Opens in a new tab
vmblog logo 2024 wht (updated)

The Human in Machine: 6 Employee Mistakes That Lead to Cybersecurity Breaches

Share: 

David Marshall | Published: November 29, 2022

 

Image sourced from threatcop.com

You probably already have a good idea of how costly cybersecurity breaches can be. A breach can cause not only financial loss, but also huge damage to your organization’s reputation if you haven’t taken sufficient steps to protect against such incidents. However, did you know that 82% of cybersecurity breaches had some aspect of human involvement?

Human error can play a big part in lapses in your cybersecurity, yet much of that error can be easily prevented or mitigated. Lapses can affect what you think of as your business efficiency definition, so let’s look at the most likely cybersecurity breaches caused by human error.

6 cybersecurity breaches that could be caused by human error

1.    Incorrect email use

Including the wrong recipients in an email may sound harmless enough but it can lead to other cybersecurity breaches. The email may contain sensitive data or information or it may disclose email addresses to others. While a very basic human error, it can also be a very serious one and, depending on the seriousness of any breach, could mean that the organization involved faces fines from any regulatory bodies that govern data protection in their location.

2.    Sending documents to wrong recipients or insecurely

Another of the common cybersecurity breaches, this is also one that could lead to financial penalties. If one of your staff works on a hybrid or remote basis, they may send confidential documents to a personal email account so they can work on them later. The other scenario is sending to incorrect recipients who do not have the ‘clearance’ to view those documents.

3.    Falling foul of phishing scams

Phishing (or vishing) accounts for around 90% of all cybersecurity breaches. Human error plays a big part in these scams, for example if your staff give out confidential information or data to an unverified phone call or email contact. You can help prevent this kind of attack by making staff aware of how common they are and training them to be extremely careful of any request for information.

4.    Publishing confidential data accidentally

When it comes to human error in cybersecurity breaches, this has the potential to be one of the most damaging, depending on the sensitivity of the data. It can involve data being uploaded onto a public server rather than a secure one, which means it can be accessed by anyone. Someone could also accidentally publish data to a website or social media platform while mistakenly assuming that it can only be seen by certain people.

5.    Mistakes with software

It can often be tempting to take shortcuts when working. However, those shortcuts could lead to cybersecurity breaches that aid cybercriminals in accessing confidential information or data. Good examples of this type of human error are:

  • Ignoring software updates, especially with anti-virus software that offers regular updates to deal with new threats.
  • Disabling security features on software or firewalls that make it easier for hackers to access your system.
  • Downloading and using unauthorized software that may have vulnerabilities and can be easily compromised.

6.    Developing poor work habits

A lot of cybersecurity breaches happen because employees develop poor work habits. Getting too comfortable in your work habits, particularly the more repetitive ones, can lead to complacency and leave your system open to a cyberattack. Cybercriminals look to expose any vulnerability and you should address this in your organization. Some common bad habits include:

  • Using weak passwords.
  • Leaving your computer or device open and unattended.
  • Having passwords or other login info written down and left in the open.
  • Sharing documents or information via unsecured communication channels that offer no protection or encryption.
  • Leaving sensitive printed documents where anyone can access them.
  • Sharing data with unauthorized persons.

The takeaway

padlock-laptop 

The common factor in all these potential cybersecurity breaches is that they are, for the most part, easily preventable. Whether your staff are using cloud-hosted VoIP or email, there are simple steps they can take to ensure any confidential information is better protected. While you may also see human error as a staff issue, you as manager or owner do bear some responsibility.

If you want to reduce the level of human error in cybersecurity breaches, then you should have a comprehensive prevention and mitigation plan that includes the following:

  • Awareness training: hold regular meetings to ensure staff are up to date on the biggest cybersecurity risks. This can include scenarios where you test them in identifying suspicious activity.
  • Use the best antivirus software and solutions. Yes, it may cost you a little more but will offer a robust defense against many threats. Also be sure to keep any solution updated.
  • Develop a recovery plan. Although many data breaches are low level, you should have a recovery plan in case you suffer a major attack and lose data or functionality.

Taking even simple steps can reduce the likelihood of suffering major cybersecurity breaches. As the old saying goes, prevention is better than cure, and taking some basic precautions could prevent a breach that could be very costly. 

##

ABOUT THE AUTHOR

Grace Lau – Director of Growth Content, Dialpad

Grace Lau 

Grace Lau is the Director of Growth Content at Dialpad, an AI-powered cloud communication platform for better and easier team collaboration and first contact resolutions. She has over 10 years of experience in content writing and strategy. Currently, she is responsible for leading branded and editorial content strategies, partnering with SEO and Ops teams to build and nurture content. Grace has also written for other domains such as Workpuls and  WebSitePulse. Here is her LinkedIn.