Report shows a third of employees don’t understand importance of cybersecurity

Human error is one of the biggest risks in cybersecurity. All it takes for an intruder to gain access to a network is for an employee to mistakenly enter their login credentials to a phishing website or to click on a malware attachment to start a breach that can cause millions of dollars worth of damages.
While everyone makes mistakes, there are a substantial number of employees who are completely oblivious to the security risks of high-risk behavior.
Research from Tessian released today found that while 99% of IT and security leaders agreed a strong security culture is important in maintaining a strong security posture, 30% of employees do not think they personally play a role in maintaining their company’s cybersecurity posture.
At the same time, only 39% of employees say they’re very likely to report a security incident, making it much more difficult for security teams to conduct investigation and remediation during a data breach.
Overall, these findings indicate that there is a cultural disconnect between the security awareness advocated for by CISOs and security leaders, and the adherence to best practice among users “on the ground,” who take a more laissez-faire approach to implementing best practices.
When considering the cause of the cultural disconnect between employees and security leaders, the core reason appears to be that enterprises have done a poor job of communicating the importance of maintaining security-conscious behaviors.
As a Forrester report highlighted earlier this year, many security leaders have a limited vision of how to influence employee behavior and build a culture of security awareness, and “reverted to describing their content and quizzes as ways to measure employee engagement and behavior.”
Many of these organizations offer training experiences that aren’t engaging to users. This is highlighted by Tessian’s research, which found that only 28% of UK and US workers believe security awareness training is engaging, with only 36% saying they’re paying full attention.
“Employees focus on what they perceive their role to be. If leadership treats security as separate from everyday work, if security is only spoken about during annual training time, people will do what matches with their perception of their job,” said head of trust and compliance at Tessian, Kim Burton.
Security awareness training not only needs to be clear in its objectives, but consistently reinforced in a way that’s engaging for learners. In practice, that means training sessions that are personalized to provide employees with information in a format that supports their learning style.
“It’s been proven time and again that “one-size fits all” security awareness training is not effective or engaging.


