Human error was the top contributor to data breaches in 2024, with 95%, according to a new study by Mimecast.
Insider threats are driving these figures, the study found, as just 8% of staff account fro 80% of these incidents.
The Mimecast report found that almost half (43%) of respondents saw an increased in internal threats or data leaks that were routed in compromised, negligent or careless staff in the past year.
Two thirds (66%) are expecting data loss from insiders as a result of this trend over the next year. A third (33%) still fear human error in the handling of email threats.
An insider-driven data exposure, loss, leak, and theft event would cost respondents’ organizations an average of $13.9 million, the report found.
Further, while 87% of respondents say that security awareness training has helped employees spot cyber-attacks, but two in three (66%) are still concerned that data loss from insiders will increase in 2025, and a third (33%) still fear human error in the handling of email threats.
Over half of organisations are also saying that they need an increased budget for cybersecurity staffing (57%), third-party services (57%), and collaboration tool security (52%).
Recommended reading
- Report: Human Error a Huge Component of ‘High-Severity’ Cyber-incidents
- CTOs: Human Error Is the Biggest Cyber Threat
- NCSC Warns Ransomware Threat to Rise with AI
While most organisations (96%) say formal security strategy has improved their cybersecurity risk level, but 61% say that it is inevitable or likely that their organisation will suffer a negative business impact from an attack linked to a collaboration tool in 2025.
In relation to this, 79% of respondents agree the use of collaboration tools poses new threats, and 95% expect to see email security challenges in 2025, demonstrating the need for strong email and collaboratiol tool security.
When it comes to AI, about four in five (81%) are concerned about GenAI leading to sensitive data leaks, and just over half (55%) are not fully prepared with specific strategies for AI-driven threats, demonstrating the continued need for organisations to implement their own AI-based platforms.





