More than a third (36%) of IT leaders have intentionally disabled security measures on their systems despite the cybersecurity risks, according to a new survey from Arctic Wolf, the security operations provider.
The news gets worse. According to data published in Arctic Wolf’s 2024 Human Risk Behavior Report, over a quarter (27%) of IT and cybersecurity leaders said they had sacked an employee for falling victim to a scam, even though 64% admitting to falling for phishing links themselves.
Even more shocking is the 68% of IT and cybersecurity leaders who admitted to reusing old system passwords, despite the increasing threat posed by the ability of attacker’s to obtain administrator credentials.
The research, compiled through a survey of more than 1,500 senior IT and security decision-makers and end users, shows that in cybersecurity the human risk factor remains a critical component of every procedure.Â
As the data makes clear, ever more advanced cybersecurity systems can be rendered essentially worthless if basic cyber-hygiene is taken for granted.
According to the report, 65% of IT and cybersecurity leaders who reuse passwords “sometimes” or “frequently” have experienced four breaches on average, while over half rely on either memory (29%), or written notes and spreadsheets (26%) to remember vital system passwords.
Employees aren’t much better. The results show that more than a quarter of employees keep using the same passwords for over three months, with 63% saying they only change their passwords when forced to by their employer.
End users are also worryingly lax about consistently locking screens when away from their workstations, another basic tenet of cyber-hygiene. Although required by 86% of IT leaders, less than half of end users (41%) said they followed the policy.
There also appears to be a mismatch between the security cultures of employees and management. Although 85% of IT and cybersecurity leaders think employees feel comfortable reporting security incidents, in reality only 77% of end users actually do.
That could be down to employee’s justifiable fears of getting let go for a security slip-up, with only a third (34%) of IT and cybersecurity managers ruling out termination for an employee who fell victim to a scam such as phishing.
Recommended reading
- Scot-Secure West | Proactive Security Made Simple and Human
- NCSC Warns Ransomware Threat to Rise with AI
- Security Awareness Training is Not Alleviating Breach Risk
Frequent training seems to be the best way to deal with gaps in security, with 84% of leaders who regularly receive and provide training being more confident about facing a cyber-attack, as well as being more likely to ensure cyber-hygiene is observed and create security policies around emerging threats, such as AI attacks.
“Cybersecurity isn’t just about technology—it’s about people,” said Adam Marre, Arctic Wolf CISO.
“As threat actors grow more sophisticated, security leaders must move beyond traditional security training methods and adopt a comprehensive human risk management strategy that will not only help them to better identify and mitigate threats, but more importantly foster a more proactive and security-conscious workforce.”





