Back to News
Market Impact: 0.2

‘The gap was not the awareness’: The company phishing trainings you loathe aren’t enough when nearly 1 in 4 security pros say their MFA is optional

Source: Fortune

Cybersecurity & Data PrivacyArtificial IntelligenceTechnology & Innovation

A Yubico- and Okta-backed survey of 1,890 technology and security professionals at companies with at least 500 employees found that 23% said their organizations did not require MFA across all applications and services, while 88% described their enterprise as secure. More than half reported being targeted by personalized phishing, and 44% said their organization had experienced at least one successful AI-driven phishing attack in the prior year. The article emphasizes layered safeguards—including stronger authentication, practical training, and verification of unusual requests—while noting the survey does not represent workers generally.

Analysis

The investable signal is a shift in security spend from awareness metrics toward controls that limit damage after a human error. That favors phishing-resistant authentication and identity policy, but the protections are not interchangeable: passkeys/security keys can reduce credential theft, while they do not stop an employee from following a fraudulent payment or gift-card instruction. The next layer of demand is therefore likely to include out-of-band approval workflows, privileged-access controls, and transaction verification—not just more MFA licenses. This broadens the potential beneficiaries beyond Okta and Yubico to identity and endpoint vendors such as Microsoft and CrowdStrike, while making standalone training outcomes harder to monetize unless vendors can demonstrate reduced incidents.

For OKTA and YUBICO, the survey supports a sales narrative, not a revenue forecast. It is vendor-associated, limited to security/technology professionals at large firms, and does not establish willingness to spend, deployment rates, or incident reduction. The partnership could improve distribution, but does not by itself prove incremental bookings. Target’s anecdote is not evidence of a company-specific exposure.

Near term, likely limited stock impact absent a disclosed contract or guidance change. Over 1–3 months, watch identity/security budget commentary and evidence that customers are moving from password-plus-code setups to phishing-resistant credentials. Over 6–18 months, the stronger thesis is controls embedded in onboarding and payment approval workflows. Contrarian risk: the market may over-credit authentication; sophisticated social engineering can bypass controls that only protect login. Falsify the spend thesis if OKTA or YUBICO reports no improvement in adoption/bookings despite elevated threat awareness, or if security budgets weaken.

AllMind Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request Trial

Market Sentiment

Overall Sentiment

mixed

Sentiment Score

-0.10

Ticker Sentiment

OKTA0.40
YUBICO0.40

Key Decisions for Investors

  • No immediate event-driven position in OKTA, YUBICO, or TGT: the survey is directional demand evidence, not proof of incremental financial impact.
  • Put OKTA and YUBICO on a catalyst watchlist. Reassess for a long only with evidence of higher phishing-resistant authentication adoption, paid conversions, or improved bookings/guidance; the partnership announcement alone is insufficient.
  • Within cybersecurity exposure, favor diversified identity/control platforms over a pure training narrative. Track Microsoft and CrowdStrike as competitive beneficiaries, while recognizing the article provides no company-specific revenue estimates.
  • Monitor for the key thesis break: security spending or vendor adoption fails to rise despite continued phishing incidents, or customers report that authentication upgrades do not reduce account-compromise losses because workflow and payment scams remain untreated.

More News

From AllMind Research

Browse all research