As cybersecurity and digital forensic professionals, we stay abreast with the latest hardware and software that protects digital landscapes and increasing threat surfaces. Here’s the problem. According to IBM’s Cost of a Data Breach 2022, over 95% of all data breaches are due to human error.
Think about how many emails your employees send and receive each day, how many cloud-based software platforms your organisation uses, the various places where data is collected and stored, and how many devices are connecting to your network from both inside and outside your firewalls. Attack surfaces are larger than ever before because of the number of vectors they hold. Any attack vector, if accessed by an unauthorised user, opens the door to potential data breaches or increases the likelihood of malware and ransomware attacks.
Mimecast’s State of Email Security 2023 report confirms that email remains the number one attack vector for threat actors, most likely because it’s such an easy door to get through. 82% of respondents to Mimecast’s study report higher volumes of email, 74% are seeing more email-based threats and 76% are expecting to face serious consequences from an email-based attack. Now consider that IBM’s research suggests that 97 per cent of users can’t recognise even a crude phishing email when they receive one. That door is wide open.
The reality facing most security leaders isn’t only that each member of an organisation can potentially be an entry point for cyberattackers, but that in most cases that’s exactly what they are. It’s not a case of ‘if’ a breach will occur but ‘when’ unless businesses can turn their people into human firewalls.
Here’s an important cyber security culture shift that we are working with our clients to instil. Data from the Psychology of Human Error 2022 report released by Tessian indicates that one in four employees implicated in breaches are dismissed within a year. More than half of those breaches occurred when employees, deceived by an attacker posing as a senior executive, engaged with a phishing email. We’ve seen similar incidents. People make mistakes, breaches occur, and the response is to blame the individual. Unfortunately, not only does this not address the problem of why the errors are happening in the first place, but it creates a culture in which employees won’t immediately report if they think they’ve been targeted or they’ve made a mistake.
Accountability and awareness must work together
If penalising employees isn’t the solution, what is? While employees must be held accountable, the emphasis should shift towards educating and equipping them to handle future challenges more proficiently. The goal is constructive engagement, not just reprimanding employees.
Many organisations have efficiently reduced error opportunities by investing in robust cyber defences and supportive technologies. Common tools include antivirus solutions, software patches, virtual private networks, vulnerability scans, and increasingly, encryption.
But cybersecurity awareness still lags. Typically, employees receive brief training during onboarding, followed by occasional refresher courses. Sporadic training just isn’t enough in this ever-evolving threat landscape.
Addressing human error requires a dual-pronged strategy: minimising potential pitfalls and enhancing user education. By reducing the avenues for mistakes, individuals face fewer tests. Coupled with increased awareness, this reduces the likelihood of missteps even when presented with opportunities to (accidently) let an attacker in.
For an organisation to be truly cyber-aware, every employee must be proactive in understanding and countering cyberthreats. This culture is cultivated when leaders inspire their teams to adopt specific mindsets and practices, which is the very essence of corporate cybersecurity training.
Here are a few key areas to focus on:
Prioritise password security: Despite its vulnerabilities, ‘123456’ remains a popular password choice. Encourage the use of complex passwords, frequent changes, and unique passwords for different accounts. Password management tools can assist users in maintaining strong, unique passwords without the challenge of remembering each one.
Stay updated: Cybercriminals are ever-evolving, continually seeking software vulnerabilities. Once identified, developers often release patches promptly. However, user procrastination in updating can lead to breaches. Timely updates are vital.
Adapt to remote work: The rise of remote work necessitates innovative communication strategies to emphasize security. While in-office reminders were once effective, the hybrid workplace demands digital methods. Gamification can be particularly useful, ensuring user engagement and retention.
Empathetic training: Training facilitators should be approachable, willing to address even basic questions. Addressing misconceptions, such as the indifference towards password re-use, is crucial.
Enhance cybersecurity training: If human errors persist, organisations must prioritise finding the reason why, potentially uncovering motivational gaps. Emphasizing the importance of cybersecurity and offering continuous support to employees is the best strategy to prevent breaches.
As a KnowB4 partner, Cyanre and Cybercom support the importance of cyber awareness training, building a cyber-aware culture and giving employees the knowledge and tools to become human firewalls. To find out more, connect with our team at info@cyanre.co.za