January 17, 2018 By Larry Loeb 2 min read

Human error remains one of the top vulnerabilities leading to cyberattacks, according to recent research. A new report from Kaspersky Lab found that employee carelessness accounted for 46 percent of breaches in the past year, suggesting an urgent need for stronger policies and increased security awareness.

Weak IT Security Policies Put SMBs at Risk

Unsurprisingly, only 12 percent of the nearly 8,000 employees surveyed said they fully understood their organization’s IT security policies. Another 24 percent said their organization lacks a concrete cybersecurity framework altogether.

In addition, roughly half (49 percent) of employees said they consider cybersecurity to be a shared responsibility. This is particularly troublesome for small and midsized businesses (SMBs), many of which have employee-owned devices on their networks and inadequate or nonexistent policies to govern them. Others divide responsibility inefficiently among the IT department and nontechnical workers.

For these reasons, SMBs have historically been prime targets for common cyberthreats such as ransomware. Lack of skilled IT employees and financial resources only exacerbates this problem.

Improving Security Awareness

The study also noted that executives, HR leaders and finance specialists were among the most at-risk employees. According to TechRepublic, these employees’ access to sensitive information makes them particularly valuable targets for threat actors.

“The issue of unaware staff can be a major challenge to overcome, especially for smaller businesses where a cybersecurity culture is still being developed,” Vladimir Zapolyansky, head of SMB business at Kaspersky Lab, said in a press release. He further noted that businesses should focus on increasing security awareness among employees and implement solutions that are simple enough for nontechnical workers to use but powerful enough to protect the organization from advanced cyberthreats.

The SMB Security Conundrum

The security conundrum facing SMBs is complex, since effective solutions require significant time, effort and financial resources, which are rare commodities. Still, the main issue revealed in the Kaspersky report — low security awareness among employees — is something all organizations can and should improve with better engagement among top leadership and better communication between security professionals and nontechnical employees.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today