TL;DR: Forty-seven percent of Americans say they have already experienced hacking or data theft, and 46% rank security as the main criterion when choosing digital services, according to Idemia research. The signal for identity and security teams is clear: trust now hinges on visible controls, not just seamless user experience.
NHIMG editorial — based on content published by Idemia: Americans Embrace Digital Services but Demand Stronger Security and Control, Finds an IDEMIA Secure Transactions Study
By the numbers:
- 47% of Americans have experienced hacking or data theft, compared with 38% on average across the study.
- 46% cite security as the primary criterion when choosing digital services.
- 77% of respondents would like to manage payment security settings from third-party websites and applications through their banking application.
Questions worth separating out
Q: How should security teams improve consumer trust without adding too much friction?
A: Start by making the controls users interact with most easy to understand and easy to change.
Q: Why do users treat security as part of the digital service itself?
A: Because security failures now affect the whole experience, from account compromise to payment abuse to identity theft.
Q: What are the signs that consumer identity controls are not keeping up?
A: Look for low visibility into settings, heavy reliance on support-led recovery, unclear consent flows, and weak control over linked applications or payments.
Practitioner guidance
- Strengthen user-visible security controls Expose the security settings users care about most, including login assurance, transaction approval, recovery options, and third-party access controls.
- Extend identity governance into transaction flows Review where authentication ends and transaction-level authorisation begins, then add controls for payment approval, consent, and delegated access.
- Design recovery and support paths for abuse resistance Harden account recovery, help-desk verification, and exception handling so social engineering cannot use support workflows as a bypass.
What's in the full report
Idemia's full study covers the survey detail this post intentionally leaves for the source:
- Country-by-country responses across the 11-market survey, useful for comparing trust expectations.
- The full breakdown of consumer views on payment security settings and third-party app control.
- Additional data on how respondents link AI and quantum computing to future cyber risk.
- Methodology notes on the IPSOS BVA sample, weighting, and representativeness.
👉 Read Idemia's study on consumer security, trust, and digital adoption →
Digital trust and consumer control: what security teams need to know?
Explore further
Security has become a trust control, not a feature. Consumer services are now judged on whether the protection model is visible, understandable, and actionable to the user. That shifts security from a back-end assurance topic into a digital trust requirement that affects adoption, retention, and fraud tolerance. For identity teams, the practical consequence is that authentication and recovery design are now part of product trust, not just risk management.
A question worth separating out:
Q: What should organisations do when AI and quantum risk starts shaping customer expectations?
A: Treat emerging threats as part of the trust roadmap, not just the architecture roadmap. Update customer messaging, map post-quantum readiness to cryptographic planning, and connect AI fraud concerns to detection and verification controls. The goal is to show that future risk is being addressed before it becomes a trust failure.
👉 Read our full editorial: Digital trust now depends on stronger consumer security controls