Tessian’s latest Psychology of Human Error report has revealed that 29% of respondents have sent work emails to the wrong person.
Arguably even more concerning, 39% of employees have sent an email with the wrong attachment in the last 12 months. This is worrying as it raises a data protection issue depending on what’s being sent.
While the percentage of employees who have sent emails to the wrong person has dropped since 2020 (by 8%), the report found that the consequences of making mistakes that compromise cybersecurity have become more severe.
The percentage of people who said their business lost a customer or client due to them sending an email to the wrong person went up from 20% in 2020 to 29% in 2021. In addition, 21% of employees said they lost their job after making the error – up from 12%.
As well as reporting the accidental data loss to their customers – something 35% of respondents said they did – businesses also had to report the incidents to regulators.
In fact, the number of breaches reported to the ICO, caused by data being sent to the wrong person on email, was 32% higher in the first nine months of 2021 than the same period in 2020.
With harsher consequences in place, Tessian’s report reveals fewer employees are reporting their mistakes to IT departments. One in five (21%) didn’t report security incidents, versus 16% in 2020, resulting in security teams having less visibility of threats in their organisation.
To Josh Yavor, Chief Information Security Officer at Tessian, businesses need to encourage employees to admit to mistakes, free of shame.
On this, he said: “Rewards are far more effective than punishment. If employees feel uncomfortable in reporting security mistakes, security teams will never have full visibility into these threats.
“So rather than scaring employees into compliance, encourage employees to engage with security by creating positive security experiences so that you can cement a partnership mindset between security teams and staff.
“Those positive incentives will help combat security nihilism and build strong security cultures.”
When asked why emails were sent to the wrong person, 50% of employees said they were under pressure to send the email quickly – up from 34% in 2020. Nearly half of respondents said it was because they weren’t paying attention, while 47% said they were distracted – up from 41% in 2020.
Academics who contributed to the report suggest these increases in mistakes caused by stress and distraction could be linked to changes to working environments over the past 18 months.
Recommended
- Scottish unicorns help push UK tech valuation to $1 trillion
- Data Protection Summit 2022 | What is the current state of legislation?
- UK could announce cryptocurrency regulations in coming weeks
Jeff Hancock, Professor of Communication at Stanford University explained: “With the shift to hybrid work, people are contending with more distractions, frequent changes to working environments, and the very real issue of Zoom fatigue – something they didn’t face two years ago.
“You also have to consider the impact that the Great Resignation is having on people’s workloads. When stressed, distracted and tired, people’s cognitive loads become overwhelmed and that’s when mistakes happen.
“Businesses, therefore, need to understand how factors like stress affect people’s cybersecurity behaviours and take steps to support employees so that they can work productively and securely.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





