Endpoint //

Privacy

10/15/2018
12:40 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

3 Out of 4 Employees Pose a Security Risk

New MediaPRO study also finds that management performed worse than entry- and mid-level employees in how to handle a suspected phishing email.

Despite concerted efforts by many US organizations to improve security awareness among users, a new study shows they still have a long way to go.

Some 75% of respondents today pose a moderate or severe risk to their company’s data, according to MediaPRO's third annual State of Privacy and Security Awareness Report, and 85% of finance workers show some lack of data security and privacy knowledge.

Tom Pendergast, chief security and privacy strategist at security awareness and training provider MediaPRO, says the firm surveyed more than 1,000 employees across the United States to quantify the state of privacy and security awareness in 2018. More people fell into the risk category this year than in 2017 – and that number had nearly doubled since the inaugural survey, he says.

"The overall results revealed a trend we weren't happy to see, that employees performed worse across the board compared to the previous year," Pendergast says. "While I think there's a certain amount of security fatigue from news of all the attacks, if in five years I don't see significant change I will be surprised. There's both a cultural a business awareness of the need to do good work in this area."

MediaPRO based its study on a variety of questions that focus on real-world scenarios, such as correctly identifying personal information, logging on to public Wi-Fi networks, and spotting phishing emails. Based on the percentage of privacy and security-aware behaviors, respondents were assigned to one of three risk profiles: risk, novice, or hero.

Here's a thumbnail of some other notable findings:

1. Employee performance was worse this year across all eight industry verticals measured. Respondents did much worse in identifying malware warning signs, knowing how to spot a phishing email and social media safety.

2. Managers showed riskier behaviors than lower-level employees. Management performed worse than their entry- and mid-level counterparts when asked how to respond to a suspected phishing email. Only 69% of managers chose the correct answer vs. 86% of lower-level employees. And nearly one in six management-level respondents – 17% - chose to open an unexpected attachment connected to a suspected phishing email.

3. Finance sector employees performed the worst. Of the seven vertical industry sectors examined, financial employees got the lowest scores. 85% showed some lack of cybersecurity and data privacy knowledge. And, 19% of finance workers thought opening an attachment was an appropriate response to a suspected phishing email.

4. Too many employees could not identity phishing emails. 14% of employees could not identity a phish, a notable increase from 8% in 2017. And, 58% could not define business email compromise. 

"We do need to train people people because it lets us reduce the number of incidents," says Frank Dickson, an IDC analyst who covers security. "But it's also the responsibility of the organization to provide the tools to stop these attacks. The organization needs to own this because it's a problem we've had for a long time."

Pendergast says most concerning to him was that some survey takers did not always know how to respond properly to a suspected phishing attempt. For example, when asked how to correctly respond to a phishing email, 10% say they would open the content to verify it contents; and another 8% say they would click on a link to verify the legitimacy of the website it leads to.

While 81% say they would report the suspected phishing email to their IT department – the correct response – Pendergast says those numbers are alarming given that that attackers only need one mistake to be successful.

"It only takes one person to click on the wrong email that lets in the malware that exfiltrates your company’s data," Pendergast says. "Without everybody being more vigilant, people and company data will continue to be at risk."

 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
CallumLepide
50%
50%
CallumLepide,
User Rank: Apprentice
10/16/2018 | 9:35:52 AM
Spot on
I could not agree more
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
How Well Is Your Organization Investing Its Cybersecurity Dollars?
Jack Jones, Chairman, FAIR Institute,  12/11/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15328
PUBLISHED: 2018-12-12
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear ...
CVE-2018-17949
PUBLISHED: 2018-12-12
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
CVE-2018-17950
PUBLISHED: 2018-12-12
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
CVE-2018-17952
PUBLISHED: 2018-12-12
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
CVE-2018-16867
PUBLISHED: 2018-12-12
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may l...