Search
Close this search box.

Untrained Staff as Greatest Cyber Risk

This is compounded by staff training ranking as one of the weakest progress categories measured against the NIST cybersecurity framework. The majority of executives (87 percent) around the world cite untrained staff as the greatest cyber risk to their business.
cyber

This is compounded by staff training ranking as one of the weakest progress categories measured against the NIST cybersecurity framework. Contributor Anthony Dagostino, Global Head of cyber risk – Willis Towers Watson.

The majority of executives (87 percent) around the world cite untrained staff as the greatest cyber risk to their business according to a new report from “The Cybersecurity Imperative” – a global thought leadership program produced by independent researcher, ESI ThoughtLab in conjunction with Willis Towers Watson and other organizations specialized in cybersecurity and risk management. Compounding this finding is the fact that staff training is ranked among the categories to have made the least progress when measured against the National Institute of Standards and Technology (NIST) cybersecurity framework.

For the Cyber Security Imperative, ESI Thought Lab surveyed 1,300 organizations with revenues ranging from under $1 billion to over $50 billion, across multiple industries spanning APAC, Europe, US/Canada and Latin America.

The research also identified the most common types of attacks to include malware/spyware (81 percent) and phishing (64 percent), with external unsophisticated hackers (59 percent) and cyber criminals (57 percent) identified as the next biggest external threats. Based on scores relating to progress on the NIST cybersecurity framework, ESI ThoughtLab segmented companies into three stages of cybersecurity maturity: beginners, intermediates and leaders.

The survey found that a company’s threat perception varied based on the firm’s cybersecurity maturity. For example, cybersecurity leaders tend to focus more on “Hacktivists” (52 percent) and malicious insider threats (40 percent), whereas cybersecurity beginners spend more time worrying about external threats (42 percent), such as partners, vendors, and suppliers.

Additionally, the research highlights that when it comes to cyber resiliency, or post-cyber incident processes, cybersecurity leaders invest more in cyber resilience versus their beginner counterparts. As companies become more advanced in cybersecurity, they increase their investment in cybersecurity resilience, with cybersecurity beginners spending 14 percent of their cyber budget and cyber leaders spending 18 percent on recovery.

Some other key findings around cybersecurity maturity and investment in cyber risk include:

  •  91 percent of cybersecurity leaders feel their investment is adequate to meet their needs
  • 33 percent of cybersecurity beginners view their investment as adequate to meet their needs

73 percent of companies plan to use behavior analytics as a cybersecurity tool over the next two years; 80 percent of companies have at least a small amount of cybersecurity insurance, with healthcare companies averaging one of the highest amounts ($16.4 million) and manufacturing averaging one of the lowest ($8.6 million)

“Leaders in cybersecurity are devoting significant resources towards protecting IT and risk functions within their organizations against external threats, but employee processes and training as well as corporate culture play a more integral role than many realize.” As the report highlights, “The vast majority of cyber incidents result from employee behavior and human error,” says Anthony Dagostino, global head of cyber risk, Willis Towers Watson. “In addition to mitigating cyber threats through technology and risk transfer, cyber managers need to take a step back and assess their organizations cyber defenses within. Cyber managers must adopt a continuous assessment strategy, one that focuses on the overall culture of engagement, talent preparedness and the role of technology and risk transfer.”


Receive more HR related news and content with our monthly Enewsletter (Ebrief)

Read more

Latest News

Read More

Keep your views to yourself and expect no change

16 April 2024

Newsletter

Receive the latest HR news and strategic content

Please note, as per the GDPR Legislation, we need to ensure you are ‘Opted In’ to receive updates from ‘theHRDIRECTOR’. We will NEVER sell, rent, share or give away your data to third parties. We only use it to send information about our products and updates within the HR space To see our Privacy Policy – click here

Latest HR Jobs

University of Reading – Human ResourcesSalary: £27,979 to £32,982 per annum

Trust Head of Human Resources. Grade 11 SCP 31-34 £45,416 – £48,706. Full Time, 36 hours per week, Full Year. The main purpose of the

Come and join the NCA Family. This is the place where we support colleagues to be their professional best so they can provide excellent patient

Salary Scale £44,000 – £50,000. Responsible to Director of Finance and Workforce. Closing Date 28th April 2024. Interviews Planning for w/c 13th May 2024. £44,000

Read the latest digital issue of theHRDIRECTOR for FREE

Read the latest digital issue of theHRDIRECTOR for FREE