August 27, 2015 By Shane Schick 2 min read

Despite the benefits, many large enterprises have been extremely worried about the security risk of moving their IT infrastructure to the cloud. But researchers say it’s only 1 percent of employees who represent 75 percent of the potential danger.

In its “Q3 2015 Cybersecurity Report,” a study that examined the behavior of some 10 million people, security vendor CloudLock found that the 1 percent — not to be confused with the extremely wealthy portion of the population targeted by the Occupy movement — cause one security risk after another. This includes using cloud-based software that isn’t authorized by an IT department, sharing their passwords and other files and falling victim to phishing schemes that lead to malware infections on corporate machines.

Unfortunately, it may be difficult to pinpoint who the 1 percent are in any given organization. As CSO Online reported, they could be anyone from senior management to support staff, and a security risk could be triggered by different people at different times. The main point, given the fact that many organizations feel they don’t have enough resources to address all threats, is that they can probably minimize them by focusing on a subset of their entire personnel.

The other main takeaway, CloudLock told BetaNews, is that the greatest security risk involves people rather than technology. The better an organization understands how its staff members behave — particularly those with high clearance or other access privileges — the better they’ll be able to contain dangers posed by the 1 percent who lead to most of the problems.

One way to start, CloudTech suggested, is by enlisting those same people as participants in a data protection strategy. This may sound like common sense, but giving a small concentration of individuals access to or control over the majority of corporate files may be a bigger security risk than failing to update IT equipment or patch software programs.

Of course, this doesn’t mean defending against cloud-related breaches is purely an HR issue. ZDNet recently published details from a study by market research firm Forrester that showed spending on products to minimize security risk is expected to reach $2 billion by 2020. This combination of products and people is essential to strong cybersecurity.

More from

2024 trends: Were they accurate?

4 min read - The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity.Here are five trends that were often predicted for…

Ransomware attack on Rhode Island health system exposes data of hundreds of thousands

3 min read - Rhode Island is grappling with the fallout of a significant ransomware attack that has compromised the personal information of hundreds of thousands of residents enrolled in the state’s health and social services programs. Officials confirmed the attack on the RIBridges system—the state’s central platform for benefits like Medicaid and SNAP—after hackers infiltrated the system on December 5, planting malicious software and threatening to release sensitive data unless a ransom is paid.Governor Dan McKee, addressing the media, called the attack “alarming”…

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today