Kaspersky Lab: Business employees conceal 40% of IT security incidents worldwide – this data emerged from the new research by Kaspersky Lab and B2B International, “The Human Factor in IT Security: How Employees Make Businesses More Vulnerable from the Inside.”
With 46% of IT security incidents being caused by employees each year, this business vulnerability must be addressed at all levels and not just through the IT security department.

Kaspersky Lab Driving hackers to your door
Uninformed or indifferent employees are one of the main reasons for information security incidents – second only to traditional malware. While malware is constantly evolving, the sad reality is that the “evergreen” human factor can be an even greater risk.
In particular, employee carelessness is one of the biggest blows to a company’s defenses against digital threats when it comes to targeted attacks. While sophisticated hackers can always use specially designed malware and high-tech techniques to plan a heist, they will likely start exploiting the easiest entry point – human nature.
According to the research, one in three (28%) targeted attacks on businesses last year were phishing/social engineering in origin. For example, a careless accountant could easily open a malicious file that looks like an invoice from one of a company’s many contractors. This could take down the entire organization’s infrastructure, unknowingly making the accountant an accomplice to the attackers.
“Cybercriminals often use employees as an entry point into corporate infrastructure. Phishing emails, weak passwords, fake phone calls from tech support departments – we’ve seen it all. Even a simple flash card that might have been dropped in the office parking lot or next to the secretary’s desk can compromise the entire network – all it takes is someone inside the company who doesn’t know or doesn’t pay attention to security, and that device can easily connect to the network with devastating consequences,” commented David Jacoby, Security Researcher at Kaspersky Lab.
Sophisticated targeted attacks don’t happen to organizations every day – but conventional malware hits businesses en masse. Unfortunately, however, research also shows that when it comes to malware, uninformed and careless employees also play a significant role, causing malware “infections” in 53% of cases.
Kaspersky Lab Hidden: why HR and top executives should get involved
With personnel concealing incidents they have been involved in, the consequences can be very bad and this increases the overall damage that may have been caused. Even a single unreported event can indicate an even larger breach, and security teams need to quickly identify the threats they face in order to choose the appropriate mitigation tactics.
Staff would rather put their organisations at risk than report a problem because they fear punishment or are embarrassed to be responsible for something that went wrong. Some companies have introduced strict rules and imposed more responsibility on employees, rather than encouraging them to simply be vigilant and cooperative. This means that cyber protection is not only in the realm of technology, but also in the culture and training of the organisation. This is where HR and senior management need to get involved.
“The problem of concealment should be communicated not only to employees but also to senior management and HR. If employees are concealing incidents, there must be a reason. In some cases, companies introduce strict but vague policies and put intense pressure on staff, warning employees not to do “this or that” because they will be held accountable if something goes wrong. Such policies encourage fear and leave employees with only one option – to avoid punishment at all costs. If your cybersecurity culture is positive, based on an educational approach rather than a restrictive, top-down one, the results will be obvious,” comments Slava Borilin, Security Education Program Manager at Kaspersky Lab.
Borilin also points to an industrial safety model where a reporting and “learning from mistakes” approach is at the heart of the business. For example, in a recent statement, Tesla’s Elon Musk asked that any employee safety incident be reported to him immediately so that he can play a central role in change.
Kaspersky Lab The human factor: corporate climate and beyond
Organizations around the world have already recognized the problem of their staff making their businesses vulnerable: 52% of companies surveyed admit that staff is the biggest weakness in IT security. The need to implement staff-centric measures is becoming increasingly evident: 35% of companies are trying to improve security by providing staff training, making this the second most popular method of cybersecurity protection, following in the ranking the development of more sophisticated software (43%).
The best way to protect organizations from human-factor cyber threats is to combine the right tools with the right practices. This should include efforts by HR and senior management to encourage employees to be vigilant and seek help in the event of an incident. Training to raise staff awareness of security issues, providing clear instructions instead of multi-page documents, building strong skills and motivation, and promoting the right work environment are the first steps organizations should take.
When it comes to security technologies, most of the threats targeting uninformed or careless employees – including phishing – can be addressed with endpoint security solutions. These can meet the specific needs of small and medium-sized businesses as well as large enterprises in terms of functionality, default protection or advanced security settings to minimize risks.
Here you can find the full report.
