Big companies are investing big money in securing their businesses. They are investing in creating personalised antivirus, doing data encryption, and state-of-the-art threat detection systems. 

But it doesn’t work for everyone because many forget about the most important link in cybersecurity: employees. This is the most important vulnerability of all large companies. It is the human factor that is to blame for 90% of cybersecurity breaches. 


How is cloud-based video surveillance helping startups in Southeast Asia with business protection?


Today, we’re going to look at why employees can be a problem if they are not trained and educated about cybersecurity. We’ll show you the most popular cases and get to the bottom of this issue. 

Cybersecurity is not just a technical problem

A big problem for companies is that they treat security as a purely technical task. They put the responsibility on IT departments and technical people. That’s a big mistake. 

Strong security technology is not going to keep someone from clicking on a malicious link or using a weak password. Even if an employee doesn’t have bad intentions, they may simply be unaware of potential threats and open the door for hackers to enter your company. 

This can be as simple as phishing emails or simply losing a device and then leaking information. And that’s where your employee’s training comes into play – the human factor.

Real-world examples

There are quite a few examples of such problems that have arisen due to employee unawareness and human error. Here are some of them: 

Sony Pictures hack in 2014: This is a major attack on the company that was launched through a common phishing attack. The result was a leak of confidential emails, personal information, and unreleased movies. And they were not helped by a modern defence system and a modern antivirus.

Target data breach in 2013: Hackers compromised the credentials of a third-party vendor. They then gained access to the company’s network. This eventually led to the loss of data of over 40 million customers.

Twitter bitcoin scam in 2020: Attackers used dialogues and deception to gain access to the accounts of prominent users of the platform. This showed that even famous people can easily fall for such provocations.

In each case, the breach originated not from a flaw in software but from the exploitation of human behaviour.

Common human errors in cybersecurity

To have a good conversation with your employees, you need to know where people are most likely to fall for hackers. Let’s break it down.

Phishing and social interaction

It is very common for employees to fall prey to phishing emails. These days, hackers are very good at faking emails and even phishing site designs. It is difficult to notice a person who is not familiar with it. 

It can be a message from the boss of a company, a supplier or a customer. And it can be very similar to the truth. 

It is necessary to inform your employees about it and explain that before clicking on a link, it is better to consult with a manager. 

Weak password

Despite the fact that almost every site tells you that you need a strong password when you register, many users ignore the rules. 

You can’t use passwords that contain personal information or easy dates. And you can’t use the same password for multiple accounts. If one account gets hacked, it can have a domino effect.

There is a good practice where the company itself creates passwords for its employees and stores them in a secure password manager. This will allow you to control the process.

Lost devices

If an employee loses their data device, it could be a gold mine for criminals. Especially if the data on that device is unencrypted.

That’s why it’s important to protect your devices – even mobile devices – well. Set good passwords on your phone, and create password folders where you will store important data. Otherwise, you risk losing it and having your company accounts blackmailed or hacked.

There are many ways to keep your phone safe. The iPhone, for example, has a feature that locks your phone if you lose it. This will help keep all your data safe.

Why are employees targeted?

All hackers always start an attack by looking for the weakest link. And it’s usually the rank and file. No matter how strong the company’s defences are, one click from an ordinary worker can break everything. And this is where phishing and social methods fit in perfectly. They play on emotions, causing people to feel fear, urgency, curiosity, and more. Often hackers use blackmail. 

If the attack is well thought out, it is not impossible that hackers will study the company and its employees. Find weaknesses and create a convincing phishing email that people will definitely fall for. This could be a call from the director or the finance department. Or a client asking for edits. 

It is very important to inform your employees and explain to them what it is and how it works.