Understanding the Human Factor

  • People are the weakest link: Analysts estimate that around 90% of data breaches involve human error, with stolen credentials and phishing accounting for about one-third of breaches.
  • Human behaviour drives incidents: Studies in 2024 found that 74% of breaches involve a human element, so comprehensive training and risk management are essential.

Common Human Errors

  • Clicking malicious links in phishing emails or attachments.
  • Reusing passwords across personal and work accounts.
  • Sharing files via unsanctioned apps or uploading sensitive data to insecure AI tools.
  • Using unsecured Wi-Fi networks while traveling.

Best Practices for a Secure Workforce

  • Use strong, unique passwords for each account.
  • Enable multi-factor authentication (MFA) on all accounts to prevent unauthorized access.
  • Keep software up to date by promptly installing patches and updates.
  • Think before you click: pause and verify email senders, domain names and links.
  • Report suspicious emails or activities to IT or security teams immediately.
  • Use secure networks: avoid public Wi-Fi or use a VPN when accessing corporate resources.

Effective Awareness Training

  • Continuous and frequent: training should be ongoing, not a one-off event.
  • Role-specific: tailor content to employees’ responsibilities and risk exposure.
  • Interactive and engaging: incorporate quizzes, simulations and phishing tests.
  • Measured and improved: track participation and improvement to refine programmes.

Additional Insights

  • Real-world impact: A spear-phishing attack on Magellan Health compromised information of 364,000 individuals, showing targeted phishing remains a major threat.
  • Credential compromise: IBM’s 2024 Cost of a Data Breach report found stolen credentials were the initial attack vector in 16% of breaches and phishing in 15%.
  • Why invest in training? Organizations with robust awareness programmes and AI-driven security tools reduce the average cost of a breach by up to $1.8 million.

Ready to strengthen your team’s cyber defenses? Reach out to our certified consultants or explore our Cybersecurity Career Launch and Cybersecurity Awareness Training for Employees programmes to build a security-aware culture.

 

 

Penetration tester performing cybersecurity assessment

Ethical hacker monitoring unauthorized access and cybersecurity threats