Half of employees are afraid to report security mistakes to their bosses, new research from ThinkCyber has found.
The survey found that half of employees said they would not feel free from repercussions if they reported a mistake within their organisation.
Respondents were also asked about security behaviours they witnessed in their organisation that caused the most concern.
Clicking on links in emails (53%), sharing corporate data outside of the business (53%), and sharing usernames and passwords (51%) were the most commonly cited alarming activities.
Worryingly, employees felt that security training and awareness did little to change the risky behaviour of their colleagues.
Concerningly, three in five admitted that they only receive training once every few months, or even just once a year. This raises some serious alarm bells as threats continue to rapidly develop and consistent training is required to defend against emerging cyber risks.
Part of the problem is the lack of progress tracking and measuring the success of security awareness programmes.
42% of respondents felt that their organisation could not even somewhat prove whether their current security awareness training is changing risky behaviour.
Further, half of respondents said they would not feel free from repercussion if they reported a mistake within their organisation, which could actually deter workers from reporting potential security risks.
While around half (51%) of respondents believed that most people across the business were focused on security, 39% felt only the executives and security teams were focused on it.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
“Cybersecurity should be a concern for everyone, so pinpointing which user groups need extra help with safe practices is crucial for any business,” Tim Ward, ceo and co-founder Think Cyber Security ltd said.
“A training programme that’s flexible and enjoyable can make all the difference, boosting staff engagement and giving cyber professionals greater confidence in their team’s ability to make smart security decisions.”





