Study Shows Employees are Putting Their Companies at Risk

Study Shows Employees are Putting Their Companies at Risk

A recent study by CompTIA, Cyber Secure: A Look at Employee Cybersecurity Habits in the Workplace, shows that the majority of employees are unaware of how their poor security habits could leave their organizations vulnerable to major cybersecurity breaches, despite the fact that major corporations have lost millions dealing with hacker situations.

The study shows the growing gap between the amount of cybersecurity attacks and the number of employees who are trained to be highly aware of cyber threats when dealing with company devices, accounts and information.

Many organizations give their employees laptops, tablets or smartphones to work with during their time with the company. While these devices are intended for company use, nearly two-thirds of the surveyed employees admitted to using their company-assigned devices at home for personal use. Every time an employee signs into a personal account such as email, social media, entertainment platforms, etc., they open their device up to potential security threats.

Employees have also admitted to using the same, unoriginal and predictable passwords for both their personal accounts and corporate accounts. They have also admitted to sharing personal information online, such as their full name, email addresses and birth date, in exchange for “more information” or to register for a social media, entertainment or online shopping account. These questions are sometimes clues as to what a user would choose their password to be.

Perhaps the most startling find of the study deals with employees and their care-free use of USB drives. In recent years, some of the most prominent cybersecurity incidents have included USB viruses. They were popularized by “Stuxnet,” the infamous worm which the U.S. and Israel supposedly used to infiltrate Iranian nuclear centrifuges in 2010. Since then, many more attacks have included USB sticks programmed with malware that can quickly infect devices and critical infrastructure.

Even though the USB threats have been all over the news, a social experiment commissioned by CompTIA sought out to find out just how many people would trust a random USB stick. From August to October, they dropped 200 USB sticks in highly public places like airports and coffee houses in populated cities such as, Chicago, Cleveland, San Francisco and Washington D.C. The sticks were programmed to take the user to a text file with directions to a link that could be tracked or an alias email address to contact.

After only a few weeks, 17% of the USB sticks were picked up, plugged in and the user followed the directions of the text file. While the study cannot show how many people plugged the USB into their device without clicking on the link, it does show that a good percentage of people will jeopardize their devices based on curiosity. In a handful of the emails received, some asked if a virus was present on the USB, showing that some understood the risks of plugging a random USB into their computer.

The study also polled employees on what they most associated “cybersecurity” with, offering a glimpse into what risks and threats they fear most. The majority (36%), said they associate “identity theft” with cybersecurity while others listed, “hacker” or “malware.” They were also asked what they would do in the event of a breach. While 35 percent of employees said they would change their all of their account login credentials, 20 percent said they would only change the password information on the hacked account. Thirty three percent said they wouldn’t personally do anything, but they would contact their companies IT department. Four percent said they would contact the police.

These findings have brought to light the poor security hygiene of the common employee in this digital era. It shows that the majority of our workforce has not been given proper training to combat a cyber threat. The majority of workers surveyed stated that their organization doesn’t provide any form of cybersecurity education or communicate the best end-user practices.  Those that do administer training, rely on a mixture of online and in-person learning formats.

As a way to combat the lack of cybersecurity education, CompTIA has announced new programs aimed at raising awareness in the workplace, on the road and at home. Visit www.comptia.org for more information on these programs and remember to ask yourself, “Am I being cyber smart?”

Featured

  • Securing the Future

    Two security experts sit down with Security Today’s editor in chief Ralph C. Jensen to discuss what they see emerging and changing over the next several years along with how security stakeholders can harness these innovations into opportunities. Read Now

  • Collaboration Made Easy Using a Work Management Platform

    Effective collaboration between security operators, teams and other departments is critical to the smooth functioning of organizations. Yet, as organizations grow in complexity, it becomes more difficult for teams to coordinate with each other. This is compounded by staffing shortages, turnover and ineffective collaboration tools. Read Now

  • Creating a Safer World

    Managing and supporting locks and door hardware within a facility is a big responsibility. A building’s security needs to change over time as occupancy and use demands evolve, which can make it even more challenging. Read Now

  • Report: 78 Percent of CISOs Seeing Significant Impact from AI-Powered Cyber Threats

    Darktrace recently unveiled its 2025 State of AI Cybersecurity report. The findings reveal that 78% of Chief Information Security Officers (CISOs) surveyed say that AI-powered threats are having a significant impact on their organizations, a 5% increase1 from 2024. While an increasing number of CISOs report feeling a significant impact from AI threats, more than 60% now say that they are adequately prepared to defend against these threats, an increase of nearly 15% year-over-year. However, insufficient AI knowledge and skills and a shortage of personnel and talent continue to be listed as the two top inhibitors to a successful defense. Read Now

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.