AACSB Event Banner

New Year, New Online Security? Why login belongs in your New Year plans

Author Rohan Whitehead - Data Training Specialist 15 January 2026
New Year, New Online Security?  Why login belongs in your New Year plans

At the Institute of Analytics we usually talk about data, models and decision making. Underneath all of that sits a simple question. Who is actually in control of your accounts? As we move into a new year and people talk about new habits and new goals, this is a good moment to look at something very basic and often ignored. The way you login.

Companies are steadily moving away from passwords as the main way to identify you. More and more services now offer two-factor authentication, multi-factor authentication and newer methods such as passkeys that use your device or a security key instead of a typed password. This is a response to a security environment where attacks are frequent, automated and increasingly sophisticated, and where a password on its own is no longer enough.

Right now, the risk is not theoretical, and it is not limited to “high value” targets. When billions of leaked passwords circulate online, attackers do not need to guess, they simply automate credential stuffing, taking known username and password pairs from one breach and testing them across thousands of other services. That works because password reuse is still common, and it turns older leaks into fresh access today, often in minutes rather than days. This is why the shift away from passwords has become urgent as we enter 2026, because the last year has not just increased the volume of exposed credentials, it has increased the speed at which they can be weaponised, especially when automation and AI are layered on top. If you take one practical action this week, it should be to treat your login methods as part of your digital identity, not as an afterthought, and the rest of this article shows exactly what to change and why it matters now.

The risk backdrop in 2025 and 2026

The numbers behind this shift are stark. One global study found that the number of breached online accounts jumped from about 730 million in 2023 to more than 5.5 billion in 2024, which works out at roughly 180 compromised accounts every second.IBM reports that the average cost of a data breach reached around 4.88 million US dollars in 2024, and while that figure eased slightly to about 4.44 million in 2025, it remains very high.Healthcare alone saw at least 133 million patient records exposed or improperly disclosed in 2023, the highest number recorded for that sector.

Ransomware has followed a similar pattern. One 2024 report recorded 5,414 publicly disclosed ransomware attacks on organisations worldwide, an increase of 11 percent on the previous year, with activity peaking in the final quarter.Another analysis found a 56 percent increase in the number of active ransomware groups in the first half of 2024.Financial tracking by Chainalysis suggests that even after some disruption, known ransomware groups still collected over 800 million dollars in ransom payments in 2024.

Looking ahead, security experts expect AI driven threats to intensify in 2026. AI is already being used to generate highly convincing phishing emails, to automate the use of leaked passwords from previous breaches and to support more targeted identity theft and account takeovers.In simple terms, attackers have more data to work with, more tools to automate attacks and more ways to turn stolen access into money.

Why this is happening

There are several reasons why the situation has become more difficult. Firstly, organisations now hold huge volumes of data across cloud platforms, on premise systems and mobile devices. Every new service, integration and device is a potential entry point for malicious activity. Secondly, criminal groups have become more organised and business-like. Ransomware is often run as a service, with developers renting out tools to affiliates who carry out the attacks and share profits. Thirdly, payment in cryptocurrencies and other channels makes it easier to receive and move funds without the same friction as traditional banking. Finally, many organisations still carry older, poorly configured systems, and many people still use weak or reused passwords, which gives attackers an easy starting point when they obtain credential dumps from one breach and try them elsewhere.

In this environment, a password is a single point of failure. Once it is known, guessed or phished, the account is effectively open if there is no second check.

How two-factor and passkeys change the picture

Two-factor (2FA) or multi-factor authentication reduces that risk by adding an extra step that proves you are really you. The usual pattern combines something you know, such as a password, with something you have, such as a phone or hardware key, or something you are, such as a fingerprint. A common example is entering a password and then confirming a prompt in an authenticator app on your phone. An attacker who only has the password cannot complete the second step, which stops many opportunistic attacks.

Adoption has grown rapidly in the past few years. Recent estimates suggest that around 78 percent of organisations worldwide report using some form of multi-factor authentication by 2024, with usage highest in large enterprises and still catching up in smaller firms. The global market for multi-factor authentication technology reached about 16.3 billion dollars in 2024 and is projected to rise above 22 billion by 2026, which reflects both wider deployment and continued investment.

Beyond 2FA, a new generation of passwordless methods is taking hold. Passkeys use cryptographic keys stored on your device or in secure hardware. When you sign in, the site and your device complete a cryptographic challenge. There is no shared secret such as a password for attackers to steal, and phishing sites cannot easily trick your device because the key is bound to the genuine domain. The FIDO Alliance reported in late 2024 that more than 15 billion online accounts can already use passkeys, more than double the number a year earlier, and that passkeys are supported on about 20 percent of the top 100 websites.

Major technology companies are moving strongly in this direction. Google, Apple and Microsoft have all committed to passkeys as a default option where possible. Research with enterprises suggests that more than 85 percent are already using or actively deploying passkeys in their workforce.Social platforms are following. Facebook, for example, began rolling out passkey support for its mobile users in 2025 to reduce phishing and password theft.For users, this often looks like a familiar action. Instead of typing a complex password, you confirm with a fingerprint, face scan or device PIN on a trusted phone or laptop.

A New Year security check for individuals

Against that backdrop, the New Year is a practical moment to treat your own security as part of your personal reset. You do not need to understand the mathematics behind cryptography to take meaningful steps. A structured review of your most important accounts is enough. That usually includes your main email account, cloud storage, online banking, primary social and professional profiles and any services that hold sensitive personal, health or financial data.

For each of these, you can check whether two-factor or multi-factor authentication is available and turn it on if it is not already. Where possible, it is better to use an authenticator app or hardware security key rather than only text messages, because phone numbers can sometimes be hijacked or redirected.If a service offers passkeys and the device you are using is private and well managed, enabling passkeys can remove the need to remember and manage a complex password for that service at all.

At the same time, it is worthwhile to think about your password habits where passwords still apply. Studies of leaked credential databases continue to show that many people reuse the same or very similar passwords across multiple sites and choose patterns that are easy to guess from personal information or common sequences.A reputable password manager can generate strong, unique passwords for each site and store them securely. When that is combined with two-factor authentication or passkeys, the chance that a single breach leads to a chain of account takeovers is much lower.

Implications for organisations and data professionals

For organisations and the data professionals within them, the logic is similar, but the stakes are higher. The rise in ransomware and data breaches is not only the result of sophisticated zero day exploits. Many attacks still begin with very simple problems such as a reused password on a remote access system, an account without multi-factor protection or an unmonitored administrator login. Multi-factor authentication and passkeys are increasingly viewed by regulators and industry bodies as basic hygiene for critical systems, rather than advanced options.

As multi-factor and passwordless methods become standard, security teams can focus more of their analytics on detecting unusual access patterns and more subtle forms of attack. Events such as repeated failed second factor attempts, new devices registering in unexpected regions and unusual patterns of passkey use can feed into monitoring systems and help identify issues before they become major incidents. Over time this combination of stronger authentication and better monitoring can reduce both the number of successful attacks and the time taken to detect and contain them. The average time to identify and contain a breach has already fallen to around 241 days in 2025, the lowest in several years, which suggests that investment in modern security controls and monitoring is starting to have an effect. However, many may argue that this value is still far too long. 

New Year, new security habits

New Year messages often focus on health, skills or productivity. There is value in adding a quieter theme for 2026. New year, new security. For most people this does not require buying new software or learning complex technical concepts. It means taking the time to turn on two-factor authentication where it matters, to accept passkeys and other passwordless options from trusted providers, and to reduce password reuse with the help of a manager. These are moderate, concrete changes that directly reduce the risk that your personal accounts, or your professional access, end up involved in the next breach or ransomware story.

From the perspective of the Institute of Analytics, this is part of responsible data practice. The more our personal and professional lives depend on digital services, the more basic choices about authentication matter. Attackers are already using data, automation and AI to increase their reach. It is reasonable for individuals and organisations to use the tools now available to defend themselves. Treating the start of the year as a checkpoint for your digital identity is one practical way to do that. The technologies behind passkeys and multi factor authentication are advancing quickly. The opportunity, as we step into 2026, is to let your habits catch up.

From big promises to clear behaviours

Most New Year goals are about outcomes. Get fitter. Learn more about data. Sleep better. Read more. These outcomes are important, but they are not actions. You cannot directly “be fitter” on a Tuesday afternoon. You can only do things that move you in that direction.

A simple shift is to rewrite each big promise as something you can see and count. “Learn data” might become “spend thirty minutes on a course three times a week and finish one small project each month”. “Get fitter” might become “walk at least six thousand steps a day on average and do two short strength sessions a week”. Now you have behaviours that either happened or did not happen. You do not need a complex system for this. You just need a clear description of what “done” means.

When you do this, you are already thinking like an analyst. You are choosing a signal for each goal, something real that you can observe again and again, instead of a slogan that changes shape in your head every time you think about it.

Choosing a small set of personal metrics

In 2026 it is easy to be flooded with information about yourself. Your phone counts steps. Your watch tracks sleep and heart rate. Apps can estimate focus time, mood and many other things. If you try to watch all of it, you will end up confused and tired. It is better to decide what really matters this year and ignore the rest.

I suggest choosing only a few personal metrics. For example one for movement, one for learning, one for relationships or social contact and one for rest. That might look like average daily steps, minutes of focused learning per week, meaningful conversations per week and hours of sleep per night. The exact choice is up to you. The key is that each metric connects directly to a behaviour you care about and you feel confident you can record it regularly.

You do not need to switch off other tracking tools, you simply decide not to pay attention to everything at once. This keeps your attention on the parts of your life that you want to shape this year.

Creating a simple way to record your data

Once you know what to track, you need one place to keep it. This should be as simple as possible. A small notebook, a basic spreadsheet or a very simple habit tracking app with adequate privacy settings is enough. The more complicated your system, the more likely you are to stop using it.

One helpful pattern is a short daily check-in. At the end of each day you can ask yourself the same few questions. Did I move as planned? Did I learn something on purpose? Did I connect with someone who is important to me? Did I sleep enough? You can record this as yes or no, or write the numbers if you have them. This usually takes less than two minutes. If you miss a day, you can fill it in the next morning from memory. What matters is consistency, not perfection.

Over time you build a simple table of days and values. It may not look impressive, but it is a real dataset about your own life, and it is specific to you.

Looking at your patterns over time

The real value appears when you look back at this data, not just when you collect it. It is natural to focus on single days. “I missed my walk, so I have failed.” Analysts know that one day is not a trend. What matters is the pattern over weeks and months.

You can calculate a rolling average for some metrics. For example, instead of looking at your step count for each day, you can look at the average of the last seven days. This smooths out random ups and downs. You can do the same for learning-minutes or sleep. Most spreadsheet tools make this easy. Even if you do not calculate anything, you can scan down the numbers and see whether they are generally going up, going down or staying flat.

It also helps to add short notes next to unusual weeks. If you were ill, travelling or under heavy pressure at work, write that down. When you look back, you will understand why your numbers changed instead of blaming yourself for every dip. This kind of context is just as important as the numbers themselves.

Trying small experiments with your habits

Sometimes you will not be sure which routine works best for you. In that case, it can help to treat your habits as experiments. Instead of deciding on one method forever, you can test two approaches for a short period and compare the results.

For example, you might try short daily learning sessions in January, then switch to longer sessions twice a week in February. In each month you keep tracking how often you actually study and how you feel about it. At the end you can compare. Did one structure lead to more completed sessions? Did one feel less stressful? This is a simple form of A B testing, applied to your own life.

You do not need complex statistics for this. You just need to be honest about what you did, look at the numbers and listen to your own experience. The point is to stop guessing and to give new ideas a fair trial instead of abandoning them after a few difficult days.

Why this matters in 2026

The answer is that the skills you use on yourself are the same skills that matter in data roles in 2026. Many tools now can write queries, draw charts and even suggest models. What remains very human is choosing what to measure, deciding how to collect it and interpreting it with judgement.

By turning your New Year goals into small, trackable behaviours, choosing a few clear metrics, recording them in a simple way and reviewing them with curiosity, you are practising exactly that kind of thinking. You are also building a healthier relationship with data. Instead of using numbers only to criticise yourself, you are using them to understand your life better and to support change that fits your reality.

As this new year begins, you do not need a complete transformation. You can keep your identity and your values and still move in a new direction by changing how you see and measure your days. Big resolutions are easy to write and easy to forget. A few clear metrics, tracked gently over time, are less exciting on the surface but far more powerful.

Share this article:

Get Involved. Lead the Future.

Join the IoA community and lead the future of data, analytics and AI.

Become a Partner

Stay Ahead with the IoA Newsletter

Subscribe for the latest updates, insights, and opportunities in data, analytics, and AI — straight to your inbox.