What was once a secondary consideration in infrastructure design now needs to be treated as a core security function from the start, especially for Apple fleets.
Cisco Duo ’s State of Identity Security 2025 report highlights that risks are growing faster than many IT teams are prepared to manage. AI-powered phishing attacks, identity theft, and internal breaches are forcing organizations to rethink authentication and access.
See also: RaccoonO365: Microsoft & Cloudflare dismantle phishing network

Only 33% of IT leaders in the Cisco Duo survey said they are confident that their identity provider can prevent identity-based attacks. Complexity is part of the problem, and 94% of respondents believe it undermines their attitude towards security. The fragmented state across multiple systems only adds to the challenge as companies scale. Mergers and acquisitions contribute to this over time, as companies end up with a plethora of tools.
Everyone agrees that multi-factor authentication technology is a core requirement, but adoption is not yet widespread across all apps and services. 87% of respondents say phishing-resistant MFA is important to their security posture, but most have not deployed it at scale. Less than 20% have implemented FIDO2 tokens. Cost, complexity, and compatibility with legacy systems continue to slow this progress, leaving gaps that attackers can exploit. Passkeyless access remains the goal, but it is not yet a reality for most organizations.
AI-powered phishing attacks are now considered one of the top identity threats for IT teams, with 44% of leaders citing them alongside insider misuse and software supply chain risks. The rise of AI in attack techniques is forcing IT teams to accelerate efforts to combat it. What once might have been a slow rollout of phishing-resistant authentication is now a race to keep up with evolving threats.
See also: VoidProxy: New phishing service steals credentials

More than 51% of organizations in the survey said they have suffered direct financial losses from identity-related breaches. When credentials are stolen or identity systems are compromised, the damage is seen in downtime, loss of customer trust, and compliance issues.
The survey also reports that 82% of CFOs are increasing their investment in identity security this year. Leaders are also reviewing their vendor strategies. Tool clutter has become a problem for both visibility and operations, and nearly 80% of organizations are considering vendor consolidation as a way to mitigate security breaches.
Simply and clearly: this will continue to be a problem until passkey authentication is the default in all solutions, hardware and software. Touch ID and Face ID should also always be available, even after a reboot. Apple should revise the secure environment in future hardware revisions to make it possible.
See also: New phishing attack mimics Google AppSheet

We are quickly entering a world where you will find it difficult to determine if something digital is real. The work that the FIDO Alliance is doing here is among the most important being done in cybersecurity.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
