What the report found An identity-industry report tracked sign-in behaviour and concluded that adoption of multifactor authentication (MFA) nearly doubled from 2020 levels. The report highlighted two linked points: organisations are increasingly turning on MFA, and the most secure options are also the most user-friendly.
Among the headline findings were specific adoption numbers from the report period: a very high share of administrators and a sizeable share of everyday users signed in using MFA. The report also singled out phishing-resistant methods — examples given were FIDO2 WebAuthn and vendor-specific approaches such as FastPass-style passwordless flows — as providing the fastest and most reliable experience for users.
The report backed up why MFA matters: a large proportion of business web application attacks and many email compromise incidents start with stolen usernames and passwords. MFA raises confidence that a person signing in is really who they claim to be by requiring an extra piece of evidence beyond the password.
Adoption varied by sector. Technology accounts showed the highest MFA usage in the dataset, with other sectors such as insurance, professional services, construction and media also reporting high rates. Interestingly, some highly regulated industries lagged behind. The report also noted that smaller organisations in its sample sometimes exceeded very large enterprises in MFA usage. An early spike in MFA adoption was observed around the start of the pandemic period, when workforce customers increased MFA rollout quickly.
What you should do about MFA If you’re responsible for an organisation’s accounts or your personal online security, the practical takeaways are straightforward:
- Prioritise phishing-resistant factors. Where possible, move away from SMS or simple one-time codes and favour methods built to resist phishing — for example hardware keys, platform authenticators using WebAuthn/FIDO2, or modern passwordless flows. The report emphasises these options for both better security and smoother sign-in.
- Start with high-risk accounts. Protect administrative and privileged accounts first, then extend MFA to all employees and critical systems. Attackers often target the few accounts that open the door to more damage.
- Balance security and usability. User friction is a common reason MFA isn’t adopted. Choose methods that work with your users’ devices and workflows, and provide clear setup instructions and support.
- Treat MFA as one layer in a broader strategy. It reduces risk from stolen credentials but should sit alongside good password hygiene, device management, monitoring for suspicious sign-ins, and a zero-trust mindset.
MFA is no longer optional for organisations that take security seriously. The report’s message is clear: adoption is rising, and choosing phishing-resistant, user-friendly authenticators makes both security and everyday access easier. If you haven’t reviewed your authentication choices recently, now is a good time to do so.