Commissioned by UC platform Zoho, the report is based on 3,322 verified responses from IT and security leaders across nine regions, six industries, and twelve roles.
"Fix foundations before chasing advanced capabilities.’”
Read More
- Microsoft Teams Users Being Targeted in State-Linked Phishing Campaign
- How To Prove the ROI of UC Security & Compliance
- 2026 Is Here: The Security and Compliance Shifts You Cannot Afford to Miss
Why Are Attacks Rising While Password Security Still Looks Undeployed?
The report says one in three businesses suffered a confirmed cyberattack last year. Another 7% were not sure if they had been attacked at all. That uncertainty is a governance risk.
What stands out is how many organizations still lack basic password security controls. Only 26% have deployed a dedicated password manager, even though the threat picture is painfully familiar.
In the report’s Threat Landscape ranking, based on the top threats identified by survey respondents, phishing and social engineering ranked first. This was followed by weak or reused passwords, and then by credential stuffing attacks. In other words, the biggest risks are not exotic hacks. They are repeatable credential weaknesses that password security tooling is designed to reduce.
Application sprawl is also pouring fuel on this. 59% of employees now use 15+ apps for work. That means more credentials, more resets, more reuse, and more chances for mistakes. You can call that an identity problem, but it also becomes an identity management workload problem very quickly. And without better password security, MFA can feel like a speed bump rather than real protection.
Why Is Identity Management Visibility The Quiet Failure Point?
Most organizations cannot fully answer a basic question: who has access to what?
The report calls this the identity visibility gap. It finds that 74% lack complete identity visibility. Only 11.6% report full visibility and control. When orphaned accounts and undocumented access are included, 88% still lack complete visibility.
This is where identity management stops being a tool conversation and becomes an architecture conversation. The report is blunt that the issue is integration. It says full credential governance requires four systems working together in real time: HR and directory services, SSO and identity provider for MFA, a password vault, and access governance for certification and orphaned account detection.
When those systems do not share data, gaps multiply. Employees leave and accounts remain. Role changes do not trigger reviews. Orphaned access builds quietly. That is how identity management becomes fragile even in well-funded teams.
Regional snapshots do not soften the picture. The report says U.S. organizations have a 34% confirmed attack rate and 76% lack complete identity visibility. Meanwhile, the UK and EU face accelerating governance pressure, yet 75% still lack full identity visibility, making it a compliance liability.
Want more weekly security and compliance updates for IT leaders? Follow UC Today on LinkedIn.
Why Do Zero Trust Security And AI Plans Stall Without The Foundations?
Security budgets are not the headline problem here. The report says 72% plan to increase security spending over five years. Yet 80% say their stack is not future-ready. That mismatch is a warning sign.




