Top 3 cyber-risk catalysts all rooted in human behavior

A new Kaspersky study reveals that 80% of organizations view people-related factors as the biggest driver of a potential successful cyberattack on their business – even ahead of technical controls. Among the top three risks are high workload on IT and IT security teams, insufficient expertise among security specialists, and a lack of security awareness among staff – equally gaining nearly a quarter of all votes.

Cyber attackers increasingly rely on the human factor, from social engineering that tricks employees into sharing sensitive data to misconfiguration left unnoticed by overloaded teams. Even high-severity incidents are often triggered by social engineering, where a single convincing lure leads to a critical human-driven lapse. Despite advances in automation, the human factor remains the decisive reason why cyberattacks succeed.

According to a new study by Kaspersky’s internal market research center, 24% of organizations identified high workload on the IT and security functions as one of the top factors increasing the likelihood of successful cyberattacks. This share rises among medium-sized businesses (27%) and large enterprises (26%), where the number of processes and tasks is higher. When expert teams are stretched thin, they have less time for proactive defense, which in turn increases the probability of errors or missed incidents.

The next factor cited by 24% of respondents is the lack of expertise and experience among security and IT professionals. This challenge directly affects an organization’s ability to identify, analyze and respond to modern threats. This concern is particularly pronounced in several regions with higher shares, reported in Mexico (30%), Colombia (29%), Turkey (28%), and Germany (27%).

Finally, 24% of respondents mention low employee security awareness, which continues to make organizations vulnerable to a range of cyberattacks. This concerns organizations even more frequently in Germany (32%), as well as across several markets in the Asia-Pacific region, particularly in Vietnam (35%), Thailand (33%), China (30%), India (28%) Indonesia (27%), and Malaysia (27%).

“At a first glance, deploying advanced security technologies seems enough to effectively defend against modern threats. However, Kaspersky’s incident analysis consistently reveals that high-impact intrusions frequently involve a human weakness, whether it’s a convincing social engineering lure or a missed alert during peak workload. Strengthening this human layer, from specialists’ skills to everyday awareness, help organizations reduce the likelihood that such errors turn into full-scale cyber incidents,” says Evgeniya Russkikh, Head of Academic Affairs at Kaspersky.

LEAVE A REPLY

Please enter your comment!
Please enter your name here