Site navigation

Human Error Costing UK Business Billions in Data Breach Losses

Tom Quinn

,

human error data breach
“As AI becomes more integrated into everyday systems and business processes, the overall attack surface continues to grow, creating new entry points for exploitation within interconnected digital environments,” said Michael Field, Workflo Solutions.

Companies may be pouring millions into cutting‑edge, AI‑focused security, but a fresh warning from Workflo Solutions suggests they may be focusing on the wrong threat, with human error still the most exploited vulnerability for many businesses.

Marking the beginning of CyberScotland Week, the West Lothian managed service provider has cautioned that too many employees are not keeping pace with the capabilities of hackers, resulting in UK firms losing billions in data breach costs every year.

Studies have shown that more than 95% of data breaches in the UK are rooted in human error, with significant incidents, categorised as costing at least £500, averaging nearly £195,000 per business.

That adds up to a staggering £14.7 billion worth of damage every year to the UK economy.

Workflo said that the most common human errors include falling for phishing scams, using weak or compromised credentials, misconfiguring security settings, and falling victim to social engineering, showing that the biggest weaknesses stem from everyday behaviour, not advanced cyberattacks.

Human behaviour has long been recognised as a major weak spot in security stacks, with recent research from KnowBe4 finding that distraction and a lack of security awareness training were the primary reasons employees fall victim to cyber-attacks, while a similar study last year from Mimecast identified compromised, negligent or careless staff as the source of most data leaks.

To give businesses an extra helping hand during CyberScotland Week, Workflo Solutions said it plans to offer 200 businesses a free dark web domain audit, but also stressed the need for firms to create a strong security posture, beginning with a culture where cyber security feels simple, relevant and part of everyday work.


Recommended reading


The firm also said that businesses should look to keep cyber training short, frequent and practical, focus on using real examples staff might encounter, and maintaining clear policies and easy routes to report suspicious activity.

“As AI becomes more integrated into everyday systems and business processes, the overall attack surface continues to grow, creating new entry points for exploitation within interconnected digital environments,” said Michael Field, Workflo Solutions’ managing director.

“It is therefore vital that we come together during CyberScotland Week to raise awareness, boost resilience and reduce the risk of human error.”

Tom Quinn

Staff Writer, DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences