Survey: Employees Will Shop Less Online But Take Bigger Risks During Holiday Season

Employees in the United States plan to spend less time shopping online from a work-supplied computer this holiday season than they did a year ago, but more of them are engaging in risky online behavior, according to the third annual “Shopping on the Job: ISACA’s Online Holiday Shopping and Workplace Internet Safety Survey.”

Employees are expecting to spend an average of 6 hours shopping from a work computer or mobile device this holiday season vs. 14 hours in 2009, with 20 percent planning to spend 9 hours or more. But, there is an increase this year in the number of employees who take risky actions online, such as clicking on an e-mail link or providing their work e-mail address when shopping online, and 42 percent report accessing social network sites from their work-supplied computer or mobile device.

“Employees who shop online reduce productivity -- especially from Black Friday through mid-December, when 71 percent of them make their holiday purchases -- and open the door to social engineering and phishing attacks, malware, and information breaches that can cost companies millions and inflict severe damage to their reputation,” said John Pironti, CISA, CISM, CGEIT, CRISC, security advisor with ISACA and president of IP Architects, LLC.

This year’s survey also found that almost half (47 percent) of those who will shop online with company devices will do so using a portable device, such as a notebook computer, tablet or smart phone. This increases a company’s security risk because these devices are often used on wireless networks outside of a protected corporate network. They also are more easily lost or stolen, and contain corporate data that are typically not encrypted.

“The number of portable computers and mobile devices in the workplace is increasing, so companies need to create realistic security policies that let employees stay mobile without compromising the company’s intellectual property. To balance productivity and security, the IT mantra should be embrace and educate,” said Mark Lobel, CISA, CISM, mobile security project leader with ISACA and a principal at PricewaterhouseCoopers.

Employees say the top three reasons for shopping online at work are that it is a convenient use of lunch/break time (38 percent), they are working long hours and don’t have time to shop from home (17 percent) and they are bored at work (11 percent).

Security is not a major worry for survey participants, with only 3 percent citing “better security” as a reason for shopping using a work computer. Under two-thirds do not use secure browsing technology on work-supplied devices. Forty-one percent assume their IT department updates their security patches.

This attitude is especially common among digital natives, who have grown up with the Internet. Young adults (ages 18-34) in the survey are the most likely to shop online using work-supplied computers or mobile devices and are more inclined to use their personal computers for business.

“Digital natives are comfortable with blurring the lines between work and play, which poses new challenges for their employers,” noted Robert Stroud, CGEIT, international vice president of ISACA and service management and governance evangelist at CA Technologies. “This generation is happy to use their own computer at work or use a work-supplied smart phone for shopping or social networking, so they need a new kind of IT security policy that balances access and control.”

A separate global survey of 837 U.S. business and information technology (IT) professionals who are members of ISACA, conducted during the same time period, shows that two-thirds of respondents believe their organization loses $1,000 or more per employee as a result of an employee shopping online during work hours in November and December. Approximately one-third put the number at $15,000 or higher.

For mobile devices, an overwhelming majority (85 percent) ranked the risk of using a mobile shopping app on a work-supplied device as high or moderate. Despite that, 43 percent allow employees to use work-supplied mobile devices for personal use and 45 percent let employees use their own mobile devices for work.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3