CISOs Identify Human Error as the Primary Threat to Cybersecurity

The Human Element in Cybersecurity: Why It’s Crucial to Address Human Error

When discussing cybersecurity, the spotlight often shines on technology—examining how cybercriminals exploit it for attacks and the various tools organizations deploy to safeguard their systems and data. However, this focus frequently neglects the most critical aspect of cybersecurity risk: human error.

The Human Factor in Cybersecurity Risks

According to Proofpoint’s 2024 Voice of the CISO report, a substantial 74% of chief information security officers (CISOs) have identified human error as their top cybersecurity concern, a significant increase from last year’s 60%. This disparity highlights a communication gap between CISOs and board members, with only 63% of board members acknowledging human error as a major risk. This suggests that CISOs need to educate both the leadership and staff on the impact of human factors.

The survey also revealed that the leading causes of data loss incidents are linked to employee actions. The primary cause (42%) was negligent behavior, such as mishandling data. Other significant factors included malicious insiders (36%), compromised employee credentials (33%), and lost or stolen devices (28%).

Supporting this, the IBM 2024 threat index shows that 30% of attacks begin with phishing. Although phishing attacks have decreased in frequency and as initial attack vectors since 2022, the ongoing enhancement and reassessment of phishing defense mechanisms are likely contributing to this decline.

It’s important to note that while human mistakes may lead to breaches, they are not always the individual’s fault—except in cases of criminal insider activity. Organizations must adopt a proactive stance on cybersecurity, incorporating comprehensive training and robust processes to minimize risk.

Strategies for Mitigating Human Risk in Cybersecurity

Addressing human-related cybersecurity risks requires more than a single initiative. A comprehensive approach that fosters a culture of cybersecurity is essential. Here are three strategies to manage human risk:

  1. Leverage AI to Mitigate Human Error

AI tools can anticipate human behavior and enhance protection against human-related risks in cybersecurity. The Proofpoint report indicates that 87% of global CISOs are exploring AI-driven solutions to address human error and sophisticated human-focused threats.

  1. Implement Thorough and Continuous Employee Training

Many organizations offer training, but it often falls short of effecting real behavioral change. To design an effective program, tailor training to the specific needs of different employees based on past incidents. Rather than relying on annual sessions, consider regular monthly updates to maintain engagement. Also, integrate cybersecurity training into the onboarding process to ensure every new employee is well-informed from the start.

  1. Foster a Cybersecurity-Centric Culture

For employees to view cybersecurity as a shared responsibility, they need to perceive it as integral to their roles. Creating a cybersecurity-focused culture involves ongoing dialogue about its importance from leadership and throughout the organization. Training alone is insufficient; embedding cybersecurity into the organizational ethos is crucial.

Emphasizing Human Risk in Cybersecurity

Cybersecurity is inherently a human issue: both in terms of those who perpetrate attacks and those who can prevent them. By prioritizing the human element and adopting a long-term strategy that engages all employees, organizations can significantly reduce their cybersecurity risks. Transforming this approach into a core aspect of the organizational culture will empower employees to contribute effectively to cybersecurity efforts.

More Articles & Posts