New research identifies need for wider employee cybersecurity training
- Date: 13 July, 2020
A new report from Kaspersky, the multi-national cybersecurity provider, highlights the need for businesses to provide enhanced cybersecurity training for all their employees.
The study reveals that only 45% of UK businesses currently provide such training to all employees. And effective training is seen as critical in ensuring that staff don’t pose unnecessary insider threats.
According to Kaspersky, almost half of businesses (46%) reported a data breach in the last year, with more than a third (36%) experiencing these issues at least once a week. When these figures are combined with the fact that an average data breach now costs a business more than £2.8 million, then it’s clear to see why effective employee training is so important.
Further Kaspersky research provides some examples of the dangers posed by employees having insufficient cybersecurity training. For instance, even though the threats posed by ransomware to businesses and public sector bodies have been widely publicised, Kaspersky found that 37% of respondents did not know what it was, showing a basic lack of knowledge and awareness about this threat, which should be a major concern for all employers.
the potential dangers posed by employees are further amplified by a new report from the highly respected Ponemon Institute, which reveals that business leaders see employee mistakes as the most significant threat to sensitive data. The 15th annual Global Encryption Trends Study revealed that more than half (54%) of business leaders harbour concerns about accidental insider threats, compared to the proportion concerned about hacking (29%) or malicious insiders (20%).
The reality is that customers’ personal information is involved in data breaches more often than any other type of corporate data. Failing to secure this type of data can result in reputational and financial losses, as well as regulation penalties if not responded to properly.
It’s vital to create a corporate culture where all employees understand the importance of cybersecurity. Appropriate training should ensure they are fully aware of how cybersecurity incidents can occur and what the likely consequences are. It should also explain to employees how following simple rules can help a company avoid cybersecurity incidents.
Finally, investment in cybersecurity training really can pay off, as David Emm, Principal Security Researcher at Kaspersky explained: “Education is crucial in ensuring consumer data is securely protected and to ward off costly cyberattacks. Businesses must do more to ensure this is achieved, especially given that the costs of an attack hugely outweigh the costs for education and ongoing training”.