Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Survey Reveals: 50% Of Respondents Face Cyberattacks Yearly — Employers Blame Employees
Study & Research

Survey Reveals: 50% Of Respondents Face Cyberattacks Yearly — Employers Blame Employees

ISBuzz TeamBy ISBuzz TeamSeptember 21, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
cyber atack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Around 24% of employees have never had any cybersecurity training, according to a new study by NordLocker. This survey also revealed that when it comes to responsibility for phishing attacks, ransomware attacks, and malware infections, respondents indicated that companies frequently shifted the blame onto employees and felt they should bear accountability for these types of threats.

The survey also reveals that a significant 54% of companies have encountered a cybersecurity incident within the past 12 months. These incidents encompass a wide range of security breaches, including phishing attacks, data breaches resulting from third-party vendor hacks, malware infections through malicious email attachments, and various other forms of cyber threats.  

The marketing industry has emerged as the most vulnerable to cybersecurity issues, particularly in relation to data breaches stemming from compromises within their network of third-party vendors.

Other findings:

  • About 25% of respondents wouldn’t know what to do in case of a cyberattack.
  • Only half of the companies use encryption.
  • Approximately 40% of companies have no dedicated person for cybersecurity incidents;
  • About 39% of respondents have sent an email to the wrong person at some point in time.

People store their personal information on their work computers

NordLocker research indicates that over 30% of respondents admit to storing their personal information on their work computers. While the percentage of individuals using work devices for personal purposes is relatively lower at 22%, this number still raises concerns and paints a worrisome picture. 

“Considering that one in five people utilize their work computers for personal tasks or to store personal data, the implications become more significant. This highlights the potential risks and security vulnerabilities associated with employees combining personal and work-related activities on company devices,” says Aivaras Vencevicius, head of product for NordLocker.

Vencevicius emphasizes that the practice of using work computers for personal purposes can have a significant impact on the overall security of company data, particularly when faced with threats like ransomware attacks. Hackers may exploit the personal information stored on these devices to manipulate employees into granting access to sensitive company resources.

The survey also reveals that 36% of respondents express a high level of concern regarding their own privacy when using their work computers. When questioned about the perceived threat of personal information leaks, an overwhelming 61% confirmed that they would view it as a serious and significant risk.

Identical passwords for home and work accounts 

The survey results indicate a trend among respondents, with 42% admitting to reusing passwords for both their home and work accounts. This behavior can be attributed to the fact that only 41% of participants claim to remember their passwords, leading them to opt for convenience over security by using the same passwords across multiple applications and systems.

Regarding password change frequency, respondents reported doing so once a year (11%), once every six months (26%), or once a quarter (39%). However, it remains unclear whether these changed passwords are genuinely unique, robust, and difficult to crack or if they are simply variations of previously used passwords.

An alarming discovery was that nearly 40% of respondents store their passwords in an open file on their computer or in a physical notebook. While some individuals utilize browser-based (27%) or third-party (28%) password managers, it is still worrisome that a significant portion of users opt for less secure storage methods for their passwords.

What do the findings mean?

The findings shed light on the concerning state of data security practices among business professionals. While a portion of employees may employ measures such as encryption, password managers, or encrypted cloud storage platforms to safeguard company data, there remains a substantial number who jeopardize the security of their organization by occasionally engaging in irresponsible behavior.

These results highlight the urgent need for organizations to prioritize comprehensive training programs and establish clear guidelines regarding data security protocols.

Vencevicius says that by instilling a culture of responsibility and accountability, businesses can mitigate the risks associated with lax data security habits and foster a more secure working environment. It is imperative for employees to understand the potential consequences of their actions and actively adopt best practices to ensure the protection of sensitive company information.

Methodology

Data was collected from an anonymous survey on June 8-13, 2023, and examined the cybersecurity habits of 500 business professionals from small to medium-sized companies (up to 100 employees) in the finance, accounting, law, tax consulting, and marketing sectors.

ABOUT NORDLOCKER

NordLocker is the world’s first end-to-end file encryption tool with a private cloud. It was created by the cybersecurity experts behind NordVPN – one of the world’s most advanced VPN service providers. NordLocker is available for Windows and macOS, supports all file types, offers a fast and intuitive interface, and guarantees secure sync between devices. NordLocker protects files from hacking, surveillance, and data collection. For more information: nordlocker.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}