-

RSA ID IQ Report Reveals What You Don’t Know Will Breach You

  • 9 in 10 respondents believe AI has a role in improving identity security; three quarters trust technology for their security and privacy more than their partner, closest friend, or financial advisor
  • Nearly one-third of all respondents reported that they were prevented from accessing the systems needed to do their work at least once a week
  • Sample size of more than 2,350 respondents from over 90 countries indicates that identity is top of mind around the world

BEDFORD, Mass.--(BUSINESS WIRE)--RSA, the security-first identity leader, released its inaugural ID IQ Report today. Using results from the RSA ID IQ Quiz, the report assesses and baselines users’ identity security knowledge, capabilities, and perceptions regarding the role of AI in cybersecurity. Results from the 2023 RSA ID IQ Report reveal that:

  • The gap in users’ identity security knowledge gives cybercriminals an opening
  • Respondents trust technological innovations for their security and privacy
  • Unmanaged mobile devices are prime targets for identity compromise
  • Fragmented identity solutions are driving up costs and slowing down productivity

See the following for further analysis:

Identity security knowledge gaps give cybercriminals an opening

The RSA ID IQ Report found significant gaps in respondents’ knowledge concerning key identity vulnerabilities, best practices for securing identity, and how to develop stronger identity security. For instance, 63% of respondents could not accurately identify the identity components needed to move organizations toward zero trust. Likewise, 64% of respondents did not select the best practice technologies for reducing phishing. More than half (55%) did not understand the full scope of identity capabilities that can improve an organization’s security posture.

These findings align with third-party research indicating that identity is the most frequent cause of data breaches: the Verizon 2023 Data Breach Investigations Report found that the use of “stolen credentials became the most popular entry point for breaches” over the past five years.

“The RSA ID IQ Report reveals why identity is one of the most susceptible ways for cybercriminals to breach an organization—users simply don’t understand identity’s full cybersecurity role, the risks that identity poses, or the ways to use identity to build safer organizations,” said RSA CEO Rohit Ghai. “The gaps in users’ identity knowledge give cybercriminals openings to exploit.”

Among self-described IAM experts, 65% did not accurately select best practices to reduce phishing and 42% underestimated the frequency with which users recycle their passwords.

“Growing numbers of users, devices, entitlements, and environments are overburdening IAM specialists—they just can’t keep up,” said RSA Chief Product Officer Jim Taylor. “Identity plays critical roles across organizations, and for organizations to stay secure and compliant, identity needs to excel in each of those roles. The RSA ID IQ Report results reveal why organizations need to invest in unified identity solutions and integrate artificial intelligence to help their personnel keep up with the pace of change.”

Respondents trust technology with their security and privacy

Nearly two-thirds (64%) of respondents put more trust in technical innovations like a computer or password manager with securing their information than their partner, closest friend, or financial advisor.

Respondents felt even stronger about artificial intelligence’s potential to improve identity security: 91% of respondents believed that AI can detect suspicious authorizations and access attempts, identify irregularities in entitlements, and recognize vulnerabilities on mobile devices.

Unmanaged devices are prime targets for identity compromise

Unmanaged devices have become prime targets for identity compromise: nearly three-quarters of all respondents (72%) believed that people frequently use personal devices to access professional resources. Nearly all (97%) cybersecurity experts felt that users opened more emails on their phones than on desktops, had more difficulty scrutinizing those emails on mobile devices, used personal devices to access professional resources, and/or that unmanaged devices don’t have the same security capabilities as managed devices.

Each of those factors could catalyze identity compromise—together, they represent a perfect storm of risks. These responses align with Zimperium’s 2023 Global Mobile Threat Report, which found that the average user is 6-10 times more likely to fall for an SMS phishing attack than an email-based attachment.

Fragmented identity solutions drive up costs, slow down productivity

Nearly three-quarters of all respondents either didn’t know or significantly under-valued the cost of a password reset, including nearly half of all self-described IAM experts. With each password reset costing upwards of $70, resets can account for nearly half of all IT help desk costs. The fact that 73% of respondents can’t accurately price this expense or understand its impact on their IT counterparts could lead to run-away costs, underscoring the value of using one identity solution for both authentication and access.

The report also revealed how inadequate identity governance and administration hurts organizational productivity. Nearly one-third (30%) of all respondents reported that they were prevented from accessing the systems needed to do their work at least once a week.

About RSA

The AI-powered RSA Unified Identity Platform protects the world’s most secure organizations from today’s and tomorrow’s highest-risk cyberattacks. RSA provides the identity intelligence, authentication, access, governance, and lifecycle capabilities needed to prevent threats, secure access, and enable compliance. More than 10,000 security-first organizations trust RSA to manage 59 million workplace identities across on-premises, hybrid, and multi-cloud environments. For more information, go to RSA.com.

About the 2023 ID IQ Quiz

The 2023 ID IQ Quiz is RSA’s first iteration of its annual industry survey. This year’s survey consisted of 15 questions conducted between April 21 and May 30, 2023. The 2023 ID IQ Quiz sampled more than 2,350 respondents from over 90 countries who work across a variety of fields both within and outside of cybersecurity and IAM. For more information, visit: https://www.rsa.com/.

More Resources:

2023 RSA ID IQ Report Infographic

2023 RSA ID IQ Report

RSA


Release Summary
The 2023 RSA ID IQ Report detailed users’ identity security knowledge and perceptions of AI’s cybersecurity potential.
Release Versions

Social Media Profiles
More News From RSA

RSA Announces Expanded Partnership with Microsoft, Enhances Leadership in Passwordless Identity Security

SAN FRANCISCO--(BUSINESS WIRE)--RSA today announced expanded support for the new Microsoft 365 E7: The Frontier Suite solution at RSAC Conference 2026. This new support joins additional passwordless capabilities that provide organizations with enhanced security, seamless experience, and resilient operations as they embrace the future of AI-driven productivity. By integrating RSA® ID Plus for Microsoft with Microsoft 365 E7, enterprises can ensure trusted authentication for both human users and...

RSA Launches ID Plus Sovereign Deployment: The Next Level of High Assurance Identity Security

SAN FRANCISCO--(BUSINESS WIRE)--Today at RSAC Conference 2026, RSA, the security-first identity leader, announced the launch of RSA® ID Plus Sovereign Deployment, a groundbreaking evolution in high assurance identity solutions designed to meet the needs of organizations that must maintain constant availability, meet policy and data sovereignty laws, and defend themselves from advanced, persistent threats. RSA ID Plus Sovereign Deployment is the next evolution in RSA® ID Plus, the market’s most...

RSA Group Announces New $135 Million Capital Infusion and Debt Refinancing to Accelerate AI Product Innovation and Organic Growth

BOSTON--(BUSINESS WIRE)--RSA Group (“RSA”), a cybersecurity company comprised of RSA (formerly known as SecurID) and Outseer (formerly known as RSA Fraud Risk & Intelligence), announced the closing of a refinancing transaction of its outstanding debt with a substantial majority of holders of its existing first lien and second lien term loans yesterday. Participation in the transaction is open to all remaining first lien and second lien lenders. The transaction includes a new capital infusio...
Back to Newsroom