Site navigation

Report: IT Leaders Are First Targets in 69% of Cyber-Attacks

Tom Quinn

,

human risk in cyber
Overlooked security basics and unfounded overconfidence among IT leaders are leaving firms wide open to attack.

Even with AI and automation fast taking control of cyber defences, one major vulnerability refuses to be patched – the human factor. 

Long viewed as the weak link in cyber, new data from Arctic Wolf shows that human error, complacency, and poor digital hygiene have contributed to a 20% spike in cyber-attacks this year for UK firms alone.

Polling more than 1,700 IT leaders and end users worldwide, Arctic Wolf’s Human Risk Behavior Snapshot found that despite 97% of firms having security awareness training in place, nearly two-thirds of IT leaders and half of employees admit to clicking malicious links.

More worrying, a fifth of IT leaders who clicked phishing links didn’t report the incident, a concerning trend given that senior leadership teams are a prime target, with 39% hit by phishing attempts, 35% facing malware infections, and 31% the victims of social engineering.

In all, Arctic Wolf found that 69% of IT leaders have been the initial victims of cyber incidents, but 76% said they were confident that they wouldn’t fall for an attack – a complacency that is leaving organisations vulnerable.

The report warns that misplaced confidence can lead to firms not investing in the right security technology, downplaying the threat of phishing, or being less on guard for potential lures in their inboxes.

It also leads to security basics being neglected. The study found that only 54% of organisations enforce MFA for all users, giving attackers the easiest path inside networks, while more than half (51%) of IT leaders admitted to having disabled security measures on their systems.

This, in particular, is becoming a more serious concern with the rapid introduction of AI, with the majority of leaders (80%) and employees (63%) now using genAI tools in their work.

Arctic Wolf found that 41% of employees and almost two-thirds (60%) of IT leaders admitted sharing confidential information with an LLM, showing that strict guardrails and governance should be in place around the use of AI tools.


Recommended reading


The figures also emphasise the need for better training, both with AI and in regards to cybersecurity measures in general. Arctic Wolf found that firms using corrective training report an 88% reduction in risk, with 82% being confident in their ability to prevent a cyber-attack.  

“When leaders are overconfident in their defences while overlooking how employees actually use technology, it creates the perfect conditions for mistakes to become breaches,” said Adam Marrè, senior vice president and chief information security officer at Arctic Wolf. 

“Progress comes when leaders accept that human risk is not just a frontline issue but a shared accountability across the organisation. Reducing that risk means pairing stronger policies and safeguards with a culture that empowers employees to speak up, learn from errors, and continuously improve.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data