Gen Z and millennials less serious about cybersecurity on work-issued devices
ey.com
ey.com
Re-spun: They understand these security practices and know what's in it for them, so they're actually serious about them when something they care about is at stake.
Nice!
I use a password that is found in leaks at my jobs.
There is no reason to care. Your company won’t pay you extra to complicate your life with security practices so it’s rational to do the bare minimum when there’s no downside. From a typical office drone’s perspective, they’re already not paid enough, so why put any more effort or good faith than strictly necessary?
Not to mention, why is password management still a thing? On a corporate machine, the only place that should require a password is the system-provided login screen. Everything else should transparently inherit this authentication. The tech is absolutely there (and you can set up Keycloak/etc to seamlessly proxy between that and SAML for external services) so there’s absolutely no excuse for it. With machine authentication, even obtaining the password shouldn’t allow any remote attacker in because they lack the machine keys (in AD, this can be done with smart cards - the “machine auth” is actually the smart card, and the password its PIN). This is an area where the industry has actively regressed from the early days, but I guess Okta/etc shareholders need to eat too, despite significantly reducing security by training users to enter their password regularly in a browser after a chain of multiple redirects.
What do you do for a living?
The poster you replied to is being realistic. Calling names doesn't change human nature. People in charge of security can work to build something that gets used properly, or they can nag and at best get people to go through the motions the absolutely have to. The latter options is what leads to findings like in the article
...Good? Handling-it-yourself is exactly what you want to avoid ANYONE doing.
IT security incidents need to be reported and discussed immediately on detection with managers. The fact that the survey suggested that Millenials and Gen Z do this suggests that they on average understand this better than EY does.
What an embarrassing article.
If you look at staff driving company vehicles vs their own, it's fairly obvious that they give the company ones a much harder time than they generally would their own. I see delivery vans thrown over speed bumps in ways that only the most inept private car owner would do (there are a few but it's more the exception). In a very similar analogy, this is basically what's happening with security: it's not their property, the incentives aren't well aligned and often there's little come back for behaving this way.
It ain't me. So yea, I worry a little more about my stuff