TL;DR: Forty-seven percent of Americans say they have already experienced hacking or data theft, and 46% rank security as the main criterion when choosing digital services, according to Idemia research. The signal for identity and security teams is clear: trust now hinges on visible controls, not just seamless user experience.
At a glance
What this is: Idemia's study shows Americans are embracing digital services, but security and control now shape whether they trust them.
Why it matters: For identity and security teams, the finding reinforces that consumer-facing trust depends on transparent authentication, transaction protection, and account controls that reduce friction without weakening assurance.
By the numbers:
- 47% of Americans have experienced hacking or data theft, compared with 38% on average across the study.
- 46% cite security as the primary criterion when choosing digital services.
- 77% of respondents would like to manage payment security settings from third-party websites and applications through their banking application.
- 72% of respondents familiar with quantum computing see it as a potential cybersecurity threat.
👉 Read Idemia's study on consumer security, trust, and digital adoption
Context
Digital trust is the practical outcome of how well organisations protect identities, transactions, and personal data while still making services easy to use. In this study, that balance has shifted toward visible security controls, because consumer adoption now depends on whether users believe the service can protect them from account abuse, theft, and fraud. That is especially relevant for identity and verification programmes, where the quality of control is often judged by the user experience as much as by the back-end assurance model.
For security and IAM practitioners, the broader lesson is that identity protection cannot be treated as a hidden control layer. Consumers increasingly expect to see and manage the safeguards around their data and transactions, which means authentication, transaction monitoring, consent controls, and recovery flows all become part of the trust model. The pattern is typical of digitally mature markets, but the scale of the confidence gap makes it more visible in the United States.
Key questions
Q: How should security teams improve consumer trust without adding too much friction?
A: Start by making the controls users interact with most easy to understand and easy to change. That means clearer security settings, stronger recovery assurance, better transaction approval flows, and transparent third-party access management. Trust improves when users can see that protection exists and can act on it without navigating hidden or inconsistent workflows.
Q: Why do users treat security as part of the digital service itself?
A: Because security failures now affect the whole experience, from account compromise to payment abuse to identity theft. Users do not separate convenience from protection. If they cannot understand how their data, identity, and transactions are protected, they will judge the service as risky even when the underlying controls are technically sound.
Q: What are the signs that consumer identity controls are not keeping up?
A: Look for low visibility into settings, heavy reliance on support-led recovery, unclear consent flows, and weak control over linked applications or payments. Those symptoms show that the trust model is fragmented. A mature programme should let users manage key protections directly and should limit the amount of hidden exception handling.
Q: What should organisations do when AI and quantum risk starts shaping customer expectations?
A: Treat emerging threats as part of the trust roadmap, not just the architecture roadmap. Update customer messaging, map post-quantum readiness to cryptographic planning, and connect AI fraud concerns to detection and verification controls. The goal is to show that future risk is being addressed before it becomes a trust failure.
Technical breakdown
Consumer digital trust depends on visible identity controls
Digital trust is not simply encryption in the background. It is the combination of authentication, authorisation, transaction assurance, and user-visible control points that convince people a service is safe to use. In consumer services, the weakest link is often not the cryptography itself but the inability of users to understand or influence security settings, recovery processes, and third-party access. That creates a trust gap even when technical protections exist. For identity teams, this means assurance has to be legible to users, not just auditable to engineers.
Practical implication: map user-facing trust moments to the identity controls that must be visible, explainable, and recoverable.
Security controls for digital services must include transaction-level governance
Modern digital services combine authentication, payments, connectivity, and third-party application access. That creates a governance problem because a user may trust the login process but still be exposed through delegated access, weak transaction approval, or poor visibility into linked applications. In identity terms, this is not only about who the user is, but what each session and transaction is allowed to do. Strong controls therefore need to extend beyond sign-in to ongoing transaction oversight, consent management, and revocation pathways.
Practical implication: evaluate where transaction approval, third-party access, and account recovery sit in your control stack.
Quantum risk and AI concern are now part of consumer security expectations
The study shows that consumers are already connecting emerging technologies with future cyber risk. That matters because security programmes are no longer judged only on today’s threats, but also on whether they are preparing for future cryptographic and fraud conditions. Post-quantum planning is still a long-horizon discipline, but public awareness can shape trust decisions sooner than organisations expect. AI concern has a similar effect, especially where automated fraud, impersonation, or synthetic identity attacks are already familiar patterns.
Practical implication: fold emerging-threat communication into your identity assurance roadmap, not just your cryptography roadmap.
Threat narrative
Attacker objective: The attacker aims to exploit trusted digital interactions to steal data, hijack accounts, or commit payment fraud at scale.
- Entry occurs through consumer-facing digital services where trust is established before the user understands the full security posture.
- Escalation happens when weak visibility, delegated access, or poor recovery controls let attackers abuse accounts or transactions after initial trust is gained.
- Impact is the theft of data, accounts, or payment value, followed by long-term erosion of trust in the service itself.
NHI Mgmt Group analysis
Security has become a trust control, not a feature. Consumer services are now judged on whether the protection model is visible, understandable, and actionable to the user. That shifts security from a back-end assurance topic into a digital trust requirement that affects adoption, retention, and fraud tolerance. For identity teams, the practical consequence is that authentication and recovery design are now part of product trust, not just risk management.
Verification trust gap: The study points to a widening gap between what providers believe they are securing and what users believe is protected. This gap appears when users cannot see, manage, or recover the controls around their identity and transactions. In identity governance terms, that makes transparency and control as important as policy strength. Practitioners should treat user perception as a control signal, not a marketing metric.
Consumer security expectations are moving toward delegated control models. The finding that many users want to manage payment settings through their banking app is a signal that trust will increasingly depend on centralised consent and cross-application control. That creates new governance demands for identity federation, consent lifecycle management, and revocation. The organisations that align user control with assurance will be better placed to reduce friction without weakening protection.
Emerging technology anxiety will influence security buying behaviour before it influences architecture. Consumers are already associating AI with more sophisticated attacks and quantum with future threat potential. That means trust narratives, disclosures, and assurance models will need to evolve in parallel with technical controls. For practitioners, the implication is straightforward: prepare the identity assurance story now, because users are already making security decisions on future risk as well as present experience.
What this signals
Verification trust gap: Consumer security programmes increasingly fail when the control plane is invisible to the user. That pattern matters beyond payments, because the same trust dynamics are now shaping identity verification, account recovery, and delegated access across digital services.
The next planning cycle should treat user-facing security controls as a measurable part of IAM and fraud strategy. Organisations that can show clear consent handling, account recovery resilience, and transaction visibility will be better positioned when user expectations tighten around AI-enabled fraud and future cryptographic change.
For practitioners
- Strengthen user-visible security controls Expose the security settings users care about most, including login assurance, transaction approval, recovery options, and third-party access controls.
- Extend identity governance into transaction flows Review where authentication ends and transaction-level authorisation begins, then add controls for payment approval, consent, and delegated access.
- Design recovery and support paths for abuse resistance Harden account recovery, help-desk verification, and exception handling so social engineering cannot use support workflows as a bypass.
- Prepare a post-quantum and AI trust narrative Align roadmap messaging with practical cryptographic migration planning and fraud detection controls so users understand how future risk is being addressed.
Key takeaways
- Consumers now evaluate digital services through the lens of visible security, which makes identity controls part of the product trust model.
- The strongest signal in the study is not just fear of breaches, but demand for direct control over security settings, payments, and account protection.
- Identity teams should connect authentication, recovery, delegated access, and emerging-threat readiness into one trust narrative.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST AI RMF set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | Consumer authentication and account recovery are central to the trust model here. Review authentication assurance and recovery paths to reduce account takeover risk without adding avoidable friction. |
| NIST CSF 2.0 | PR.AC-1 | Identity and access controls underpin user trust in digital services. Map consumer-facing identity controls to access governance and make them visible in the service journey. |
| GDPR | Art.32 | The study focuses on personal data protection and user trust. Align protection, access, and recovery controls to the security of personal data processing. |
| NIST AI RMF | GOVERN | AI concern affects trust decisions and communication around future risk. Use AI RMF governance to ensure emerging-risk messaging and controls are owned and reviewed. |
Review authentication assurance and recovery paths to reduce account takeover risk without adding avoidable friction.
Key terms
- Digital Trust: Digital trust is the set of cryptographic and identity controls that allow systems, users, and services to verify each other reliably. It includes PKI, federation, certificates, and authentication foundations that must remain adaptable as technologies and threat conditions change.
- Sequence-Level Authorisation: Sequence-level authorisation is control over the full chain of actions an autonomous agent can take, not just the permissions on each individual request. It matters because an agent can combine several valid calls into an outcome that no single policy check would flag.
- Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
What's in the full report
Idemia's full study covers the survey detail this post intentionally leaves for the source:
- Country-by-country responses across the 11-market survey, useful for comparing trust expectations.
- The full breakdown of consumer views on payment security settings and third-party app control.
- Additional data on how respondents link AI and quantum computing to future cyber risk.
- Methodology notes on the IPSOS BVA sample, weighting, and representativeness.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It helps security practitioners connect identity assurance to broader control design across modern digital services.
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org