Site navigation

10% of Staff Are Behind Three-Quarters of Cyber Risk

Tom Quinn

,

cyber risk
A minority of careless users are putting businesses at major cyber risk, with repeat offenders behind nearly three-quarters of all risky behaviour.

It’s not always hackers that cause the most security problems. Sometimes, too often, it’s a well-meaning teammate who forwards chain emails, uses “password123”, and always clicks the link. 

New research from cyber firm Living Security’s latest State of Human Cyber Risk Report has found that this small but consistent group of repeat offenders are behind most cybersecurity breaches, with just 10% of employees responsible for 73% of all risky behaviour. 

Drawing on data from more than 100 enterprises and hundreds of millions of user events, Living Security discovered that this small pool of incautious staff members is driving more than 65% of malware risks across businesses, almost 70% of compliance risks, and a staggering 75% of all risk associated with data loss.

The study found that more than half (55%) of users tend to do the same few things over and over. For example, while 53% of all organisations suffered from multiple phishing clicks, those actions were attributed to just 3% of employees.

While Living Security found that most staff (41%) can be described as ‘lawful, vigilant’ users, 8% work in a ‘chaotic, risky’ fashion. These are the individuals who keep security leaders up at night, with their actions routinely exposing organisations to a wide range of risks.

“Cybersecurity is no longer just about technology, it’s about behaviour,” said Ashley Rose, CEO and co-founder of Living Security.

“If we don’t understand who our riskiest users are, why they’re at risk, and how to help them improve, we’ll continue chasing symptoms instead of solving the root problem.”


Recommended reading


If greater understanding is the key, then firms have to begin by looking at their own security training regimen. The study found that organisations relying solely on security awareness training (SAT) have visibility into only 12% of risky behaviour.

The study found that, on average, companies could spot fewer than half of the actions linked to human risk. 

The good news, though, is that after rolling out targeted action plans, users spent 60% less time engaged in risky behaviour, and when it came to data loss specifically, that drop was even sharper, with a 98% reduction in time spent at risk.

“Security teams have always known the human factor plays a critical role in breaches, but they’ve lacked the visibility to act on it,” said Rose.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data