Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Top Five Ways The Human Factor Threatens Your Data Security
Articles

Top Five Ways The Human Factor Threatens Your Data Security

Ilia SotnikovBy Ilia SotnikovMarch 26, 2019Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Data protection regulations have become stricter and now focus on protection of data privacy of consumers. New state regulations like the California Consumer Privacy Act (CCPA) force businesses to make it their top priority. However, many companies lack a strong cybersecurity culture and therefore become more vulnerable to security and compliance issues. According to a whitepaper by Osterman Research, only 18 percent of organizations have a program to train employees on the CCPA, which comes into force in less than a year. 

Lack of training and failure to implement other security practices increase risk of human errors, which often lead to data breaches. Here are the five most common mistakes that your employees make and recommendations you need to follow in order to minimize potential damage. 

  1. Fall forphishing schemes 

Phishing attacks are the most common way for hackers to easily gain access to sensitive data. The attack can be opportunistic or targeted. An attacker sends a malicious email that seems to be from a trusted source, and waits until an employee opens it. To minimize risk, I recommend you tell employees about cybersecurity, not only when you hire them, but also train them regularly and effectively. For example, use a series of short videos that show how social engineering attacks work in real life. A good practice would be to run simulation tests periodically to check whether the training was effective. Implement anti-spam and email filtering tools to mitigate the risk even further.   

  1. Stick to badpassword habits 

Despite everyone talking about the importance of good password practices, employees still reuse passwords, forget to change them, use weak passwords (e.g. 12345 or qwerty) or even leave access credentials on sticky notes. These habits make it easy for attackers to steal or crack passwords, which may lead to a data breach. To avoid this, conduct training sessions dedicated to password practices and use password manager software that generates and retrieves complex credentials and stores them in an encrypted database. Also, consider using a password expiration tool that automatically reminds users to change their passwords before they expire.   

  1. Give unauthorized users access to corporate devices

When your employees let their friends or family members access employee-issued devices at home, this poses a threat to your IT environment. They may accidentally access sensitive data like the organization’s financial records or download malware that could damage your data. To avoid this threat, introduce an information security plan that everyone is familiar with, and encourage team leaders to ensure their teams follow these practices. Also, make sure your devices are password protected and employ two-factor authentication to all corporate devices and applications if possible.   

  1. Misdeliver information

It is not unusual for an employee to send an email with the company’s data to the wrong recipient. To avoid this, it is important to require encryption for all emails that contain sensitive information. In addition, employ pop-up boxes that remind senders to double check the email address when they’re emailing sensitive data. A good practice is to implement a data loss prevention (DLP) solution that tracks events that may cause information leakage and automatically takes action (e.g., prevents users from sending sensitive data outside of the corporate network).   

  1. Fail to update and secure privileged accounts

Privileged accounts are powerful, but security controls for preventing their misuse are often weak. The Netwrix 2018 IT Risks Report shows that only 38 percent of organizations update admin passwords once a quarter; others do it less than once a year. Meanwhile, if IT pros don’t update and secure passwords of privileged accounts, attackers can easily crack them and access the entire organization’s network. To prevent this, you need to implement least privilege principles and grant privileges only to those who really need them for specific tasks. Use two-factor authentication and establish separate administrative and employee accounts for IT personnel; admin accounts should be used only to manage specific parts of the IT infrastructure.   

No matter how strong your cybersecurity defenses are, people will still make mistakes. The Netwrix report discovered that 29 percent of organizations had to deal with human errors that resulted in data breaches over the last year. To minimize the risk of security incidents, you need to enable continuous control over your data, quickly detect suspicious activities and respond to incidents. Strong cybersecurity culture and effective training programs for employees can contribute to protecting your sensitive data and mitigating potential threats. 

Ilia Sotnikov
Ilia Sotnikov

Ilia Sotnikov is Security Strategist & Vice President of User Experience at Netwrix. He has over 20 years of experience in cybersecurity as well as IT management experience during his time at Netwrix, Quest Software, and Dell. In addition, Ilia is a regular contributor at Forbes Tech Council where he shares his knowledge and insights regarding cyber threats and security best practices with the broader IT and business community.

  • Ilia Sotnikov
    How to Defend Against High Cyberthreat Activity During the Holidays
  • Ilia Sotnikov
    Five Ways to Improve Your Security Posture, Fast
  • Ilia Sotnikov
    Top Cybersecurity Trends To Consider For The New Year
  • Ilia Sotnikov
    Top Seven Cybersecurity Ripple Effects From 2020

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}