SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Security leaders overconfident as authentication lags

Security leaders overconfident as authentication lags

Fri, 28th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

rf IDEAS and Wavelynx have published a report on authentication modernisation that points to a gap between executives' confidence in their security posture and the progress being made inside organisations.

Based on a survey of 500 IT and security leaders at mid-sized to large organisations, the report suggests many businesses believe they are ahead of their peers even as core identity and access systems remain dated. It found that 93% of respondents said their organisation's authentication and security maturity was more advanced than others in their industry, while only 24% said their own systems were largely modernised.

The mismatch also appeared in responses from senior leaders and managers. Among managers, whom the report described as closest to day-to-day execution, 72% said authentication modernisation was a high priority, below the overall figure of 78% who said authentication and security modernisation would be a high priority over the next 12 months.

Many respondents also indicated a willingness to spend on the issue. Among those giving any degree of priority to modernisation, 55% said they planned to allocate USD $500,000 or more to the effort.

Even so, progress in practice appears slow. More than half of respondents, 53%, said they had not significantly updated their systems in at least three years, despite rising concern across the cybersecurity industry about identity-related attacks and unauthorised access.

Confidence gap

The findings suggest leaders may be overstating the strength of existing controls while underestimating the work required to update them. Although 90% of respondents described their approach to security as proactive or mostly proactive, authentication-specific work ranked below several other priorities.

Upgrading credentials and authentication methods ranked as the eighth most important initiative, cited by 23% of respondents. Investment in mobile credentials or digital identity tools ranked ninth at 20%.

The survey also suggests some organisations may not fully account for the cost of delay. Twenty-seven per cent of respondents said unclear return on investment was a barrier to modernisation, highlighting continued difficulty in making the internal case for replacing fragmented or ageing systems.

Views on breach costs appeared to reinforce that point. Four in 10 respondents said the total impact of a security breach involving unauthorised access would cost less than USD $1 million, while the report cited a global average data breach cost of USD $4.4 million in 2025.

Access focus

The report comes as identity and access systems face greater scrutiny from security teams. It cited industry data showing that seven in 10 organisations suffered at least one identity-related breach over the past year, increasing attention on how employees, contractors and visitors gain access to systems and buildings.

rf IDEAS makes RFID credential readers used in logical access environments such as single sign-on, secure printing and visitor management. Wavelynx focuses on physical access control, including credential and reader technology for facilities. The report argues that organisations should examine logical and physical access together rather than treat them as separate projects.

That combined approach reflects the way access systems now overlap in many workplaces, where a single credential can be used both to enter a site and to log in to devices or applications. When systems are managed separately, businesses can face duplicated administration, uneven user experiences and weaker oversight of who can access what.

David Cottingham, President of rf IDEAS, said the research showed many organisations were exposed by outdated systems.

"Organisations today are facing more threats than ever, and security leaders cannot become overconfident in their defenses," Cottingham said.

"Our data highlights that many organizations are still using outdated systems, which puts them more at risk than they think. It's critical for company leaders to prioritize authentication modernization and take a long-term approach to securing their systems."

Scott Lordo, Chief Executive Officer of Wavelynx, said cost concerns should be weighed against breach risks.

"Working with rf IDEAS on this data has shown that companies say they are prioritizing modernization, but they may not realize how timely a problem it is," Lordo said.

"While cost can be an issue, the implications of a breach can be far greater. It's up to security leaders to ensure they prioritize modernizing systems to prevent emerging threats."