惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
V
V2EX
Cloudbric
Cloudbric
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
量子位
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
K
Kaspersky official blog
博客园 - 【当耐特】
T
Tenable Blog
L
Lohrmann on Cybersecurity
The Cloudflare Blog
S
Schneier on Security
A
Arctic Wolf
Latest news
Latest news
C
Cyber Attacks, Cyber Crime and Cyber Security
罗磊的独立博客
T
The Exploit Database - CXSecurity.com
Cisco Talos Blog
Cisco Talos Blog
小众软件
小众软件
P
Privacy & Cybersecurity Law Blog
WordPress大学
WordPress大学
Simon Willison's Weblog
Simon Willison's Weblog
雷峰网
雷峰网
NISL@THU
NISL@THU
人人都是产品经理
人人都是产品经理
月光博客
月光博客
J
Java Code Geeks
V
Visual Studio Blog
S
Security Affairs
博客园 - Franky
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
H
Heimdal Security Blog
有赞技术团队
有赞技术团队
V2EX - 技术
V2EX - 技术
AWS News Blog
AWS News Blog
G
GRAHAM CLULEY
T
Troy Hunt's Blog
SecWiki News
SecWiki News
Spread Privacy
Spread Privacy
宝玉的分享
宝玉的分享
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - 聂微东

Blog on 1Password Blog

NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password Zero knowledge vs. a malicious server: A look at ETH Zurich’s research | 1Password Agents are making filesystems cool again | 1Password Black History Month employee spotlight: Joseph Ojelade | 1Password 1Password's new benchmark teaches AI agents how not to get scammed | 1Password Streamlining SaaS onboarding and offboarding | 1Password 3 common SaaS Management challenges and how to avoid them | 1Password How 1Password Is Evolving Its Partner Ecosystem | 1Password How to build secure agent swarms that power production-grade autonomous systems | 1Password From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password Solving the unsanctioned SaaS problem | 1Password 1Password and 60 Day Hustle: cybersecurity for small businesses | 1Password Security advisory for AI-assisted browsing interactions with the 1Password browser extension | 1Password It’s incredible. It’s terrifying. It’s OpenClaw. | 1Password Managing the risks of social logins | 1Password What’s the first security tool your small business should buy? | 1Password As AI Supercharges Phishing Scams, 1Password Introduces Built-In Protection | 1Password How to interview with confidence at 1Password | 1Password Five tips for successful SaaS Management | 1Password SaaS Manager | 1Password Why SaaS License Waste Is a Cost and Security Problem | 1Password AI is changing the IDE. With 1Password, security keeps up | 1Password How IT teams can get a handle on shadow IT | 1Password Bringing secure, just-in-time secrets to Cursor with 1Password | 1Password The Chasing Entropy Podcast Season One is in the Books | 1Password Now available via QBS Software: 1Password Enterprise Password Manager – MSP Edition | 1Password The role of credentials in the AI espionage campaign reported by Anthropic | 1Password The hidden offboarding step draining your budget | 1Password AWS and 1Password: Innovation in AI and beyond | 1Password Simplifying credential security on OpenAI Atlas | 1Password From Social Work to Social Impact: Growing at 1Password | 1Password Improving in-page notifications in the 1Password browser extension | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password Now available via Renaissance: 1Password Enterprise Password Manager – MSP Edition | 1Password Behind the wheel at Oracle Red Bull Racing | 1Password Securing MCP servers with 1Password: Stop credential exposure in your agent configurations | 1Password What’s new in 1Password Enterprise Password Manager - Q4, 2025 | 1Password Belonging as a catalyst for high performance | 1Password Password habits are worsening, but leaders see a path to passwordless | 1Password A simpler, faster way to unlock 1Password | 1Password Oracle Red Bull Racing Episode 4, CIO Matt Cadieux | 1Password 70% of IT and security pros say SSO is falling short | 1Password 1Password's Phishing Survey: Avoid Holiday Phishing Scams | 1Password Securing the Win | 1Password SaaS optimization: How to maximize value and reduce costs | 1Password The enterprise AI crisis: Unsanctioned tools and unenforced policies | 1Password An Identity Security taxonomy for Agentic AI | 1Password Introducing new .env file support in 1Password environments | 1Password Speed and security: Mark Hazelton on protecting Oracle Red Bull Racing’s most valuable asset – its data | 1Password 1Password for Good: Giving back during cybersecurity awareness month | 1Password Utah Mammoth and Utah Jazz score with identity security | 1Password Oracle Red Bull Racing CEO and Team Principal | 1Password Three signs you need a SaaS Management Platform | 1Password Closing the credential risk gap for AI agents using a browser | 1Password Microsoft and Dropbox password managers are sunsetting: What it means and what to do next | 1Password From hackathon nerves to internship wins: Kavya’s journey at 1Password | 1Password 1Password now available in Comet, the AI-powered browser by Perplexity | 1Password 1Password announces new integration with Zscaler | 1Password Breaking the mold: Why more women should consider a career in sales | 1Password What security leaders need to know about mergers and acquisitions | 1Password Clickjacking: What it means for 1Password users | 1Password AI and security at Black Hat: 5 key takeaways from a security expert panel | 1Password Blog | 1Password Do any CISOs feel lucky? | 1Password How to lead with confidence in the AI era: a conversation with Nancy Wang, VP, Engineering | 1Password New Device Trust Check makes browser extension enforcement easier | 1Password Purpose, performance, and trust: Inside the culture powering 1Password’s next chapter | 1Password Now available on Pax8 Marketplace: 1Password Enterprise Password Manager - MSP Edition | 1Password The security principles guiding 1Password’s approach to AI | 1Password Choosing the right SaaS management platform for your business | 1Password Simplify access reviews with 1Password SaaS Manager | 1Password How great usability tripled Duke University's password manager adoption | 1Password
Password Manager for Families, Enterprise & Business | 1Password | 1Password
info@1passwo · 2026-06-16 · via Blog on 1Password Blog

One of the less surprising findings of the 2026 Verizon Data Breach Incident Report (DBIR) is the fact that incidents targeting the Financial and Insurance sector are on the rise. As they put it, “This sector continues to be a favorite among attackers, which isn’t surprising given that its core business is handling money.”

For small-to-medium businesses (SMBs) in the financial services sector, the DBIR paints an even more dire picture. The report notes that SMBs face the same threats and breach patterns of larger organizations, but are also disproportionately impacted by attacks; 96% of ransomware victims were SMBs. 

In short: businesses in the financial services industry who are still building their foundation, or who possess limited security resources, are caught between a rock and a hard place. They operate within one of the most heavily targeted sectors for cyberattack, and are held to enterprise-level security standards by regulators and clients alike, but they’re operating with startup-level security resources. 

For lean security and IT teams to make the most of those limited resources, they need to focus on what they can afford. That means getting the fundamentals right for a strong and impactful security foundation. The highest-leverage fundamental is, of course, credential management.

Top security challenges for financial services organizations

Small IT and security teams in the financial services industry are faced with high expectations when it comes to security. Unfortunately, they also experience significant challenges when it comes to securing credentials.

AI is accelerating SaaS and credential sprawl

JP Morgan Chase’s recent research report, Understanding the use of AI among small businesses, finds that not only are a growing number of small businesses adopting AI, when they do, they also tend to implement a greater number and variety of AI tools.

It’s not hard to understand why this is the case; AI’s ability to automate processes and improve productivity is a natural fit for lean teams, trying to maximize impact with limited resources. However, AI tools and agents are also accelerating the rate of SaaS sprawl, shadow IT, and policy violations. One in four employees has used AI applications that weren’t approved by their company, and over a third of employees admit to having knowingly disregarded their company’s AI policies. 

AI is also increasing the sophistication of attacks. Attackers are able to move faster, and are particularly able to generate more convincing phishing attacks. Unfortunately, phishing-resistant authentication factors are hard to deploy at scale. As RSM reported, “Many middle market and smaller financial services organizations lag their larger counterparts in this area.” 

AI use can also drastically accelerate credential risks, as AI tools and agents interface with credentials and developer secrets at a scale far beyond what traditional identity and access management (IAM) systems were designed to govern.

Complex compliance standards

Cybersecurity compliance represents one of the greatest challenges for businesses of all sizes in the financial services industry. SOC 2, GLBA, and PCI DSS are just a few of the compliance standards with strict guidelines designed to protect financial information. 

These standards exist with good reason; when financial data is compromised, the consequences can be dire for companies and users alike. Still, the complex and varied legal and compliance standards that financial service providers have to meet can be daunting, to say the least, particularly when access is distributed across a growing sprawl of unmanaged apps and credentials.

For instance, to meet standards like GLBA, HIPAA, and PCI DSS, teams have to be able to prove to an auditor that every system or app that interacts with protected data is being guarded by strong credentials and other authentication factors. 

Unfortunately, 1Password’s 2025 annual report found that two-thirds of employees admit to engaging in poor password practices, including:

  • Using the same passwords across multiple work accounts

  • Never changing IT-default passwords

  • Using the same password for both work and personal accounts

  • Texting, emailing, or otherwise messaging passwords to yourself or a colleague

Each of these practices fly in the face of compliance guidelines. Unfortunately, scattered security tooling and unmanaged sprawl can make it difficult to enforce policies around password use, leaving access records fragmented at best, or non-existent at worst. 

All of this can make it difficult to prove compliance to the satisfaction of an auditor, and compliance failures can represent significant costs. A survey in 2026 found that 25% of small business owners stated that they had received a compliance-related fine or citation. As they reported, “Most penalties totaled between $2,000 and $10,000…” 

The cost alone is a serious detriment, but the report goes on to point out that these failures represent further disruptions for small teams. “Beyond paying fines, businesses also had to modify internal processes, update documentation practices, or implement new tracking systems to prevent repeat violations.”

Insider threats are a major concern

Smaller IT teams often have limited time to ensure that every new employee is given the right level of access according to their role, and to ensure that every departed employee is properly offboarded from systems. This can leave lingering credentials with over-privileged access to sensitive data.

Over one-third of employees have successfully accessed a prior employer’s account, data, or applications after leaving the company. The insider threats posed by this statistic should be of particular concern to financial services institutions. 

In 2024, more than 70 percent of financial institutions experienced insider threat incidents that year, referring to both deliberate actions and inadvertent errors. In 2026, misconfiguration or human error was the leading cause of breaches for those organizations. 

AI’s difficulties are accelerating these kinds of errors as well, but the more significant issue is that for businesses that are still building their security foundation, access controls are often informal, and employee lifecycle processes are inconsistent or overly manual.

Traditional security tools can’t serve the needs of growing businesses

Unfortunately, traditional security tools are often unsuited to meeting the needs of growing businesses, particularly those with strict compliance requirements. For instance, when teams think of securing access, single sign-on (SSO) is one of the first solutions that come to mind. Unfortunately, SSO also leaves serious gaps in oversight; 1Password’s recent annual report found that the average company has a third of its apps outside SSO. 

For smaller companies, or those with otherwise limited resources, SSO is likely to leave even more oversight gaps. The infamous “SSO Tax” means that for an application to be guarded behind SSO, app providers often force customers to upgrade to an “enterprise tier.” 

Not only does the enterprise tier tend to cost exponentially more per user than the basic tier, it may require a minimum number of users for the plan. Even if an SMB has the budget to put a given app behind SSO, they may not have enough users to.

SSO is just one example of how traditional security tooling falls short of meeting the needs of SMBs, leaving significant gaps in a team’s app and credential oversight. This lack of resources can often result in a scattered approach to credential management, where credentials are stored in spreadsheets, shared over email, or saved within consumer browsers

This level of credential sprawl is overwhelming and costly, compromising compliance efforts while drastically increasing a company’s attack surface. But if a business is hit by a breach, the financial losses can quickly reach the millions, leaving teams caught in a dilemma between costly security versus costly risks.

How credential management helps meet financial compliance requirements

An enterprise password manager (EPM) like 1Password’s is one of the most effective and efficient security tools that any business can implement. An EPM centralizes visibility into how and where credentials are used, enabling secure sharing and access that can be granted and revoked as needed. 1Password EPM enables IT and security teams to organize credentials into vaults and provision or revoke vault access according to employee roles and access needs. This benefits both security and productivity; after all, autofilling passwords from a shared vault tends to be easier than searching for them through a spreadsheet.

1Password utilizes zero-knowledge encryption, meaning that not even the company that’s storing credential data can access or decrypt it. This keeps information protected at the highest level, so credentials stay secure even if the server where they’re held ever gets breached. 1Password's breach monitoring also informs users and admins if a managed credential has been compromised in a breach (since re-use of compromised credentials is a major attack vector).

Most significantly, 1Password provides automated and detailed logs of app sign-ins and other events, ensuring that small teams in the financial services industry are set up for success when it comes time for an audit.

In short: the credentials to every workplace app stay secured and centralized where IT can easily oversee employee access and measure the strength and security of their password ecosystem. It’s a tool that works with small teams, empowering them to use the tools they need without putting sensitive data at risk.

Learn more

Do you have twenty minutes and want to learn more? Try out 1Password’s on-demand demo, or look through our “Secure in 20” series for quick and informative sessions on security for modern teams.