Published Date:
Nearly half of all successful cyberattacks start with a negligent employee. Why is that and what can be done about it.
If you google this question, then it answers you that it’s because of ‘Falling for Phishing and Social Engineering Scams’, ‘Poor Password Management and Credential Hygiene’ and ‘Negligent Data Handling and Unsecured Devices’. Of course, these are important reasons, but this answer is much more helpful if you take a step back and realize that nearly all statements, so to speak, are about people!
And that’s how it is today, it’s proven that at least 47% [1] of successful cyber-attacks start with a careless employee and mostly with an phishing email. Why does this happen, why do employees get caught up in it? Our experience shows that there are three main reasons why employees fall for malicious emails:
If you want to counter this, then correcting technical deficiencies or misconfigurations of the PC, server and the network environment is a relatively simple measure. Most company computers today have a firewall activated, the latest updates are installed and backups are made. At least the basis for secure work is laid. Are misconfigurations then of any importance at all? Of course, because something like this can be exploited by cybercriminals if they were to gain access to the company network.
Weak IT security skills among employees are another reason why they get hacked. The demands on employees’ security know-how have increased considerably in recent years, as today an employee must have knowledge in around 20 IT security domains. This starts with
And then we come to the most dangerous reason why employees are hacked: Human behavior patterns.
From the perspective of cybercrime prevention, personal behavior – and attitude[2] – such as gullibility, ignorance, unreflective sense of duty, overconfidence, carelessness and so on are the greatest risks that can lead to a successful cyber-attack. It is not without reason that 47% of successful hacks start directly with a careless colleague.
[We | the companies | the management] are struggling with technical weaknesses, a lack of IT security knowledge and, above all, with insufficient / outdated behavior patterns among our employees.
In view of this, it is clear what is being done about it: We train and improve the risk behavior (read: awareness) of our staff. And this is best done with a well-defined cybersecurity awareness program, time and with the help of a tool, which can improve behavior and not only attitude. CYBERDISE achieves exactly that, because it raises awareness by up to 60% compared to conventional anti-phishing solutions 🙂 [2]
A good cybersecurity awareness program is comprehensive and mostly online. It pursues the sensitization of employees with at least these measures:
The ideal tool for this is the CYBERDISE Awareness. It greatly simplifies the implementation of an awareness program and drives the behavioral change. With the solution
Learn more at https://cyberdise-awareness.com/
#humanauthored