RSA: Despite a Year of Breaches, Consumers’ Security Behaviors Unchanged
New Report Highlights Attitudes Toward Online Shopping and Mobile Security
- Consumer online security study surveys more than 1000 consumers in the United States
- Nearly 50% have been a victim of a data breach
- 45% say even with all of the retail breaches, they have not changed their behavior when using credit and debit cards
- 69% admit to using the same password for more than one device or website
- 77% do not trust the security of mobile apps
Today, RSA, The Security Division of EMC (NYSE: EMC), released the results of a new survey in conjunction with the Ponemon Institute highlighting consumer attitudes toward online security. Surveying more than 1,000 consumers in the United States, the survey found that nearly half of respondents had fallen victim to at least one data breach and 45% say they are not confident they know all instances of when their personal information has been leaked. As such, many of the respondents have showcased a boosted concern around security driven by the increase in mobile and the prevalence of data breaches. However, despite growing concerns, in many cases behaviors toward security have not changed.
Long Live (Secure) Online Shopping
Despite a year of major retail breaches, there is an inclination to increase online behaviors that have proven risky, like online shopping, and an overwhelming unwillingness to change risky behavior. Forty-eight percent admit to online shopping on a weekly basis, and while respondents rated security expectations high for activities like online banking and mobile transactions, security expectations for online shopping were shockingly low. Even with expectations being low, so many being personally affected by data breaches, and the wave of retail data breaches involving payment card information, 45% of the respondents say that it has no effect on their use of credit or debit cards.
Is Mobile Security a Weak Link?
According to RSA’s Anti-Fraud Command Center, during the first six months of 2014, 33% of banking transactions originated in the mobile channel, which marks an increase of 20% from 2013 and a 67% increase from 2012. One out of four fraud transactions originated in the mobile channel – showing a significant increase in mobile fraud. Of all of the online activities measured in the Ponemon survey, making mobile payments ranked highest on the list in terms of expectations of security, yet 77% admit to not trusting the security of mobile apps and only 35% say that they always read permissions of apps being downloaded.
Welcome Next Generation Authentication
It comes as no surprise that weak authentication is still an issue among most consumers, with 62% expressing a lack of trust in websites that only require a username and password at login. While seventy-one percent of respondents say they are most concerned about losing their password in a data breach, nearly a third admits to only having one to two passwords for all online accounts; 69% admit to using the same password for more than one device or site; and only 54% say that they regularly change their passwords. When questioned about preferred authentication methods, a majority of respondents cited software tokens and/or biometrics (voice and fingerprint verification) as the ideal ways to manage identities.
RSA EXECUTIVE QUOTE:
Brian Fitzgerald, Vice President, Marketing
“As the capabilities and convenience of the Internet continue to grow, so does consumer security concerns. The results of the Ponemon Study show that while these concerns are top of mind, behaviors and attitudes of consumers are not changing. It is incumbent upon the industry, to deliver on promises of strong and convenient security methods to help customers take advantage of the Internet while significantly limiting the risk of threats – both simple and sophisticated.”
- Download the eBook highlighting key consumer attitudes and behaviors towards online security from the report
- Download an infographic that provides survey highlights on consumers’ security concerns and behaviors
- View the October RSA Monthly Online Fraud Report for the latest trends in e-commerce fraud
- Join the webcast titled The Impact of Data Breaches on Consumers
- Check out Speaking of Security blog featuring Rueben Rodriguez and join the conversation
EMC Corporation (NYSE: EMC) is a global leader in enabling businesses and service providers to transform their operations and deliver IT as a service. Fundamental to this transformation is cloud computing. Through innovative products and services, EMC accelerates the journey to cloud computing, helping IT departments to store, manage, protect and analyze their most valuable asset — information — in a more agile, trusted and cost-efficient way. Additional information about EMC can be found at www.EMC.com.
RSA’s Intelligence Driven Security solutions help organizations reduce the risks of operating in a digital world. Through visibility, analysis, and action, RSA solutions give customers the ability to detect, investigate and respond to advanced threats; confirm and manage identities; and ultimately, prevent IP theft, fraud and cybercrime. For more information, please visit www.rsa.com.
RSA and EMC are either registered trademarks or trademarks of EMC Corporation in the United States and/or other countries. All other products and/or services referenced are trademarks of their respective companies.