36 percent of cybersecurity breaches are caused by personnel

Kaspersky Head of Information Security Alexey Vovk stated, "In addition to external cybersecurity threats, there are many internal factors in any organization that can lead to cyber incidents."

12punto

Kaspersky has announced that information security breaches committed by personnel cause as much damage as hacking.

According to the statement from Kaspersky, the company conducted research to learn the views of IT security professionals working for SMEs and enterprises worldwide regarding the impact of employees on corporate cybersecurity.

The research, which aimed to gather information about different employee groups affecting cybersecurity by considering both in-house staff and external actors, revealed that violations of information security policies by employees, as well as actual mistakes, are among the biggest problems for companies.

Participants from organizations around the world stated that intentional actions to break cybersecurity rules have been taken by both IT and non-IT employees over the last two years.

In terms of individual employee behavior, the most common problem stems from employees intentionally doing things that are prohibited or failing to do things that are required. Participants in Turkey stated that 14 percent of cyber incidents in the last 2 years occurred due to the use of weak passwords or failure to change them in a timely manner.

Another reason for 36 percent of cybersecurity breaches is personnel visiting insecure websites. Meanwhile, 21 percent report that they have encountered cyber incidents because employees did not update system software or applications when necessary.

"IT IS IMPORTANT TO IMPLEMENT AN INTEGRATED APPROACH TO CYBERSECURITY"

In the statement, Kaspersky Head of Information Security Alexey Vovk, whose views were included, stated that in addition to external cybersecurity threats, there are many internal factors in any organization that can lead to cyber incidents, noting, "As the statistics show, employees from any department, whether they are IT security experts or non-IT professionals, can negatively affect cybersecurity both intentionally and unintentionally."

Emphasizing the importance of considering methods to prevent information security policy violations while ensuring security, Vovk noted the following:

"It is important to implement an integrated approach to cybersecurity. Across the research, while 26 percent of cyber incidents are caused by violations of information security policies, 38 percent of breaches occur due to human error. Since these figures are concerning, it is necessary to establish a cybersecurity culture in the organization from the very beginning by developing and implementing security policies and increasing cybersecurity awareness among employees. This way, personnel will approach the rules more responsibly and understand the potential consequences of their violations more clearly."