There's one thing that almost all successful cyber attacks all have in common: human error.
Human error comes in various forms. It may be a weak password, failing to update software, downloading malware from an infected attachment, or falling for common phishing tricks.
IBM conducted a study looking into the cyber breaches of its customers across over 130 different countries. In it they found that in 95% of cases, "Human error was a major contributing cause" of a breach.
European defence and security consultancy, QinetiQ, warns that a lack of security culture is the reason so many organisations are being exposed to cyber attacks. QinetiQ explains that employees are the main vulnerabilities to a secure organisation, citing human error, lack of staff awareness, and weaknesses in vetting individuals as common causal factors in security incidents.
This trend is having a significant impact closer to home too. In a recent study from Microsoft, the Asia Pacific region had 1.7 times higher-than-average encounter rates for ransomware in 2020, accounting for 7% of the total worldwide number of reported ransomware incidents. Another report showed Asia Pacific had higher cyber attack rates than the global average in the first half of 2020. And, between April and May 2021, the APAC region saw a 53% increase in cyber attacks.
(Read more about why Australian businesses are a target for ransomware attacks)
These are concerning trends for any organisation operating in APAC. And, as Australia is revealed as the third most targeted country in the world for cyber attacks in the first six months of 2021, it doesn’t look like the pressure will be off CIOs anytime soon.
A different focus
As threats continue to mount, understanding and managing cyber security risks has become a critical issue for IT and business leaders alike. Australian organisations are responding by boosting their security budgets – Gartner predicts that Australian organisation spending on information security and risk management technology and services in 2021 will reach $5.1 billion in an expected 7.3% year-on-year growth.
Yet, although this figure lags behind the global expected growth of 12.4%, technology can only do so much to protect a business against a breach, particularly when attackers are making the most of employee negligence. Without proper staff education and behavioural change, any technology investment is made in vain.
For CIOs, this means taking a holistic approach to security and having a clear understanding of the complex interaction between human behaviour, technology, and organisational process.
Most employees interact with information and technology that is critical to the functioning of the organisation, but if they’re not aware of how to protect these assets, the organisation is at risk.
It is the IT department’s responsibility to give employees the right skills and awareness, and to influence the behaviour that protects the organisation. Employees need to understand what to protect, why they should want to protect it, and how IT can help them do so. Rather than security being an add-on, or a department off to the side, it needs to be embedded into everything employees do. It’s about securing the human, not the device.
Senior consultant on human performance at QinetiQ, Simon Bowyer, explains it well: