The ability of organisations and people to manage digital security risk and privacy is key to fostering trust in online environments. From a business perspective, management of digital security risk needs to be integrated across the entire business process in order to be effective. It may be undertaken internally by employees or outsourced depending on the business strategy and the availability of resources, including skills present in the workforce. From an individual perspective, awareness of security and privacy threats and the competencies to prevent and respond to them are crucial for prospering in the digital society.
In 2017, ICT security and data protection functions were performed mainly by own employees in about 22% of enterprises in EU28 countries. Differences according to firm size are notable. Given the composition of the business population in most economies, this is driven mostly by the behaviour of smaller firms. Large firms are considerably more likely to perform such functions internally (57% on average) as compared to small ones (19%). In countries such as Slovenia, Austria, Latvia and Poland, the share of large firms with own employees in charge of ICT security and data protection was above 65% of all large firms.
With the almost universal uptake of digital technologies, such as smartphones, digital security and privacy skills are playing an increasingly important role in individuals’ daily lives. New evidence from the European Community Survey of ICT Usage in Households and by Individuals suggests that about 60% of smartphone users in the EU28 have restricted or refused access to their personal data at least once when using or installing an app, in contrast to 28% who have never done so. The share of those who were unaware of the existence of such functionalities was rather low (7% on average) indicating strong overall awareness of digital security and privacy threats related to smartphone use.
Training allows individuals to heighten their awareness while gaining more up-to-date digital security and privacy skills in a context of fast technological change. In the EU28, about 20% of individuals who carried out a learning activity related to the use of computers in 2018 received training on IT security or privacy management. The propensity to learn about these topics was greater among highly skilled individuals in most of the countries with available data, especially in Austria, Finland, Ireland and Hungary.
These variables from ICT usage surveys allow for the computation of internationally comparable statistics, which shed light on the availability of digital security and privacy skills across countries and link them to other usage metrics both for firms and individuals.