Employee error is one of the main causes of internal IT security incidents leading to leakage of confidential corporate data. This is according to the findings of the Global Corporate IT Security Risks 2013 survey conducted by B2B International and Kaspersky Lab this year.
Although vulnerabilities in software used by company staff in their daily duties is one of the top reasons behind internal IT security incidents (with 39 per cent of companies reporting this issue), the volume of different types of incidents taking place due to staff errors is equally high. Four out of five types of internal IT security incidents that took place within companies were closely related to erroneous employee actions.
Approximately 32 per cent of respondents reported leaks that took place as a result of employee mistakes. A slightly lower number of companies — 30 per cent — reported incidents where the employee was at fault over the loss or theft of mobile devices. 19 per cent of the companies participating in the survey reported that employees were involved in intentional leaks. 18 per cent reported incidents that were caused by incorrect use of mobile devices (via mobile email clients or text messaging).
At the same time, an average of 7 per cent of respondents reported that employee actions were the cause of leakages of critically confidential information relating to company operations. Most commonly, leakages of critically sensitive data occurred when employees were responsible for the loss or theft of mobile devices with 9 per cent of respondents reporting these types of incidents.
A comprehensive approach to a complex problem
“These types of incidents can be eliminated – or at least the risk can be minimised – by implementing a set of measures including educating employees about IT threats and developing, putting into place, and overseeing the enforcement of appropriate security policies within the company. Another preventative action to consider is the use of specialised security solutions, such as Kaspersky Endpoint Security for Business”, comments David Emm, senior security researcher at Kaspersky Lab.
As a top-quality security platform, this Kaspersky Lab product includes a component that protects both desktop computers and mobile devices, and offers the ability to effectively manage them.
This platform will not only provide a top level of security for a corporation’s IT infrastructure, but will also help enforce a company’s IT security policies, and even compensate them in the event of no policy being in place.
Employee carelessness among top causes of data theft
KasperskyAbout Kaspersky
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.
Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.
Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.