Nearly two-thirds (61%) of US firms have experienced insider data breaches in the past two years, according to a new OPSWAT report conducted by the Ponemon Institute.
On average, affected organisations reported eight insider incidents involving unauthorised access to sensitive and confidential files. These breaches were linked to both unintentional and malicious insider activities, with costs per organisation averaging $2.7m. Financial impacts included regulatory fines, reduced workplace productivity, and loss of customer data.
US IT and IT security practitioners surveyed for the study identified data leakage from malicious and unintentional insiders as the most serious risk to file security at their organisations (45%). This was followed by file access visibility and control (39%), and malicious files and applications from third-party vendors (33%).
Malicious insiders were defined as employees or contractors deliberately stealing or leaking data for reasons such as sabotage or financial gain. Unintentional insiders were described as staff who leaked data due to negligence or being tricked by external actors, including examples such as posting sensitive information on publicly accessible AI tools.
File Storage Tools Seen as Most Vulnerable
The study found that file storage environments are considered the most at-risk location for data security, cited by 42% of respondents. This category included on-premises systems such as SharePoint and network-attached storage (NAS) devices.
Web file uploads were ranked as the next most vulnerable environment (40%), followed by web file downloads from websites or SaaS platforms and collaboration tools such as Microsoft Teams (39%).
Cloud storage services, including Google Workspace, were named by 29% of respondents, while SaaS applications such as Dropbox were cited by 23%.
Mixed Views on Generative AI
The OPSWAT report, published on 4 September, also examined how organisations are approaching generative AI.
Nearly a third (29%) of respondents said their organisations have banned generative AI tools altogether, while 19% said they have no plans to adopt them. Only 25% of organisations have a formal policy in place for generative AI use, with 27% instead opting for an ad hoc approach.
Recommended reading
- API and Bot Attacks Cost Businesses £141 Billion A YearÂ
- NCSC Issues Advisory to Combat China-linked Cyber Threat
- NCSC Releases Cyber Incident Response Guidance for CEOs
Despite this caution, a significant proportion of firms see AI as integral to their file security strategies. One-third (33%) said AI already forms part of their file security approach, and 29% plan to add AI capabilities by 2026. Of those, 59% said AI is very or highly effective in enhancing file security maturity.
In terms of practical deployment, 29% of respondents said they are piloting generative AI technology to unlock files, while 18% reported the tools are already in production.





