Employees surveyed at small and midsized businesses reported widespread unsanctioned AI use and password reuse, and 39% said their employers lacked an accurate software inventory, according to a research report by WatchGuard, a cybersecurity company focused on managed service providers (MSP).
The April online survey covered 684 employees at organizations with 50 to 500 workers in the U.S., U.K., Germany, France, Spain, Australia, Mexico and Brazil. 64% reported using unsanctioned AI tools for work, 76% reused passwords and 30% shared passwords.
The findings were self-reported, and WatchGuard did not publish country-level results, sampling details or the full questionnaire.
Managing the risks of shadow IT and AI
The survey separately measured unsanctioned AI use and software inventories but did not publish data showing how often the two findings overlapped. The National Institute of Standards and Technology’s generative AI profile recommends that organizations inventory generative AI systems, establish lists of approved generative AI providers and update acceptable-use policies for proprietary and open-source tools.
The U.K. National Cyber Security Centre defines shadow IT as business technology operating outside an organization’s asset-management and risk processes. Its guidance says unsanctioned tools often appear when approved services or internal processes do not meet employees’ working needs.
“There might not be a risk, there might be a critical risk. The organization simply doesn’t know,” the NCSC guidance says.
The agency advises organizations to identify the reasons employees adopt unofficial services rather than treating every instance as deliberate misconduct.
“Organizations are investing in security tools, but many still lack visibility into how employees actually work,” Marc Laliberte, WatchGuard’s director of security operations, said in the release. WatchGuard recommends software discovery, AI acceptable-use policies and rules governing the information employees may send to external services.
Identity gaps and evolving password standards
The survey also reported uneven adoption of multifactor authentication and password managers. Only 22% of respondents used multifactor authentication everywhere and 63% used a password manager. WatchGuard also treated infrequent password rotation as a risk, reporting that 34% changed passwords only when required.
Current NIST digital identity guidance takes a different approach. Under NIST SP 800-63B-4, verifiers and credential service providers must not require periodic password changes and must force a change when there is evidence of compromise.
The standard requires prospective passwords to be checked against commonly used, expected or compromised values, prohibits mandatory composition rules and requires verifiers to allow password managers and autofill.
Survey finds widespread public Wi-Fi use
The survey also recorded frequent use of public Wi-Fi for work. 70% reported using public Wi-Fi for work, while 50% of all respondents reported doing so without VPN protection.
The National Security Agency has warned that public wireless connections can put organizational data, credentials and devices at risk. Its guidance recommends a trusted VPN when public Wi-Fi must be used.
Connecting survey data to commercial opportunities
WatchGuard’s report directs managed service providers to turn the findings into client assessments and services covering identity, AI governance, endpoint controls and training. WatchGuard markets its cybersecurity platform to MSPs, and the report explicitly describes employee-risk data as a commercial opportunity for those providers.
Several recommended controls also appear in the NIST CSF 2.0 guide for small businesses, including software inventories, MFA, password managers, training reviews and acceptable-use policies. NIST says businesses can also use the guide as a discussion prompt with an MSSP or another provider helping them manage cybersecurity risk.
Similarly, Verizon’s 2026 Data Breach Investigations Report analyzed a broader breach dataset rather than an SMB-only sample. It found that vulnerability exploitation was the entry point in 31% of breaches, surpassing stolen credentials.