multifactor authentication (MFA) on their cloud accounts, with 50% of all findings being resolved within a month.

PublisherVerizon
Report2026 Data Breach Investigations Report
Published19 May 2026
TopicsMFA, Cloud

Published by Verizon in 2026 Data Breach Investigations Report , 19 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Compare this across sources

3 sources answer what share of organisations have deployed multi-factor authentication. They report between 40% and 66%, with a median of 60%.

See all 3 sources

Related statistics

51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.
Secret Double Octopus, 12/07/2026
SaaS applications in financial organizations are protected by MFA at a rate of 74%.
Secret Double Octopus, 12/07/2026
53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.
Secret Double Octopus, 12/07/2026
Legacy systems in financial organizations are protected by MFA at a rate of 50%.
Secret Double Octopus, 12/07/2026
Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.
Secret Double Octopus, 12/07/2026
79% of IAM leaders and stakeholders cite technical or architectural complexity as an obstacle to universal phishing-resistant MFA.
Secret Double Octopus, 12/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.