DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

94% Of Organizations Have Suffered Insider Data Breaches, So Why Aren’t These a Bigger Worry?

Posted on July 14, 2021 by Dissent

Sometimes, 2+2 does not = 4, it seems. When employees falling for phishing attempts represent one of the two biggest preludes to a ransomware attack, why are 28% of IT leaders in a recent survey more concerned about malicious insiders than human error? Why  are only 21% of those surveyed most concerned about human error?

London, UK – 13th July 2021 – Egress’ Insider Data Breach Survey 2021 has revealed that an overwhelming 94% of organisations have experienced insider data breaches in the last year. Human error was the top cause of serious incidents, according to 84% of IT leaders surveyed. However, IT leaders are more concerned about malicious insiders, with 28% indicating that intentionally malicious behaviour is their biggest fear. Despite causing the most incidents, human error came bottom of the list, with just over one-fifth (21%) saying that it’s their biggest concern.

Additionally, almost three-quarters (74%) of organisations have been breached because of employees breaking security rules, and 73% have been the victim of phishing attacks.

The survey, independently conducted by Arlington Research on behalf of Egress, surveyed 500 IT leaders and 3,000 employees in the US and UK across vertical sectors including financial services, healthcare and legal.

Read the full press release for more highlights.

So are non-malicious insider errors being underprioritized?  Consider another study that came out this week:

According to a recent study conducted by Aberdeen and commissioned by Code42, data breaches from insiders can cost as much as 20% of annual revenue. Perhaps just as important, the study showcased that at least one in three reported data breaches involve an insider. Both accidental and malicious Insider Risk can cost businesses material portions of revenue on an ongoing annual basis.

Consider two of that study‘s key findings:

  • At least one in three (33%) of reported data breaches involve an insider. Over three-quarters (78%) of those insider data breaches involve unintentional data loss or exposure, demonstrating that malicious data theft and exposure is not the most significant Insider Risk facing security teams.
  • Every day, trusted insiders cause an average of 13 data exposure events by moving corporate files to untrusted locations via email, messaging, cloud or removable media.

And one last bit of statistics for now — the following from an Osterman Research study commissioned by Trend Micro:

The report further split the threat landscape into 17 types of security incident and found 84% of respondents had experienced at least one of these—highlighting the prevalence of phishing and ransomware. Most common were successful:

  • Business email compromise (BEC) attack – 53%
  • Phishing messages resulting in malware infection – 49%
  • Account compromise – 47%

So what — other than repeating exercises to try to train employees to recognize phishing attempts or to refrain from clicking on links — are entities doing these days to prevent or significantly reduce human error incidents? And what are they doing — via software solutions or other — to immediately detect any errors before there is a major incident?


Related:

  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Confidence in ransomware recovery is high but actual success rates remain low
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach
  • KT Chief to Resign After Cybersecurity Breach Resolution
Category: Breach IncidentsCommentaries and AnalysesInsider

Post navigation

← WV: Morgan County Schools’ computers hit by Kaseya attack
Tulsa Says Network Hack Gained Some Social Security Numbers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Report released on PowerSchool cyber attack
  • Sue The Hackers – Google Sues Over Phishing as a Service
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • Eurofiber admits crooks swiped data from French unit after cyberattack
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill
  • French agency Pajemploi reports data breach affecting 1.2M people
  • From bad to worse: Doctor Alliance hacked again by same threat actor (1)
  • Surveillance tech provider Protei was hacked, its data stolen, and its website defaced
  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data
  • India’s Digital Personal Data Protection Act 2023 brought into force
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill
  • Keeping Cool When ICE Arrives: Basic Raid Response Strategies for Laboratories
  • IRS Accessed Massive Database of Americans Flights Without a Warrant

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.