Technology

According to CTOs, Human Error is Biggest Cybersecurity Threat

According to research conducted by IT consulting company STX Next, Chief Technology Officers (CTOs) are increasingly identifying human error as the most significant cybersecurity threat to their organizations, with 59% expressing this concern. This surpasses the perceived threats of ransomware (48%) and phishing (40%) attacks. Human errors range from downloading malware-infected attachments to using weak

According-to-CTOs-Human-Error-is-Biggest-Cybersecurity-Threat

According-to-CTOs-Human-Error-is-Biggest-Cybersecurity-Threat

Share
Picture: Intelligent CISO
Advertisement

According to research conducted by IT consulting company STX Next, Chief Technology Officers (CTOs) are increasingly identifying human error as the most significant cybersecurity threat to their organizations, with 59% expressing this concern. This surpasses the perceived threats of ransomware (48%) and phishing (40%) attacks. Human errors range from downloading malware-infected attachments to using weak passwords and have been reported to contribute to as much as 95% of all cybersecurity breaches.

In response to these threats, CTOs are adopting various strategies to safeguard their teams and organizations. Key measures include the widespread adoption of multi-factor authentication (94%), identity access management technology (IAM) usage by 91%, security information and event management (SIEM) technology by 58%, and single sign-on (SSO) solutions by 86%.

STX Next’s 2023 Global CTO Survey, which gathered insights from 500 global CTOs, revealed that 24% considered security to be their organization’s most significant challenge, ranking it as the fourth most common response. Despite the rising threat landscape, only 49% of surveyed companies currently have a cyber insurance policy, and 59% have implemented ransomware protection solutions.

The study also highlighted that in-house security teams remain a minority, with only 36% of companies having dedicated internal security departments. Instead, 53% rely on external specialized companies for security services.

Krzysztof Olejniczak, Chief Information Security Officer (CISO) at STX Next, emphasized the crucial role of employees in an organization’s security posture. He noted that despite technological advancements, poor implementation, inadequate support processes, or a lack of governance can undermine security efforts. Olejniczak emphasized the need for ongoing employee education, periodic resilience testing through simulated attacks, and the adoption of industry-standard solutions like multi-factor authentication, IAM, and SSO to mitigate the risks associated with human error.

He also highlighted the persistent threat of ransomware, emphasizing that cybercriminals often rely on human error and social engineering techniques rather than highly advanced methods of attack. Olejniczak urged management teams to focus not only on educating staff but also on regularly testing their resilience through simulated attacks, phishing tests, and ransomware simulations. Additionally, he stressed the importance of implementing protective measures, such as MFA, IAM, and SSO, to fortify defences and minimize the impact of potential human errors on cybersecurity.

TechnologyAfrican startups
Greg Stewart

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Africa is getting more Big Tech investment, but the basics are still holding it back
Read nextTechnology

Africa is getting more Big Tech investment, but the basics are still holding it back

Google, Meta, Microsoft, Amazon and Starlink are putting more money into Africa's digital infrastructure. Subsea cables are reaching more parts of the continent, satellite internet is expanding and cloud companies are adding services for African customers. For businesses that have spent years dealing with unreliable connections, that is useful. There is still a problem underneath

Vutomi Manzini · 4 min readContinue reading