The human firewall is crumbling: Why 2026 must be the tipping point for legacy security

The human firewall is crumbling: Why 2026 must be the tipping point for legacy security

AI-powered fraud and increasingly sophisticated phishing attacks are exposing the limitations of passwords and legacy authentication methods, forcing organisations to rethink how they protect identities and sensitive data. Nic Sarginson, Principal Product Manager at Yubico, tells us why phishing-resistant, hardware-backed passkeys can help organisations counter AI-driven attacks, strengthen authentication and build greater cyber-resilience.

For years, ransomware has dominated boardroom discussions and the strategic roadmaps of C-suite executives. However, the threat landscape has reached a critical and irreversible inflection point: according to the World Economic Forum’s Global Cybersecurity Outlook 2026, cyber-enabled fraud has officially overtaken ransomware as the top concern for chief executive officers (CEOs). This historic shift is driven by the rapid proliferation and weaponisation of Artificial Intelligence (AI).

We have now entered an era where the traditional ‘human firewall’ is crumbling under the weight of AI-fuelled attacks. To effectively mitigate the threats of cyberfraud, it’s important for business leaders to move on from legacy cyberdefences, which have become outpaced by increasingly sophisticated modern threats like Artificial Intelligence (AI)-powered phishing attacks.

The cost of cyberfraud

The financial and operational toll of this new wave of cyberfraud is staggering. Recent research shows that UK businesses are losing a total of £64 billion annually in remediation costs, staff overtime and lost business as a result of these incidents.

This proves that cyberattacks have become much more than a mere nuisance for businesses. In fact, they are a pervasive issue that blurs the lines between corporate and personal security, especially with employees commonly accessing work applications on their personal devices. Highlighting this risk, Yubico’s latest State of Global Authentication survey found that 70 percent of respondents have been exposed to cyberattacks in their personal lives in the past year. This concerning proportion demonstrates the extent of the potential threat to businesses when employees use business devices for personal activity.

The AI phishing epidemic

Cybercriminals are increasingly turning to AI as a means of supercharging their scams. In the past, tell-tale signs like far-fetched details or clearly inaccurate information might have given a scam away. Today, large language models can instantly generate human-sounding, highly personalised messages that are nearly impossible for recipients to identify as fraudulent.

These tools have made targeted ‘spear-phishing’ attacks – which once required time-consuming research – scarily easy to execute. Cybercriminals can easily automate these attacks using personal information that is often publicly available through social media profiles.

Bad actors are now also exploiting AI to clone voices and likenesses from audio, video and even images found online, a tactic known as ‘vishing’. Combined with tools that mimic known caller IDs, an attacker can convincingly impersonate a colleague or employer seeking urgent assistance, tricking employees into making a costly mistake.

Employees are acutely aware of this shifting dynamic, with 70% of respondents believing that AI has made phishing more successful. Ultimately, the human brain is simply not equipped to consistently detect this level of synthetic deception, so organisations cannot afford to continue using legacy defence methods.

The unfixable problem with legacy defences

Since the Internet was born, passwords have been the primary key to our digital lives. Despite the dramatic evolution in offensive capabilities, an eye-opening 62% of organisations still rely primarily on username and password credentials.

Further highlighting the prevalence of this frightening overreliance, Yubico’s recent survey revealed that one in four respondents is steadfast in their belief that using a username and password is the most secure method of authentication. However, they are an out-of-date and fundamentally flawed method of security designed for an Internet not prepared for this era of sophisticated cyberattacks.

The catastrophic vulnerability of passwords was recently highlighted by the discovery of one of history’s biggest data breaches, which revealed a treasure trove of 16 billion passwords from users on all of the world’s major platforms – proving once again that passwords are an inherently insecure authentication method.

To help illustrate the danger of a stolen password, once a cybercriminal has a user’s password, they can bypass outdated security measures like SMS-based verification codes with ease, allowing them to access sensitive company and personal data. Ultimately, there is ample evidence demonstrating that building corporate defences that rely on better password habits is a failing strategy.

Neutralising the threat with hardware-backed passkeys

To stop the rising tide of AI-powered cyber fraud, CEOs, Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) must remove human vulnerability from the authentication process entirely. The question for business leaders is no longer if they should move on from passwords, but what they should move on to if they want to properly secure their company’s devices.

In the modern digital age, security needs to shift towards a robust, modern authentication model backed by modern cryptography that is designed for modern cyberthreats. This is where phishing-resistant passkeys, built on FIDO standards, are rapidly becoming the new requirement for secure authentication.

Adopting passkeys – both synced and hardware-backed – is a huge step forward in achieving enhanced security compared to relying on legacy MFA. Synced passkeys offer a practical, user-friendly solution for some use cases, but they depend heavily on the security and availability of the sync mechanism, recovery systems and processes and the cloud accounts they’re tied to. For people and organisations that face higher risks, have greater sensitivity or accessibility needs or individuals who just want the best protection for their finances or other critical accounts, synced passkeys won’t be sufficient.

In its most secure form, a passkey is device-bound – meaning it is stored on a local device like a physical hardware security key instead of on a remote server like passwords. These cryptographic keys are bound to the device and pair a public key with an unguessable private key which is never shared, meaning remote attackers are unable to intercept them.

Rather than depending on something an employee has to remember – which can easily be forgotten, stolen or phished – a passkey relies on something they have (the physical key), something they know (a PIN) and something that proves the identity of the user who is supposed to gain access (a physical touch of the key).

Crucially, this method provides a powerful defence against modern AI-driven attack campaigns. If an employee is tricked into clicking a link and lands on a fraudulent website, the passkey simply won’t allow access. The authentication will fail and the attacker is stopped in their tracks, even if they have the user’s credentials. With device-bound passkeys, the phishing risk is significantly reduced, helping organisations to develop cyber-resilience in the face of unauthorised access from phishing attacks.

This transition is being endorsed at the highest levels, with the UK Government in the process of adopting passkeys for its own digital services, recognising their superior security and long-term cost effectiveness.

Securing the enterprise future

As AI continues to democratise cyberfraud, maintaining legacy authentication methods leaves enterprises unnecessarily exposed. While providing every employee with a physical passkey is a financial consideration, it is surprisingly affordable, especially when weighed against the cost and reputational damage of a single breach. Furthermore, embracing modern authentication helps ensure compliance with evolving regulations like PCI DSS 4.0 and NIS2 – helping businesses on their journey to cyber-resilience.

Cybercriminals will undoubtedly continue to innovate and add new AI tools to their arsenal. But businesses do not have to remain defenceless. By moving beyond the password and investing in a comprehensive, phishing-resistant authentication strategy, organisations can free up resources and grant their teams more time to focus on growth. For any business leader, knowing their staff accounts and company data are safe and sound is a truly worthwhile investment – one that will pay off for years to come.

Browse our latest issue

Intelligent CISO

View Magazine Archive