Understanding the Human Factor
- People are the weakest link: Analysts estimate that around 90% of data breaches involve human error, with stolen credentials and phishing accounting for about one-third of breaches.
- Human behaviour drives incidents: Studies in 2024 found that 74% of breaches involve a human element, so comprehensive training and risk management are essential.
Common Human Errors
- Clicking malicious links in phishing emails or attachments.
- Reusing passwords across personal and work accounts.
- Sharing files via unsanctioned apps or uploading sensitive data to insecure AI tools.
- Using unsecured Wi-Fi networks while traveling.
Best Practices for a Secure Workforce
- Use strong, unique passwords for each account.
- Enable multi-factor authentication (MFA) on all accounts to prevent unauthorized access.
- Keep software up to date by promptly installing patches and updates.
- Think before you click: pause and verify email senders, domain names and links.
- Report suspicious emails or activities to IT or security teams immediately.
- Use secure networks: avoid public Wi-Fi or use a VPN when accessing corporate resources.
Effective Awareness Training
- Continuous and frequent: training should be ongoing, not a one-off event.
- Role-specific: tailor content to employees’ responsibilities and risk exposure.
- Interactive and engaging: incorporate quizzes, simulations and phishing tests.
- Measured and improved: track participation and improvement to refine programmes.
Additional Insights
- Real-world impact: A spear-phishing attack on Magellan Health compromised information of 364,000 individuals, showing targeted phishing remains a major threat.
- Credential compromise: IBM’s 2024 Cost of a Data Breach report found stolen credentials were the initial attack vector in 16% of breaches and phishing in 15%.
- Why invest in training? Organizations with robust awareness programmes and AI-driven security tools reduce the average cost of a breach by up to $1.8 million.
Ready to strengthen your team’s cyber defenses? Reach out to our certified consultants or explore our Cybersecurity Career Launch and Cybersecurity Awareness Training for Employees programmes to build a security-aware culture.


