HomeSecurityBusinesses: Employee non-compliance with security protocols leads to cyberattacks

Businesses: Employee non-compliance with security protocols leads to cyberattacks

A new report from Kaspersky has revealed that a not complying employees with the security protocols established by companies. This figure closely rivals the 20% attributed to external intrusion attempts.

cyberattacks businesses

Kaspersky explained that, contrary to prevailing beliefs that human error is the main cause of cybersecurity , the reality is different.

By speaking with IT security professionals in small and medium-sized businesses and other businesses worldwide, the company wanted to understand the impact of different individuals on companies' cybersecurity posture.

See also: Citrix: Administrators must terminate NetScaler user sessions

It found that intentional violations of security protocols by employees (both IT and non-IT) played a significant role in cyberattacks. In fact, non-compliance with security policies by IT security officers led to 13% of incidents, non-compliance by IT professionals led to 12%, and non-compliance by other employees (non-IT) led to 4% of security incidents.

The study revealed that 22% of security in businesses were due to the intentional use of weak passwords or failure to change them in a timely manner. In addition, 18% were linked to staff visiting unsecured websites, while 25% resulted from neglecting system software or regularly applying updates.

Also, the use of insecure devices to share data led to cybersecurity incidents in 14% of companies. Particularly worrying was the finding that 20% of malicious actions were committed by employees for personal gain . In the financial services sector, this is even more common.

See also: Lumma: Can restore expired Google auth cookies

Alexey Vovk, security expert at Kaspersky, stressed the importance of cultivating a cybersecurity culture in companies.

“It is essential to create a cybersecurity in an organization from the beginning, by developing and enforcing security policies, as well as raising employee awareness of cybersecurity,” Vovk explained.

“Thus, staff will approach the rules more responsibly and clearly understand the possible consequences of their violations“.

security protocols
Businesses: Employee non-compliance with security protocols leads to cyberattacks

Organizations can take several steps to strengthen their employee policies and prevent cyberattacks. One of the first steps is to create and enforce a comprehensive security information. This includes defining the security standards, procedures, and rules that employees must follow to protect the company's information.

Additionally, businesses should provide education and awareness to their employees about cybersecurity threats and the importance of adhering to security policies. This can be done through training programs, informational events, and ongoing communication with employees.

See also: DarkGate and PikaBot malware fill the gap left by Qakbot (QBot)

Businesses should also implement strict access and privilege policies in. place to ensure compliance with these policies.

Finally, organizations must keep systems and software up-to-date and secure. This includes installing required security updates and patches, using antivirus software, and implementing strict policies to prevent and detect malware.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS