{"id":14901,"date":"2013-10-14T17:14:05","date_gmt":"2013-10-14T17:14:05","guid":{"rendered":"http:\/\/kasperskydaily.com\/b2b\/?p=1085"},"modified":"2020-02-26T10:44:32","modified_gmt":"2020-02-26T15:44:32","slug":"current-threats-and-graceless-ignorance-of-users","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/current-threats-and-graceless-ignorance-of-users\/14901\/","title":{"rendered":"Current threats and graceless ignorance of users"},"content":{"rendered":"<p>The question of ordinary users\u2019 awareness of cyber threats and the scope of their knowledge about them may seem philosophical or rhetorical, but only at first glance. The results of studies and surveys show that ordinary people\u2019s awareness of threats unrelated to strictly \u201cconditional\u201d viruses or Trojans is very low. Meanwhile, the understanding of problems that network users may encounter now directly affects the well being of his\/her employer. That is without mentioning the comfort of a user whose computer would have been crippled, or a bank account compromised by attackers via a user\u2019s mobile device.<\/p>\n<p>Here are the most common examples. If an employee who has just joined the company does not know the basics such as not running email attachments without checking if they are forbidden.\u00a0 Such behavior may threaten the entire company. In most cases, there are various foolproof solutions enabled in corporate networks, but it does not mean incorrect user actions can be absolutely dismissed, and that there is no more need to teach employees the basics of IT security.<\/p>\n<p>According to the <a href=\"http:\/\/media.kaspersky.com\/pdf\/Kaspersky_Lab_B2C_Summary_2013_final_EN.pdf\" target=\"_blank\" rel=\"noopener nofollow\">survey<\/a> of user attitudes to IT security, which Kaspersky Lab and B2B International conducted in August 2013, the awareness of end users on topical IT threats leaves much to be desired.<\/p>\n<p>Most users have a common understanding of threats, i.e. know that they exist at all. About 50% of the respondents in our study indicated that regardless of the operating system a mobile device or a computer can be considered safe only with the installed means of protection against information threats.<\/p>\n<p>Nevertheless, too few are willing to take any additional security measures. For example, as much as <a href=\"https:\/\/business.kaspersky.com\/the-splendors-and-miseries-of-passwords-on-the-web\/\" target=\"_blank\" rel=\"noopener nofollow\">17% of users do not take any steps to ensure more safety of their passwords to financial and\/or billing services accounts<\/a>, while 39% of people in the whole world prefer to use one or just a few passwords for the whole range of resources they visit. At the same time 63% of respondents admitted that their passwords are not hard to guess, and only 9% of users take extra measures to secure their passwords.<\/p>\n<p>But if the majority of users generally know about such threats as malware \u2013 viruses and Trojans, the degree of awareness of the more exotic phenomena is very low.<\/p>\n<p>For example, the information about cyber espionage campaigns like <a href=\"http:\/\/www.securelist.com\/en\/blog\/8105\" target=\"_blank\" rel=\"noopener nofollow\">Red October<\/a> and cyber weapons such as Mini Flame and Gauss is being closely followed by 3% of respondents at best. 21% have heard something about Red October, 12-13% have heard something about <a href=\"http:\/\/www.securelist.com\/en\/analysis\/204792257\/Kaspersky_Security_Bulletin_2012_Cyber_Weapons#6\" target=\"_blank\" rel=\"noopener nofollow\">Mini Flame<\/a> and <a href=\"http:\/\/www.securelist.com\/en\/analysis\/204792257\/Kaspersky_Security_Bulletin_2012_Cyber_Weapons#5\" target=\"_blank\" rel=\"noopener nofollow\">Gauss<\/a>.<\/p>\n<p>But let us say that an average user is not very endangered by messing with that kind of stuff, if he or she is not engaged with banking or governmental organizations.<\/p>\n<p>The same \u201cgraceless ignorance\u201d is demonstrated by users en masse when it comes to much more common threats. For example, only 6% of the respondents know about zero day vulnerabilities and exploits. 21% \u201chave heard something\u201d and 74% have no idea what they are.<\/p>\n<p>A similar pattern is observed in the case of botnets: 6% know what they are, 24% have heard something, 69% are totally unfamiliar with the notion.<\/p>\n<p>Just 4% of the respondents truly know about <a href=\"http:\/\/www.securelist.com\/en\/analysis\/204792107\/ZeuS_on_the_Hunt\" target=\"_blank\" rel=\"noopener nofollow\">Trojan Zeus\/Zbot<\/a>, which infected computers in 196 countries of the world, i.e. it didn\u2019t make it to Antarctica only. With its help the operators of it \u201cearned\u201d about $70 million, but 23% of users only have heard something, 73% just do not know about it at all.<\/p>\n<div class=\"pullquote\">Only 6% of the respondents know about zero day vulnerabilities and exploits. 21% \u201chave heard something\u201d and 74% have no idea what they are.<\/div>\n<p>Thus, the majority of people still do not know what a botnet is\u2026 It must be said, it is partly the reason they are prevalent. No user is going to check a computer or a mobile device for a present malicious botnet if he does not know what it is.<\/p>\n<p>In turn, the lack of knowledge of zero day threats is dangerous and quite concerning, too, since there are multiple mentions of vulnerabilities and exploits in mass media.<\/p>\n<p>Totally, the picture is clear. The degree of awareness of users about the threats that go beyond \u201cconditional\u201d viruses and Trojans is perilously low and has to be upgraded. The most promising option here is IT security basic training of employees.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The question of ordinary users\u2019 awareness of cyber threats and the scope of their knowledge about them may seem philosophical or rhetorical, but only at first glance. The results of<\/p>\n","protected":false},"author":209,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3052],"tags":[251,2042],"class_list":{"0":"post-14901","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-business","7":"category-smb","8":"tag-corporate-security","9":"tag-it-threats"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/current-threats-and-graceless-ignorance-of-users\/14901\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/current-threats-and-graceless-ignorance-of-users\/14901\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/current-threats-and-graceless-ignorance-of-users\/14901\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/corporate-security\/","name":"corporate security"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/14901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/209"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=14901"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/14901\/revisions"}],"predecessor-version":[{"id":32937,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/14901\/revisions\/32937"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=14901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=14901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=14901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}