2015 Consumer Trust Survey

Similar documents
The Impact of Extended Validation (EV) Certificates on Customer Confidence

Web Presence Security

WHY YOU NEED AN SSL CERTIFICATE

WHY YOU NEED AN SSL CERTIFICATE

Gain a New Level of Trust with Extended Validation SSL Certificates

Security and Trust: The Backbone of Doing Business Over the Internet

How Extended Validation SSL can help to increase online transactions and improve customer confidence

Internet threats: steps to security for your small business

You re FREE Guide SSL. (Secure Sockets Layer) webvisions

Trust or bust: How to make summertime shoppers feel safe online and boost your sales at the same time

SSL Certificates: A Simple Solution to Website Security

Chapter 4 Copyright Statement

WHITE PAPER. The latest advancements in SSL technology

Protecting Your Name on the Internet The Business Benefits of Extended Validation SSL Certificates

How Extended Validation SSL Brings Confidence to Online Sales and Transactions

extended validation SSL certificates: a standard for trust THAWTE IS A LEADING GLOBAL PROVIDER OF SSL CERTIFICATES

Realize Greater Profits As An Authorized Reseller Of Network Solutions nsprotect Secure SSL Certificates

WHY YOU NEED AN SSL CERTIFICATE Introduction

WHITE PAPER SECURITY AND TRUST: THE BACKBONE OF DOING BUSINESS OVER THE INTERNET

SSL Certificates 101

Extended SSL Certificates

Certificates, Revocation and the new gtld's Oh My!

BEGINNER S GUIDE TO SSL CERTIFICATES: Making the best choice when considering your online security options

Cybersecurity Best Practices

HOW TRUST REALLY AFFECTS ONLINE SHOPPERS DECISION TO BUY

Beginner s Guide to SSL Certificates

Why You Need an SSL Certificate

AVOIDING ONLINE THREATS CYBER SECURITY MYTHS, FACTS, TIPS. ftrsecure.com

Websense Content Gateway HTTPS Configuration

Industry Leading Encryption Balanced Offerings from domain validated to secure EV certificates Mobile Device Capability Full Service and Support

White Paper. Hidden Dangers Lurking in E-Commerce- Reducing Fraud with the Right SSL Certificate

BEGINNERS GUIDE BEGINNERS GUIDE TO SSL CERTIFICATES: MAKING THE BEST CHOICE WHEN CONSIDERING YOUR ONLINE SECURITY OPTIONS

Web Payment Security. A discussion of methods providing secure communication on the Internet. Zhao Huang Shahid Kahn

The Benefits of SSL Content Inspection ABSTRACT

Internet Basics. Meg Wempe, Adult Services Librarian ABOUT THIS CLASS. P a g e 1

Wireless Network Best Practices for General User

Digital Citizenship Lesson Plan

McAfee S DO s AnD DOn ts Of Online Shopping

Your Members May Be Under Attack From Cybercriminals

Central and Eastern Europe

Extended Validation SSL Certificates

White paper. How to choose a Certificate Authority for safer web security

Everyone s online, but not everyone s secure. It s up to you to make sure that your family is.

Social Media Status Update Messages. Twitter

A Proper Foundation: Extended Validation SSL

Creating Trust Online TM. Identity & Trust Assurance in a changing standards environment. *(Extended Validation)

WHAT YOU NEED TO KNOW ABOUT CYBER SECURITY

The Devil is Phishing: Rethinking Web Single Sign On Systems Security. Chuan Yue USENIX Workshop on Large Scale Exploits

Basics of SSL Certification

ALTERNATIVES TO CERTIFICATION AUTHORITIES FOR A SECURE WEB

beginners guide Beginners Guide Certificates the best decision when considering your online security options.

Phishing The latest tactics and potential business impacts

White Paper. Enhancing Website Security with Algorithm Agility

Extended Validation (EV) SSL Certificates. Key to Online Success for you and your customers

Creating Trust Online TM. Comodo Mutual Authentication Solution Overview: Comodo Two Factor Authentication Comodo Content Verification Certificates

BUT. Before you start shopping on the Internet, there are a number of questions you need to ask yourself.

Security Breaches. There are unscrupulous individuals, like identity thieves, who want your information to commit fraud.

NORTON CYBERSECURITY INSIGHTS REPORT

Data Security for Retail Consumers Perceptions, Expectations and Potential Impacts

Why are we changing Security Partners?

Massey University Wireless Network Client Configuration Mac OS X

Leveling the E-Commerce Playing Field

How to check if I care for the safety of my Clients?

DISCLAIMER AND NOTICES

Understanding Digital Certificates & Secure Sockets Layer A Fundamental Requirement for Internet Transactions

N-CAP Users Guide Everything You Need to Know About Using the Internet! How Electronic Payment Works

Contents. Identity Assurance (Scott Rea Dartmouth College) IdM Workshop, Brisbane Australia, August 19, 2008

GeoTrust Extended Validation SSL and Customer Confidence

Identity Theft: A Growing Problem. presented by Melissa Elson Agency Liaison Office of Privacy Protection - Bureau of Consumer Protection

Deception scams drive increase in financial fraud

Whitepaper. Best Practices for Securing Your Backup Data. BOSaNOVA Phone: Web:

Domain Name Considerations for your e-commerce Service

STOP.THINK.CONNECT A NATIONAL CYBERSECURITY AWARENESS CAMPAIGN OLDER AMERICANS PRESENTATION

Malware & Botnets. Botnets

Online security. Defeating cybercriminals. Protecting online banking clients in a rapidly evolving online environment. The threat.

Reducing the Cost and Complexity of Web Vulnerability Management

The USP Maker for the hosting industry Welcome to my presentation Christian Heutger WorldHostingDay

Five Trends to Track in E-Commerce Fraud

FIVE KEY BUSINESS INSIGHTS FOR MOBILE SECURITY IN A BYOD WORLD

Understanding Digital Certificates & Secure Sockets Layer (SSL): A Fundamental Requirement for Internet Transactions

Identity Theft Protection Plan Descriptions

BEGINNERS GUIDE TO SSL CERTIFICATES: Making the BEST choice when considering your online security options

When life happens... Protect Against Identity Theft. Keeping personal information safe & what to do if it happens to you

WhitePaper. Building Online Trust Using Actual Relationships

2012 NORTON CYBERCRIME REPORT

Certified Secure Computer User

STRONGER ONLINE SECURITY

A Proper Foundation: Extended Validation SSL

STOP THINK CLICK Seven Practices for Safer Computing

Guide to credit card security

BEHIND OUR DIGITAL DOORS: CYBERSECURITY & THE CONNECTED HOME. Executive Summary

WHITE PAPER. Maximizing Site Visitor Trust Using Extended Validation SSL

Five PCI Security Deficiencies of Restaurants

10 Quick Tips to Mobile Security

1 Billion Individual records that were hacked in

Identity Protection Guide. The more you know, the better you can protect yourself.

National Cyber Security Month 2015: Daily Security Awareness Tips

Complete Website Security

GUIDE. Stop Phishing: A Guide to Protecting Your Web Site Against Phishing Scams

Transcription:

2015 Consumer Trust Survey CASC Survey Report https://casecurity.org

Increasing numbers of consumers are browsing and making their purchases online, and are clearly embracing e-commerce with 200 million online shoppers in the U.S. spending nearly $600 billion. The results of a new survey commissioned by the CA Security Council (CASC) found that consumers understand online security but lack the attentiveness to certain aspects of it. Overview After years of belt tightening brought on by the Great Recession of 2007, Americans optimism for the economy s recovery is rising, accompanied by a soundtrack of ringing cash registers and computer mouse clicks. More Americans are shopping again, with six in 10 people telling Consumer Reports that in 2014 they had spent money on a major purchase such as an appliance or a car. 1 Increasing numbers of consumers are browsing and making their purchases online, and are clearly embracing e-commerce with 200 million online shoppers in the U.S. spending nearly $600 billion. This number continues to rise despite the rash of news headlines about data breaches at some of the world s largest retailers and financial services institutions. This implies that consumers have a good understanding of, and trust in, the security of the online e-commerce infrastructure. The results of a new survey commissioned by the CA Security Council (CASC) found that consumers understand online security but lack the attentiveness to certain aspects of it. These findings present an opportunity for those who do business online to educate consumers better so they can avoid risky behaviors. They can also serve as a lesson to retailers, financial institutions, and others about why taking the necessary steps to earn a green bar and a small padlock symbol next to their website URL addresses can increase the security of the site and attract new customers. 2 Survey Report

Key Findings First, consumers want the highest level of protection available and they recognize that the padlock and green bar provide a trusted connection. In this study, we found that the padlock and warnings do appear to work. Just two percent admit to ignoring ONLINE SHOPPING IS IMPORTANT 38 % Percentage of consumers budget spent online the untrusted connection message, and only three percent would give out their credit card information to sites without the padlock icon. Thus, the padlock symbol is something consumers actively look for, even if they don t understand how the SSL validation process works or what assurances they can assume. The study also confirmed that consumers find online shopping to be important. While shopping in person at a consumers store still leads in terms of total spending, online shopping represents more than a third of consumers budgets (38 percent). CYBERCRIME IS EVERYWHERE 100 % Respondent or friends/ family fell victim to cybercrime This mirrors the findings of similar studies conducted by retail industry watchers. For example in February 2015, E-commerce Platforms and Forrester Research released a joint report predicting that e-commerce sales in the U.S., which totaled $176 billion in 2010, will rise to $279 billion by the end of 2015. 2 What was surprising was consumers attentiveness toward certain aspects of online security, especially considering 100 percent of them had either fallen victim to cybercrime, or knew friends and family members who had. These incidents include compromised passwords, identity theft, lost or stolen computing devices, hacked online accounts, and stolen personal items or photos. Despite being well aware of the risks, consumers need to be more attentive to overall security issues. Most reported to have at least one device they don t bother password protecting. The most common device left unguarded is the tablet, a device that 61 percent leave unprotected. Forty-three percent are happy to use Wi-Fi without regard to security issues, as long as it is free. Finally, 33 percent use just one or two passwords to login across all their websites. This is especially problematic CONSUMERS NEED TO BE MORE ATTENTIVE 61 % Leave their tablet devices unprotected 43 % Happily use any free Wi-Fi regardless of security 33 % Use just one or two passwords across all websites when considering the number of companies experiencing breaches that resulted in stolen passwords within the last few years. METHODOLOGY: The CA Security Council recently commissioned Survata Consumer Research to survey 670 U.S. consumers to gauge how security savvy they really are, and how much they trust the e-commerce infrastructure. Survey respondents were 18 years or older and shopped at least several times each year. Survey Report 3

CONSUMERS TRUST THE GREEN BAR AND PADLOCK 53 % 42 % Recognize the padlock means more trust Understand the green bar means greater safety WHO CONSUMERS TRUST THE MOST AND LEAST 68 % 49 % 42 % 40 % 17 % However, consumers do appear to have taken the time to educate themselves about how to identify secure e-commerce sites and to avoid those that pose greater risks to their information and interactions. The majority are somewhat savvy about SSL security: they recognize the padlock symbol in their browsers URL address bars, and understand that the padlock and the green bar keep them safe. They just don t understand how. EV-SSL certificates use the highest level of authentication and indicate a rigorous verification process. Sites with EV-SSL certificates provide visual cues such as the green bar in a browser s URL. Consumers know to favor websites that display the padlock symbol and the green bar in the URL, but they could still benefit from greater education on how certificates work, the benefits of authentication, and to highlight why EV provides value to businesses and consumers. Better educated consumers are not only less likely to fall fictim to cyber thieves, but they are more likely to help their friends and family adopt conscientious behaviors too. A final survey question dealt with who consumers trust the most and least to keep them safe from financial or privacy threats while shopping online. Financial institutions scored highest followed by certificate authorities at 49 percent. This finding points to a need to educate consumers on the work CAs do on their behalf and to draw the direct line between the padlock symbol they see in their browsers and the role CAs play in determining when a site has earned the right to display that symbol. 68 % 49 % 42 % 40 % 17 % Financial institutions Certificate authorities Browsers Online merchants Stores with free Wi-Fi This also helps explain why consumers look for the padlock and the green bar. Without it, they are left to trust the online merchant exclusively, and only 40 percent are comfortable with that. So, the lesson for retailers is this: Add a padlock and a green bar and you will draw a larger share of the more than 200 million Americans who are spending nearly $600 billion online. 4 Survey Report

Recommendations: These findings point to five best practices consumers should follow to keep their information safe: Update your browser to the latest version, which addresses the most current online risks. Look for https in the address bar. The s means it s secure. You should also see a padlock symbol. For an added sign that the site is authentic, look Retailers trying to build up their e-commerce operations must realize consumers will not visit unless they trust them to protect their private information. for the green browser bar and the website s name to appear in green. If your browser gives you a message about an untrusted security certificate for a website, don t proceed. Wherever possible, don t allow merchants to keep your payment information on file. Regulated industries and e-commerce should use high validation to provide stronger trust and assurance to customers and to protect against fraud. The responsibility does not rest with consumers alone. Retailers trying to build up their The security industry and CAs are a powerful tandem to ensuring retailers earn consumers trust by enforcing the highest standards for identity vetting prior to issuing certificates. e-commerce operations must realize their end users will not visit unless they trust in the protection of their private information. Using EV certificates provides the most reliable indicator of the trustworthiness of the site, and makes a very public statement of accountability to consumers. Security industry solutions providers should work closely with CAs, which, as the survey shows, are important arbiters of online trust, with global standards that have been developed and refined over time. The security industry and CAs form a powerful duo that ensures retailers can earn consumers trust by enforcing the highest standards for identity vetting prior to issuing certificates. They can also serve as an effective educational resource for consumers and IT administrators to understand what SSL/TLS trust indicators mean. 1 How America Shops Now, Consumer Reports, September 2014 http://www.consumerreports.org/cro/magazine/2014/11/how-america-shops-now/index.htm 1 How America Shops Now, Consumer Reports, September 2014 http://www.consumerreports.org/cro/magazine/2014/11/how-america-shops-now/index.htm 3 Extended Validation (EV) SSL Certificates: Improve Conversion Rates and Customer Confidence with Green Bar Assurance, 2003-2015 DigiCert Inc SSL Certificate Authority https://www.digicert.com/ev-ssl-certification.htm Survey Report 5

Web www.casecurity.org Who is the CA Security Council? The CASC is comprised of leading global Certificate Authorities that are committed to the exploration and promotion of best practices that advance trusted SSL deployment and CA operations, and the security of the Internet in general.