Study Shows Employees are Putting Their Companies at Risk

Study Shows Employees are Putting Their Companies at Risk

A recent study by CompTIA, Cyber Secure: A Look at Employee Cybersecurity Habits in the Workplace, shows that the majority of employees are unaware of how their poor security habits could leave their organizations vulnerable to major cybersecurity breaches, despite the fact that major corporations have lost millions dealing with hacker situations.

The study shows the growing gap between the amount of cybersecurity attacks and the number of employees who are trained to be highly aware of cyber threats when dealing with company devices, accounts and information.

Many organizations give their employees laptops, tablets or smartphones to work with during their time with the company. While these devices are intended for company use, nearly two-thirds of the surveyed employees admitted to using their company-assigned devices at home for personal use. Every time an employee signs into a personal account such as email, social media, entertainment platforms, etc., they open their device up to potential security threats.

Employees have also admitted to using the same, unoriginal and predictable passwords for both their personal accounts and corporate accounts. They have also admitted to sharing personal information online, such as their full name, email addresses and birth date, in exchange for “more information” or to register for a social media, entertainment or online shopping account. These questions are sometimes clues as to what a user would choose their password to be.

Perhaps the most startling find of the study deals with employees and their care-free use of USB drives. In recent years, some of the most prominent cybersecurity incidents have included USB viruses. They were popularized by “Stuxnet,” the infamous worm which the U.S. and Israel supposedly used to infiltrate Iranian nuclear centrifuges in 2010. Since then, many more attacks have included USB sticks programmed with malware that can quickly infect devices and critical infrastructure.

Even though the USB threats have been all over the news, a social experiment commissioned by CompTIA sought out to find out just how many people would trust a random USB stick. From August to October, they dropped 200 USB sticks in highly public places like airports and coffee houses in populated cities such as, Chicago, Cleveland, San Francisco and Washington D.C. The sticks were programmed to take the user to a text file with directions to a link that could be tracked or an alias email address to contact.

After only a few weeks, 17% of the USB sticks were picked up, plugged in and the user followed the directions of the text file. While the study cannot show how many people plugged the USB into their device without clicking on the link, it does show that a good percentage of people will jeopardize their devices based on curiosity. In a handful of the emails received, some asked if a virus was present on the USB, showing that some understood the risks of plugging a random USB into their computer.

The study also polled employees on what they most associated “cybersecurity” with, offering a glimpse into what risks and threats they fear most. The majority (36%), said they associate “identity theft” with cybersecurity while others listed, “hacker” or “malware.” They were also asked what they would do in the event of a breach. While 35 percent of employees said they would change their all of their account login credentials, 20 percent said they would only change the password information on the hacked account. Thirty three percent said they wouldn’t personally do anything, but they would contact their companies IT department. Four percent said they would contact the police.

These findings have brought to light the poor security hygiene of the common employee in this digital era. It shows that the majority of our workforce has not been given proper training to combat a cyber threat. The majority of workers surveyed stated that their organization doesn’t provide any form of cybersecurity education or communicate the best end-user practices.  Those that do administer training, rely on a mixture of online and in-person learning formats.

As a way to combat the lack of cybersecurity education, CompTIA has announced new programs aimed at raising awareness in the workplace, on the road and at home. Visit www.comptia.org for more information on these programs and remember to ask yourself, “Am I being cyber smart?”

Featured

  • It Always Rains in Florida

    Over the years, and many trips to various cities, I have experienced some of the craziest memorable things. One thing I always count on when going to Orlando is a massive rainstorm after the tradeshow has concluded the first day. Count on it, it is going to rain Monday evening. Expect that it will be a gully washer. Read Now

    • Industry Events
  • Live from GSX 2024 Preview

    It’s hard to believe, but GSX 2024 is almost here. This year’s show runs from Monday, September 23 to Wednesday, September 25 at the Orange County Convention Center in Orlando, Fla. The Campus Security Today and Security Today staff will be on hand to provide live updates about the security industry’s latest innovations, trends, and products. Whether you’re attending the show or keeping tabs on it from afar, we’ve got you covered. Make sure to follow the Live from GSX page for photos, videos, interviews, product demonstrations, announcements, commentary, and more from the heart of the show floor! Read Now

    • Industry Events
  • Elevate Your Business

    In today’s dynamic business environment, companies specializing in physical security are constantly evolving to remain competitive. One strategic shift these businesses can make to give them the advantage is a full or partial transition to a recurring revenue model, popularly called a subscription service. This approach will bring numerous benefits that not only enhance business stability but also improve customer relationships and drive innovation. Recurring monthly revenue (RMR) or recurring annual revenue (RAR) are two recurring cadence choices that work simply and effectively. Read Now

  • Playing a Crucial Role

    Physical security technology plays a crucial role in detecting and preventing insider cybersecurity threats. While it might seem like a stretch to connect physical security with cyber threats, the two are closely intertwined. Here’s how physical security technology can be leveraged to address both external and internal threats. Read Now

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3