Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Tenable Study Finds Many Consumers Fail To Practice Basic Cyber Hygiene
Study & Research

Tenable Study Finds Many Consumers Fail To Practice Basic Cyber Hygiene

ISBuzz TeamBy ISBuzz TeamJanuary 5, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Consumers acknowledge risks in the breach era but do not take important steps to protect their data and identities

COLUMBIA, Md., A study conducted online by Harris Poll, on behalf of Tenable™,Inc., the Cyber Exposure company, has found that many consumers fail to practice basic security cyber hygiene. While nearly all Americans (94 percent) were aware of news stories about security breaches in the past 12 months, few have taken critical steps to protect their data or changed their online habits. The study, conducted among over 2,000 U.S. adults found 44 percent of Americans did not use a password to protect their personal information on their computer in the past 12 months, and 55 percent failed to use a PIN to protect their personal information on their mobile devices. When it comes to the industry recommended practice of two-factor authentication, a staggering 75 percent of Americans revealed they had not implemented this feature to protect their personal information on their devices. Just 32 percent of Americans who have heard of any news stories about security breaches in the past 12 months say they reduced their use of public Wi-Fi or unknown hotspots as a result. There were some positives as over half of Americans (53 percent) confirmed that they had made their account passwords more complicated, and 15 percent have  used a password management tool to protect their personal information in the past 12 months.

“Given the recent slew of data breaches you’d expect consumers to be more aware of security incidents and potentially to have changed their habits. However, this study found quite the reverse. While nearly all the respondents were aware of recent breaches, among them almost half (43 percent) confessed they’d not changed their online habits as a result. Another surprising figure was that only 19 percent of Americans said they’d utilized biometric security options on their devices in the past 12 months, which is unexpected given Apple introduced the use of a thumbprint as a security measure in 2013,” said Amit Yoran, CEO of Tenable. “This all indicates that many consumers still fail to comprehend the role they play in accountability when it comes to taking specific actions to safeguard their own personal data. It’s basic cyber security illiteracy.”

Only 12 percent of Americans said they believed that their personal information had been stolen by hackers due to a security breach in the past 12 months. Given the Equifax breach alone exposed the sensitive data of as many as 143 million Americans, that number is statistically impossible. Add to this the Yahoo! breach and countless others, the results of this study suggest an alarming lack of understanding about the pervasiveness of recent breaches and the risks they pose. In fact, 37 percent of Americans think it’s likely their personal information will be stolen as a result of a security breach in the next six months.

Focusing on where perceived risks lie, 63 percent of Americans said they were worried that their data may be stolen when connecting to public or unknown Wi-Fi/hotspots. Fifty-eight percent are worried that their personal information may be stolen when online shopping, while half are worried when banking online, and only 35 percent are concerned when connecting with their friends/family through social media.

A popular inroad for hackers to compromise devices and steal data is when apps have security vulnerabilities, yet few people patch promptly. Fourteen percent of smartphone users wait more than a week to update apps on their smartphone after receiving a prompt, including 5 percent confessing they never get around to it. Meanwhile, 13 percent of computer users wait more than a week to update the apps on their computer, with 3 percent who wait longer than a month after receiving a prompt, and 5 percent who never update apps on their computer.

“The irony is that cyber poses an existential threat to our economy and to our very social fabric and safeguarding ourselves is therefore a shared responsibility,” Yoran said. “Enterprises must lead the way by practicing fundamental hygiene and enforcing a basic standard of care for their customers’ data; but individuals must do their part, too — both as consumers and in many cases, as employees of those same enterprises — and that starts with cyber literacy.”

Tenable’s Consumer Security Checklist:

  1. Where applicable, enable two-factor authentication for all online services.
  2. Update your apps and computers within 24 hours of receiving a notification.
  3. Assign strong passwords to your computer, mobile phone and tablet and don’t share them with others.

“Organizations need to lead the way in basic security practices that keep their customer and critical business data safe. It seems there is a need for a ‘top down’ approach where organizations provide comprehensive cybersecurity but also team up with customers and employees to educate them about what they can do extend their best practices across their own personal attack surface,” said Yoran. “This starts with companies being more transparent about their own security practices and holding themselves accountable for lapses. If they don’t make security a top business priority and they aren’t sensitive to these changing consumer patterns and needs, they risk losing customers. Today, being customer-focused isn’t just about making good products; it’s about listening to customers and making sure the products and services they are using don’t cause them harm.”

[su_box title=”About Tenable Network Security” style=”noise” box_color=”#336588″][short_info id=’61021′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}