TLDR / Summary Highlights

usecure 2026 Cyber Hygiene Report

Employees remain the easiest way into an organization. These are the five hygiene failures behind most account compromises — and what they cost when they go unnoticed.

Start reading

TLDR / Summary Highlights

1
Five failures drive most compromisesMFA gaps, password reuse, dormant/orphaned accounts, OAuth over-permissioning, and external mailbox forwarding. Individually common, collectively catastrophic.
2
MFA still isn’t universalMFA blocks 99%+ of credential stuffing and 96%+ of bulk phishing. Yet a significant share of users still operate without it.
3
Awareness training isn’t enoughAn employee can score 100% on a phishing simulation and still expose the business through a breached password or a dormant admin account.
4
Compound risk is the real dangerAttackers rarely need one big exploit, instead, they chain small hygiene gaps together into critical, high-value exposure.
01

Executive Summary

In every organization, employees are both the greatest asset and the most targeted vulnerability. While security teams invest heavily in firewalls, endpoint protection, and threat intelligence, adversaries increasingly bypass these controls entirely by targeting the human element through the path of least resistance: poor cyber hygiene.

Cyber hygiene refers to the everyday digital habits and configurations that determine how easy or difficult it is to compromise a user’s identity. Weak passwords, inactive MFA, dormant accounts, excessive application permissions, and stale credentials are not exotic threats, they are the mundane realities of most organizations’ environments. Yet these overlooked factors consistently form the foundation of the most damaging breaches recorded each year.

The five hygiene failures highlighted in this report reflect a consistent truth: attackers do not need sophisticated exploits when employees leave doors unlocked. Multi-factor authentication gaps, password reuse, dormant privileged accounts, OAuth over-permissioning, and external mailbox forwarding each represent a discrete attack vector, yet their true danger emerges when they combine into a compound exposure that dramatically amplifies an organization’s risk profile.

This report explores how these hygiene failures manifest in practice, why legacy security controls struggle to surface them, and how Human Risk Intelligence provides the visibility and prioritization organizations need to close these gaps before attackers exploit them.

02

5 Hygiene Failures Increasing Enterprise Exposure

usecure’s Human Risk Intelligence tool answers a critical question: who is easiest to compromise? It surfaces the digital habits and account configurations that make some employees far more vulnerable than others, regardless of their awareness training scores.

The following failures represent some of the most common cyber hygiene weaknesses observed across organizations today. They are not theoretical risks; they are active exposures present in the majority of mid-market organizations today. Each one lowers the barrier to account compromise; in combination, they create critical compound risk.

Attackers follow a playbook. They target someone valuable, set a trap to deceive them, compromise their access, then cause damage.
MFA Gaps: The Unlocked Front Door
Password Weakness and Credential Reuse
Dormant and Orphaned Accounts
OAuth Over-Permissioning
External Mailbox Forwarding
MFA Gaps: The Unlocked Front DoorPassword Weakness and Credential ReuseDormant and Orphaned AccountsOAuth Over-PermissioningExternal Mailbox Forwarding
5
Critical compound risk
Individually common, collectively catastrophic.
03 · Hygiene Failure 01

MFA Gaps: The Unlocked Front Door

Multi-factor authentication (MFA) is widely regarded as one of the single most effective controls available to defend against account compromise. Studies consistently show that MFA blocks over 99% of automated credential stuffing attacks and more than 96% of bulk phishing attempts. Yet despite this, a significant proportion of users in most organizations operate without any form of MFA, and those users are disproportionately the ones attackers choose to target.

MFA gaps are particularly insidious because they are invisible to traditional security tools. A user without MFA will successfully authenticate with only a username and password — a login that looks entirely normal until the moment an attacker uses stolen credentials to do the same. By the time the intrusion is detected, the attacker may already have established persistence, exfiltrated data, or pivoted to higher-value accounts.

Looking ahead to 2026

MFA gaps are expected to remain a primary attack enabler of account compromise throughout 2026. As credential theft through phishing, dark web markets, and data breaches continues to accelerate, any account without MFA protection is effectively an open invitation — regardless of how well that user performs in phishing simulations.

User with MFA (locked)
Username
•••••••
Enter code
Verify
Access blocked without second factor
Attacker with stolen credentials
User without MFA (unlocked)
Username
•••••••
Sign in
Access granted with username and password only
What attackers can do once in
Establish persistence
Exfiltrate data
Pivot to high-value accounts
No MFA = Easy entry for the attacker.

Illustrative Attack Scenario: MFA Gap

The following scenario is fictional but reflects techniques commonly used by attackers.

A Finance Manager at a mid-size professional services firm had never enrolled in Microsoft Authenticator despite repeated prompts from IT. The account had full access to the company’s financial systems, accounts payable workflows, and shared drives.

Phishing email Phishing

From: finance.update@[legitimate-domain.com]
Subject: Action required: Verify your Microsoft account

Dear [Name],

We have detected unusual sign-in activity on your account. To verify your identity, please click the link below and enter your credentials.

Verify account now

Microsoft Security Team

Because the account had no MFA, the attacker used the harvested credentials to log in directly. Within hours, they had set up inbox rules to redirect payment confirmation emails, modified two pending wire transfers, and exfiltrated a copy of the firm’s accounts payable ledger. The breach was not detected for eleven days.

Detecting MFA Gaps with Human Risk Intelligence

Traditional security tools treat MFA as a configuration checkbox — present or absent. They do not contextualise the risk based on who the user is, what they have access to, or what other hygiene factors compound their exposure.

usecure’s Human Risk Intelligence tool continuously monitors MFA enrollment status across the Microsoft 365 and Google Workspace environments. Critically, it correlates this with the user’s Target Value score: their seniority, data access, and financial authority to surface “MFA absent on high-value account” as a critical compound risk, not merely a configuration gap. Security teams are alerted with actionable tasks that identify the specific users to remediate first.

04 · Hygiene Failure 02

Password Weakness and Credential Reuse

Despite decades of awareness campaigns, password hygiene remains one of the most persistently poor practices in enterprise environments. Employees reuse passwords across personal and professional accounts, use variations of the same base password across internal systems, and frequently allow credentials to go unrotated for months or years. The consequence is that a single breach can cascade into enterprise account compromise.

The dark web credential market has made this risk tangible and quantifiable. Billions of username-password pairs from prior breaches circulate freely, and automated tools can test them against Microsoft 365, Google Workspace, or VPN portals in minutes. Users who have reused a breached password are perpetually vulnerable until that credential is rotated, and most do not know they are exposed.

Looking ahead to 2026

Password weakness and credential reuse will continue to be amplified by AI-powered credential stuffing tools in 2026, dramatically reducing the time between a breach disclosure and a targeted attack against organizations whose employees reused those credentials.

Data breach
User registers with weak/reused password
password123
Dark web market
Stolen credentials enter the dark web market
Automated attacks test credentials at scale
Bots test billions of username-password pairs against enterprise services
Microsoft 365
Google Workspace
VPN Portal
Other Apps
Account compromised
Account compromised
Reuse once, exposed everywhere.

Illustrative Attack Scenario: Credential Reuse

The following scenario is fictional but reflects techniques commonly used by attackers.

A software company’s Senior Developer had used the same password for their corporate Microsoft 365 account and a personal project management SaaS tool. When the SaaS tool suffered a breach and credentials were published on a darknet forum, the attacker identified the employee’s corporate email through LinkedIn and attempted a credential stuffing attack.

With no MFA on the account, authentication succeeded immediately. The attacker spent three days quietly enumerating internal SharePoint sites, downloading source code repositories, and cataloguing the organization’s cloud infrastructure — all from within a legitimate, authenticated session that generated no alerts.

Detecting Credential Risk with Human Risk Intelligence

usecure’s Dark Web Monitoring Tool continuously monitors for employee email addresses appearing in known data breach databases. When a credential breach is detected, the security team will be notified. Our Human Risk Intelligence tool also displays user’s current password rotation status, MFA enrollment, and access privilege level. This helps create a comprehensive picture of the user’s risk exposure rather than generating a generic notification buried in a dashboard.

05 · Hygiene Failure 03

Dormant and Orphaned Accounts

Every time an employee leaves an organization, changes roles, or simply stops using a service, they leave behind an account. If that account is not promptly deprovisioned, it becomes a dormant attack vector — a valid, authenticated identity with no active owner to notice suspicious activity. Dormant accounts are particularly dangerous when they retain legacy privileges from a previous role, hold admin rights that were never revoked, or have credentials that have never been rotated.

Orphaned accounts — those belonging to contractors, partners, or service processes with no clear owner — present a similar risk. They often operate beneath the radar of standard HR offboarding processes and remain active indefinitely. Attackers actively seek out these accounts precisely because they are less monitored, less likely to trigger anomaly detection, and often carry permissions that were generous at the time of original provisioning.

Looking ahead to 2026

Dormant account exploitation is expected to intensify in 2026 as ongoing workforce churn and organizational restructuring continue to generate a growing inventory of inactive but still-active identities. A single dormant admin account can hand an attacker the keys to an entire Microsoft 365 tenant.

Dormant accounts
Employee leaves
Account not removed
Attacker exploits dormant account
Risks
  • Retains legacy privileges
  • No active owner to detect suspicious activity
  • Credentials may never be rotated
Orphaned accounts
Contractor / Service provisioned
No clear owner
Attacker exploits orphaned account
Risks
  • Bypass HR offboarding processes
  • Often have elevated or broad permissions
  • Fly under the radar of monitoring
No owner. No oversight. Open door.

Illustrative Attack Scenario: Dormant Account Exploitation

The following scenario is fictional but reflects techniques commonly used by attackers.

A regional logistics company had offboarded a contracted IT consultant twelve months prior, but the consultant’s Microsoft 365 account remained active, complete with Global Administrator privileges granted during an infrastructure migration project.

The contractor’s personal laptop was later compromised in an unrelated phishing attack. The attacker discovered saved credentials in the browser and used them to access the logistics company’s Azure Active Directory. Within four hours they had created two new admin accounts, reset the passwords of senior executives, and established persistent access via a registered OAuth application, all through an account that should not have existed.

Detecting Dormant Accounts with Human Risk Intelligence

The Human Risk Intelligence tool automatically surfaces accounts that have been inactive beyond configurable thresholds and correlates inactivity with privilege levels to prioritize dormant administrative accounts as critical risks. Organizations can use this data to automate access revocation workflows, transforming dormant account remediation from a manual audit exercise into a continuous security process.

06 · Hygiene Failure 04

OAuth Over-Permissioning

OAuth (Open Authorization) enables users to grant third-party applications access to their cloud accounts without sharing passwords. It is a foundational mechanism of the modern SaaS ecosystem, but also one of its most significant and least understood attack surfaces in modern cloud environments. Users routinely authorise applications with far broader permissions than necessary, often granting write access, the ability to send emails on their behalf, or even the right to consent on behalf of their entire organization.

These consent grants persist indefinitely unless explicitly revoked. An application authorised two years ago, perhaps no longer in active use, may still have full read and write access to a user’s mailbox, calendar, and files. If that application is subsequently compromised — or if a malicious application was granted consent in the first place through a phishing attack — the attacker inherits all of those permissions without needing to steal a single credential.

Looking ahead to 2026

As organizations deepen their SaaS footprint in 2026, OAuth over-permissioning will emerge as a top-tier hygiene risk. The combination of legitimate-looking consent flows and persistent token access makes this one of the hardest attack vectors for employees to recognize and for legacy tools to detect.

User consents to an app
“Contoso App” wants to access your account
Read mail
Send mail as you
Read and write files
Access all calendars
Maintain access to data you have given it access to
Accept
Broad permissions granted
App
Read & write mail
Send mail as you
Read & write files
Access calendars
Consent behalf of org
Consent persists until explicitly revoked
If the app is compromised (or malicious)
Attacker inherits all permissions — no password needed
Exfiltrate data
Send phishing
Persist at scale
Too much access for too long.

Illustrative Attack Scenario: OAuth Abuse

The following scenario is fictional but reflects techniques commonly used by attackers.

A marketing manager at a financial services firm received a calendar invite appearing to originate from a Microsoft Teams HR notification. On clicking “Join meeting,” she was redirected to a Microsoft-branded OAuth consent screen requesting permissions for an application called “Calendar Sync Pro.” The application requested access to read her email, modify her calendar, and send messages on her behalf.

Because the consent screen used genuine Microsoft branding and the request seemed consistent with a calendar sync tool, she clicked “Accept.” The attacker immediately received an access token and a refresh token, granting silent, persistent access to her inbox. Over the following three weeks, they monitored her communications, identified an upcoming wire transfer approval, and used her account to redirect the payment entirely without her knowledge.

Detecting OAuth Risks with Human Risk Intelligence

Human Risk Intelligence inventories OAuth application consents granted within the Microsoft 365 and Google Workspace environments. It flags applications that hold write-level delegated permissions, applications consented to by users who have since become inactive, and applications with no verified publisher. Security teams receive actionable tasks to audit and revoke suspicious consents grants, transforming what was previously an invisible risk into a monitored and manageable control.

07 · Hygiene Failure 05

External Mailbox Forwarding

Email forwarding rules are a legitimate productivity tool, but when they route corporate email to an external mailbox, they become a persistent and silent data exfiltration channel. External forwarding rules are routinely established by attackers who have gained temporary account access, enabling them to maintain visibility into an organization’s communications long after the initial compromise has been remediated. They are also occasionally set by employees for convenience. Forwarding corporate email to a personal account, for example, creates an unintended data leakage path.

The danger of external forwarding lies in its persistence and invisibility. Once established, a forwarding rule continues to operate silently in the background, sending copies of every incoming email to an external address. Unless an organization actively audits mailbox configurations, these rules can persist for months, even after a password reset or MFA enrollment has been completed, because forwarding rules are not credential-dependent.

Looking ahead to 2026

External mailbox forwarding will continue to be a key post-compromise persistence mechanism in 2026, particularly following Business Email Compromise attacks where attackers seek to monitor financial communications and intercept payment workflows over extended periods.

Forwarding rule created
Attacker (or user) sets forwarding rule
All incoming mail is forwarded to external mailbox
External mailbox (Attacker or personal email)
Silent, persistent data exfiltration
Inbox
(Corporate)
Copies of all incoming emails sent externally in real time
Why it’s dangerous
Works even after password reset or MFA enrollment
Persists until manually removed
Hard to see without audits
Enables long-term visibility and data loss
Once on, it keeps leaking.

Illustrative Attack Scenario: External Forwarding Abuse

The following scenario is fictional but reflects techniques commonly used by attackers.

A sales director at a professional services company had their Microsoft 365 account compromised through a credential phishing attack. The attacker, having gained access, immediately created a mailbox forwarding rule sending all inbound emails to an external address hosted on a free consumer email service.

The company’s IT team detected and remediated the phishing compromise within 48 hours, resetting the director’s password and enrolling MFA. However, the forwarding rule was not identified as part of the incident response. For the next four months, every email received by the director, including commercial proposals, contract negotiations, and pricing strategy discussions, was silently copied to the attacker’s mailbox. The breach was only discovered when a competitor appeared to have prior knowledge of a confidential bid.

Detecting External Forwarding with Human Risk Intelligence

Our Human Risk Intelligence tool continuously monitors mailbox configuration settings across the Microsoft 365 and Google Workspace environments, specifically flagging external forwarding rules established on accounts. It correlates forwarding configuration with the user’s role and seniority (an external forwarding rule on a C-suite or finance role is surfaced as a critical alert, rather than a routine configuration finding.) This transforms mailbox auditing from a periodic manual task into a continuous and automated hygiene control.

08

Defending Against Hygiene-Based Threats

The most effective defense against hygiene-based threats is continuous, automated visibility into the hygiene posture of every identity in the environment. This requires moving beyond static reports and periodic audits to a platform that monitors hygiene signals in real time, correlates them with identity context, and surfaces actionable remediation priorities.

Our Human Risk Intelligence tool provides this capability by connecting human risk signals from across the platform, combining results from security awareness training, phishing simulation, policy management and dark web monitoring, into a unified Human Risk Intelligence dashboard. It evaluates every user across target value, awareness, hygiene, and access level, and automatically identifies where individual risk factors combine into compound exposures that require immediate attention.

security awareness trainingphishing simulationpolicy managementdark web monitoring
Human Risk
Intelligence dashboard
target value
awareness
hygiene
access level

With our Human Risk Intelligence tool in place, organizations gain the intelligence they need to focus remediation where it matters most, before an attacker exploits the gaps that already exist in their environment.

Security awareness training remains a critical component of any human risk program. However, awareness alone cannot close hygiene gaps. An employee can score 100% on a phishing simulation and still have an MFA gap, a breached credential, or a dormant admin account that exposes the organization to catastrophic compromise.

09

Predictions on Cyber Hygiene for 2026 and Beyond

01
AI Will Accelerate Credential Stuffing at ScaleGenerative AI tools are already being used to automate the pairing of breached credentials with organizational identity data. In 2026, the time between a breach disclosure and a targeted attack against reusing employees will compress from weeks to hours. Organizations without continuous breach monitoring face exponentially increasing exposure.
02
MSPs Will Need Hygiene Intelligence to Retain ClientsManaged service providers that cannot articulate their clients’ hygiene posture — who has MFA gaps, which accounts are dormant, what OAuth grants are in place — will increasingly lose competitive reviews to providers who can. Hygiene intelligence will become a baseline expectation in QBR conversations, not a premium differentiator.
03
Compound Risk Will Replace Single-Risk PrioritizationSecurity teams have traditionally treated risks in isolation: a missing MFA enrollment, a breached credential, or a dormant account. However, attackers rarely exploit a single weakness. They look for combinations of weaknesses that dramatically increase the likelihood of successful compromise. Organizations will increasingly adopt risk models that identify and prioritize compound exposure, where multiple hygiene failures combine to create disproportionately higher risk.
04
Attackers Will Prioritize Persistence Over Immediate ImpactMany modern attacks are no longer focused on immediate disruption. Instead, attackers increasingly seek long-term access through mechanisms such as OAuth tokens, mailbox forwarding rules, delegated permissions, and dormant accounts. The ability to maintain silent access for weeks or months will become more valuable to attackers than rapid exploitation, making continuous hygiene monitoring essential for early detection.
05
Cyber Hygiene Will Become the Primary Attack SurfaceAs MFA adoption increases among security-conscious organizations, attackers will increasingly pivot to hygiene-based vectors — dormant accounts, OAuth abuse, and credential reuse — that bypass multi-factor controls entirely. The battle will shift from credential theft to identity exploitation.
06
Human Risk Intelligence Will Become a Core Security MetricOrganizations have long measured technical risk through vulnerability scores, patch compliance, and endpoint health. Over the next several years, human risk metrics will become equally important. Security leaders will increasingly seek to understand which employees represent the highest likelihood of compromise based on a combination of behavior, access privileges, cyber hygiene, and target value.
Glossary

Glossary

Show definitions

Human Risk Intelligence (HRI): The practice of identifying, measuring, and prioritizing human-centered cybersecurity risks by combining behavioral, identity, access, and security telemetry.

MFA (Multi-Factor Authentication): An authentication method requiring two or more verification factors before access is granted.

Credential Stuffing: An automated attack where stolen username-password combinations are tested against multiple services.

Dark Web Monitoring: The process of identifying employee credentials or organizational data exposed in criminal marketplaces and breach repositories.

OAuth: An authorization framework that enables users to grant applications access to resources without sharing passwords.

OAuth Consent: Permission granted by a user allowing an application to access specific data or services.

Delegated Permissions: Permissions that allow an application to act on behalf of a signed-in user.

Refresh Token: A credential used to obtain new access tokens without requiring the user to authenticate again.

Dormant Account: An account that remains active but has not been used for a defined period.

Orphaned Account: An account that no longer has a clearly identifiable owner.

Privileged Account: An account with elevated permissions capable of accessing sensitive systems or administrative functions.

Target Value: A measure of how attractive a user account is to attackers based on access, authority, and business impact.

Human Attack Surface: The collection of user behaviors, identities, permissions, and configurations that can be exploited by attackers.

Compound Risk: Multiple risk factors that combine to create significantly greater exposure than any single risk factor alone.

External Mailbox Forwarding: A mailbox rule that automatically forwards emails from a corporate account to an external address.

Business Email Compromise (BEC): A form of fraud in which attackers impersonate trusted individuals to manipulate financial transactions or sensitive communications.

About usecure

The Human Risk Intelligence platform built for the modern threat landscape.

usecure is a Human Risk Intelligence platform designed to help businesses reduce their human attack surface through continuous, intelligent, and measurable security awareness. Built with a managed service provider (MSP)-first approach, usecure equips security teams and their clients with the tools to simulate phishing attacks, deliver adaptive training, manage policy compliance, monitor dark web exposure, and — critically — bring all of these signals together into a single, unified Human Risk Intelligence view.

Where traditional security awareness programs stop at training completion, usecure goes further: quantifying individual risk, surfacing toxic combinations before attackers can exploit them, and turning human behavior into a manageable, reportable metric.

Protected
0+
organizations protected globally
Partners
0+
MSP partners worldwide
Recognition
#1
Human Risk Intelligence (HRI) platform
G2 Leader - Security Awareness Training ISO/IEC 27001 CertifiedISO/IEC 27001 AICPA SOC 2SOC 2 Type 2
Start managing your human risk today

3 ways to take action now

See the usecure platform in action

Book a 30-minute demo to see how Human Risk Intelligence works in practice, including real risk scores, dashboards, and automated interventions.

Book a demo

Browse the Help Centre

Explore guides, FAQs, and tutorials across uLearn, uPhish, uPolicy, uBreach, and more — all in one place at usecure’s self-serve Help Centre.

Learn more

Get in touch

Prefer to talk it through? Use the contact form and the usecure team will get back to you swiftly, or kick off a live chat if you need real-time help.

Talk to us

Attackers are already profiling your people. Every day without visibility is a day your human attack surface remains unmanaged.

Take it with you

Download the full report as a PDF

Get the complete usecure 2026 Cyber Hygiene Report to read offline or share with your team. Complete the short form and you’ll be taken straight to the download.

usecure 2026 Cyber Hygiene Report
2026 Edition
Prefer to read online? Jump back to the full report.