The Onus Of Security: Consumer Responsibility Or Companies?

The Onus Of Security Consumer Responsibility Or Companies

Passwords suck. It sucks to remember them. It sucks to update them. It sucks to create new variations of them across different accounts. What’s more: research shows we as humans are not very good at it. We make passwords that are easy to hack. We’re lazy about using different passwords for work and home. And yet, by and large, passwords are what we’ve relied upon to keep our information safe.

Consider just a few of these statistics:

Which begs the question: Is data security really a business problem? Or is it a consumer responsibility?

Big Tech’s Response to Consumer Password Issues

Honestly, the issue could be argued either way. Lucky for consumers, Big Tech is taking the brunt of the accountability. This past World Password Day, Google took the opportunity to announce a few developments designed to protect consumer data across devices. For instance, it’s moving toward two-step verification (2SV) for all Google accounts, with built-in security keys for Android and Google Smart Lock for iOS that allows phones to be used as a secondary form of authentication. This, in addition to an array of password managers and import programs to help keep users safe.

Apple, similarly, is working to help consumers keep their data safe, offering a “keychain” service that serves as an encrypted container that stores things like account names, passwords, credit card numbers, and account pins for Mac computers, apps, and websites. And obviously, its face recognition has helped improve security on iPhones specifically.

And, all of this is in addition to the security implemented by businesses like Target, Walmart, Amazon, etc. that are also working hard to keep customer data in line.

There is definitely a greater push to biometric, multi-factor authentication, stronger password requirements, and regular password updating coming from many companies. These are all positive steps that can significantly reduce the risk of hackers gaining access to accounts, even if they are somehow able to obtain sensitive data like password or credit card information. Adding at minimum two-factor authentication for services where highly sensitive data may live should really be a minimum requirement and companies should be aggressively pushing consumers toward utilizing it to keep their data as safe as possible.

So, Whose Issue Is It?

Companies could easily point to consumers’ refusal to create stronger passwords as a reason for the ongoing breach of content that costs companies billions each year. For instance, 59% of American’s use a person’s name or birthday in their passwords. Some 33% include a pet’s name. Clearly, it can’t be that difficult for hackers to guess based on information that is publicly available.

Still, as much as consumers can be blamed for lazy password practice, I do believe that the onus will always be on the part of companies to keep data safe. Why?

First of all, and most obviously, businesses are the ones making money from data that is stored online. It’s the company that wants their customer data to live and breathe on their website. It wants to make it as easy as possible for customers to buy more — and more often — on its website. Customers stand to lose if their data is breached. But he isn’t really gaining much besides a speedy checkout if it is kept safe.

Similarly, for the Big Tech companies: if they are going to create devices and applications that allow 24/7 connectivity, it is their responsibility to make that connectivity safe. When we purchase a new device or object—be it a car or a printer or a Peloton machine—don’t we all assume that item was proven to be safe? We need to believe that minds bigger than our own have already considered the potential dangers and come up with ways to thwart them.

Consumers simply don’t have access to things like SecOps and increased observability that big companies do to detect threats more quickly. They don’t have the ability to pay ransoms to get their data back. In fact, 55% of consumers believe the companies they deal with should pay a ransom to keep their data safe if the issue should arise.

As they say, using a password to keep your data safe is like using an old-fashioned lock to protect your home. These days, it just isn’t enough, and we all know that. Clearly, consumers can do better. We can do a better job of thinking of stronger passwords and playing an active role in the digital world in which we operate. But at the end of the day, it’s the businesses that make money from having us share our data online. And it’s the businesses that will need to play the greatest role in keeping that data safe.

Disclosure: Futurum Research is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article. 

The original version of this article was first published on Forbes.

Author Information

Daniel is the CEO of The Futurum Group. Living his life at the intersection of people and technology, Daniel works with the world’s largest technology brands exploring Digital Transformation and how it is influencing the enterprise.

From the leading edge of AI to global technology policy, Daniel makes the connections between business, people and tech that are required for companies to benefit most from their technology investments. Daniel is a top 5 globally ranked industry analyst and his ideas are regularly cited or shared in television appearances by CNBC, Bloomberg, Wall Street Journal and hundreds of other sites around the world.

A 7x Best-Selling Author including his most recent book “Human/Machine.” Daniel is also a Forbes and MarketWatch (Dow Jones) contributor.

An MBA and Former Graduate Adjunct Faculty, Daniel is an Austin Texas transplant after 40 years in Chicago. His speaking takes him around the world each year as he shares his vision of the role technology will play in our future.

Related Insights
Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?
July 23, 2026

Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?

Mend.io's security team identified 199 malicious RubyGems and achieved complete takedown within hours, intercepting a cryptomining campaign before execution and demonstrating the critical importance of continuous open-source monitoring....
Hugging Face Breach: A Wake-Up Call for AI Agent Security
July 23, 2026

Hugging Face Breach: A Wake-Up Call for AI Agent Security

The Hugging Face breach reveals how autonomous AI agents exploit code flaws to harvest credentials and move laterally at machine speed. Enterprise leaders now recognize identity security as urgent, with...
Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation
July 22, 2026

Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation

Brendan Burke and Fernando Montenegro, analysts at Futurum, share their insights on the Intel-Fortinet SP6 collaboration, what it validates about Intel Foundry's custom silicon strategy, and why the supply chain...
Thales Strengthens Industrial Presence in Germany with Major Defense Contract
July 22, 2026

Thales Strengthens Industrial Presence in Germany with Major Defense Contract

Thales secured a major German defense contract, strengthening its European presence as a key sovereign supplier amid rising defense spending across the continent....
Fortinet's AI Controls Join the Field. Can Integration Set Them Apart?
July 21, 2026

Fortinet’s AI Controls Join the Field. Can Integration Set Them Apart?

Fernando Montenegro, VP at Futurum, examines why FortiEndpoint's consolidated AI controls are a real buyer win, while platform and SASE integration, not the individual features, will decide whether Fortinet stands...
SCSK Security Launches Prisma Browser to Enhance Cloud Security
July 21, 2026

SCSK Security Launches Prisma Browser to Enhance Cloud Security

SCSK Security Corporation launches Prisma Browser Deployment Support Service, enabling enterprises to implement cloud access control and data protection through standard web browsers, positioning itself to capture meaningful channel partner...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.