News: 1666197910

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Millennials, Gen Z actually suck at workplace security

(2022/10/19)


It's just as you suspected: your Gen Z and millennial coworkers just aren't taking cybersecurity at work seriously enough.

Professional services firm EY made that determination after speaking to 1,000 US workers whose current job requires the use of a work-issued laptop/computer a majority of the time. While 83 percent of respondents said they understood their employer's security protocols, [1]the data points to a disconnect between understanding and implementation.

According to EY's findings, 58 percent of Gen Z and 42 percent of millennial respondents said they disregard mandatory IT updates for as long as possible, something only 15 percent of boomers and 31 percent of Gen X admitted to.

[2]

Roughly one-third of Gen Z and millennials said they reuse passwords between personal and business accounts, something that less than a quarter of older respondents cop to, while nearly a half of Gen Z and millennials were "likely to accept web browser cookies on their work-issued devices all the time or often," which 31 percent of Gen X and 18 percent of baby boomer respondents also do.

[3]

[4]

"There is an immediate need for organizations to restructure their security strategy with human behavior at the core," said EY America's Consulting Cybersecurity Leader Tapan Shah.

The behavior Shah and EY are urging companies to break in their younger employees is an apparent apathy toward technology that would make a Gen Xer proud, with much of that attitude stemming from an over familiarity with tech.

Hipster whines at tech mag for using his pic to imply hipsters look the same, discovers pic was of an entirely different hipster [5]READ MORE

EY did not define ranges for the four generations included in the report.

Not the first inter-generational blame rodeo

One doesn't need to look far to find additional evidence that Gen Z and millennials are damaging organizational cybersecurity postures – [6]studies and [7]stories to that effect abound online.

Tech services company NTT released a [8]report in 2019 which found similarly that younger workers, classified as those under 30, were "laid back about cybersecurity responsibilities." NTT concluded that age and familiarity with the digital world were less likely than knowledge and skills acquired at work for improving security behaviors.

[9]

But let's be frank. The fact that a third of Gen X and around a sixth of baby boomers disregard updates, use work passwords for personal accounts, and accept web cookies equates to millions of workers with poor security practices. Businesses need to consider everyone a potential weak link.

"Increasing enterprise-wide security … requires a holistic focus on the human," Shah said. He added that companies have to focus on engaging every employee by embedding safety checks and protocols into workflows "that make the risks tangible in their professional and personal lives."

Improve your posture today

The report's timing couldn't be better for organizations looking for a cue to overhaul their cybersecurity culture: 2021 was the worst year for cybercrime on record, the FBI said in a [10]report earlier this year , and [11]things aren't looking quieter in 2022.

[12]IBM settles age discrimination case that sought top execs' emails

[13]Why tell the doctor where it hurts, when you could use emoji instead?

[14]The common factor in all your failed job applications: Your CV

[15]Telstra chairman: If those darn kids can earn $5m playing Fortnite, why can't execs?

Per the FBI's Internet Crime Complaint Center, businesses lost some $7 billion to cybercrime in 2021, with confidence tricks like phishing, tech support scams, business email compromise, and ransomware all cited as causes of the staggering losses.

Turning back to EY's report, there's an immediate link visible between it and the FBI's statistics: only 41 percent of EY's respondents said they were confident they could identify a phishing attempt, and only 38 percent were confident they could avoid ransomware.

While companies pour money into technical solutions, said Shah, "software, controls, processes and protocols are only part of the equation for minimizing cyber risk." ®

Get our [16]Tech Resources



[1] https://www.ey.com/en_us/news/2022/10/gen-z-and-millennials-less-serious-about-cybersecurity-on-work-issued-devices-than-personal-according-to-new-ey-consulting-survey

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y1Bzde1-@B8BiQ9Kqpg9VQAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1Bzde1-@B8BiQ9Kqpg9VQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1Bzde1-@B8BiQ9Kqpg9VQAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2019/03/06/hipsters_all_look_the_same_fact/

[6] https://www.prnewswire.com/news-releases/63-of-employees-reuse-work-passwords-millennials-are-biggest-offenders-301171453.html

[7] https://www.forbes.com/sites/larryalton/2017/12/01/how-millennials-think-differently-about-online-security/

[8] https://www.businesswire.com/news/home/20191022005729/en/NTT-Report-Finds-Digital-Natives-Don%E2%80%99t-Prioritize-Cybersecurity

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1Bzde1-@B8BiQ9Kqpg9VQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/03/23/cybercriminals_made_7bn_2021/

[11] https://www.theregister.com/2022/05/18/fraud_economy_booms/

[12] https://www.theregister.com/2022/06/27/ibm_age_discrimination_emails/

[13] https://www.theregister.com/2021/09/09/emoji_healthcare/

[14] https://www.theregister.com/2021/06/02/cv_improvement_job_search/

[15] https://www.theregister.com/2019/10/15/telstra_chairman_if_kids_can_earn_5m_playing_fortnite_why_cant_i/

[16] https://whitepapers.theregister.com/



pimppetgaeghsr

It's not that we are bad, it's that we just don't care anymore.

I'd love to see how much worse these phishing email clicks get when an entire generation gets 2% raises next year on the backdrop of 20+% inflation in food and bills.

Anonymous Coward

Company doesn't pay livable salary, peons don't give a f**k. That's the reality.

Too bad: They created that all by themselves, it's too late to whine about it.

Bunch of whiners.

Anonymous Coward

"disregard mandatory IT updates for as long as possible"

Yes, as they *know* that "update" is a downgrade in everything: Actually useful features, usability and outlook. And introduces bunch of new bugs without repairing old ones. No-one sane installs those.

Funny how YT totally wipes reality off the board and whines about one minor aspect (to the user) of the whole.

Re: Bunch of whiners.

Anonymous Coward

> Yes, as they *know* that "update" is a downgrade in everything:

Ha, reminds me of a highly amusing (for me) argument with a MS support person.

This doesn't work on W10 does it

Errrr no

But it does on W7

Errrr

So can I have an upgrade from W10 to W7

Errrr that not an upgrade Sir, that's a downgrade

How can moving from it doesn't work to it does work be considered as a downgrade and not an upgrade. The system is down as it is, it can't go down any further, the only way from here is up

Errrrrrr it's still a downgrade... IErrrrrrrr ... 'll send you the kit

Meh

chivo243

From personal experience, boomers to what ever is the current name of the generation, I think the same percentage of users are from the risk groups: Don't care at all, Don't know how to start the computer, Don't ask for help... no matter the generation, each one has people in the above categories.

Re: Meh

Yet Another Anonymous coward

Possibly a difference between some of us whose first meeting with a computer was a terminal at university with a username and a password and permissions and a big scary BOFH. And the younglings who have been used to clicking OK on their phones to get the new shiny since they were toddlers.

Now get off my virtual lawn you whippersnappers.

Re: Meh

chivo243

Yes, forgot to wag my fist and say get of my *tumbleweeds* what was I saying again? In any case stay off my lawn!!

Re: Meh

Anonymous Coward

> and a big scary BOFH

And they really were scary they were and they were called Doug. I mean they'd use sarcasm

Interviewer Doug?

Vercotti Doug I was terrified of him. Everyone was terrified of Doug. I've seen grown men pull their own heads off rather than see Doug. Even Dinsdale was frightened of Doug.

Interviewer What did he do?

Vercotti He used sarcasm. He knew all the tricks, dramatic irony, metaphor, bathos, puns, parody, litotes and satire.

Re: Meh

Terry 6

I'd hazard a guess that the younger ones are just more prepared to admit to it. (I'm old and cynical)

Not surprising

Will Godfrey

When so many companies come out with the stock "We care about your security" when it's plainly obvious they don't.

Also how about doing that survey here in the UK? Might give quite different results.

"something only 15 percent of boomers and 31 percent of Gen X admitted to"

Anonymous Coward

So... 85% of Boomers don't actually know enough about a computer to realize they are lying as well, and the Gen-Xers that aren't lying themselves are currently employed in IT and trying to get the rest of the company to get their shit together?

(OK let's face it, there are still some Gen-Xers that are BOTH liars about their password and security habits and also work in IT)

Re: "something only 15 percent of boomers and 31 percent of Gen X admitted to"

Yet Another Anonymous coward

My home system doesn't require me to change the password every 90days, so I don't need to use Password1,2,3 etc like i do at work

karlkarl

I think my "generation" (~1987) is more savvy when it comes to the basic threats from email attachments and and things like that.

However they do open themselves to attack from all the many online services that they flippantly use which older generations don't. Similarly with phone apps. These tend to hit my generation more because they seem to love them.

So really I think it is education, there will be pros and cons, strengths and flaws in each generation as we use computers differently.

It would help

Anonymous Coward

if we stopped making this so difficult for people.

Passwords need to go, their are no excuses, just businesses giving in to inertia. SSO and passkeys, if they were a few clicks for the admins to implement would bury a big chunk of this. Also, providing a decent password vault for your employees wouldn't hurt. I doesn't help that on both Macs and Windows boxes the password infrastructure is stuck in the 90's, and since so many systems try to pull from AD if you set password expiration, users inevitably get blocked trying to log into a system that can't successfully update their password. Bonus points for confused Mac users resetting their password on the windows/AD side and losing their keychain.

And then there is the patching issue. Windows patching is a crime against humanity at this point, and Apple has been nearly as bad with OSX updates. Both have been moving two steps forwards and 1.5 steps back since the Win 7/Leopard era. Installing updates is slow, needs admin rights, dumps unsaved work, and in many cases the user will lose all their open windows. The OS will nag them incessantly, but your choice as an admin is "Force install and reboot regardless of the howls" or to individually chase users down and pry the computer out of their hands to make them run the updates. Nagging pisses them off, and the prompts don't guide users through doing it properly, or in many cases make it easy for users without admin rights to request the updates be applied other then calling, opening a ticket or showing up at the IT office doorstep holding their laptop like a caricature of a pauper in some old Dickens novel.

"Please sir, may I have my system updates? It's been nagging something fierce, but when I hits OK it the progress bar stops after 25 min and she just says install failed! Try again?"

They'll learn...

Someone Else

The young-uns will learn in time, once they have their credit broken, their bank accounts drained and/or their jobs lost as a result of their blithely arrogantly cavalier attitudes about cybersecurity. After all, one can't be arsed to give a flying fuck about cybersecurity in one's lemming-like 1 chase for the latest shiny.

Won't somebody think of the FOMO?

1 OK, I know the lemming thing was faked, and real lemmings don't do that...do they?

Easy one this

Dan 55

People who put off restarting to install updates don't have time to close down each program, wait for Windows to update, restart, wait for Windows to update some more, log in, and open all their programs again because they have actual real work to do. They're usually younger employees as opposed to older managers.

Meanwhile,

Jan 0

us old bulge babies just wish these new gizmos could plot our old punched tape porn archives. Modern generations just don't understand.

drug, n:
A substance that, injected into a rat, produces a scientific paper.