Research data published by a cybersecurity expert at NordLayer shows that phishing websites are not identified by as many as 68% of people. The expert analysis reveals the ten most common cybersecurity mistakes employees make. With hybrid work models and working from anywhere still popular, the risks increase, along with potential costs for businesses. NordLayer shares tips on what businesses can do to avoid these mistakes.
Threats by phishing websites are everywhere
Organizations arenโt only made up of routers, servers, and networks โ there are also people. Sometimes, employee negligence can lead to cyberattacks as tricking a person is always easier and doesnโt require as much technical knowledge as spoofing an advanced security system, and hackers know it.
Today, more than 90% of all cyberattacks begin with a phishing email. This cyberattack is also prevalent even in social media. For example, a phishing attempt is the second most prominent scam on LinkedIn, as revealed by NordLayerโs study. What is worse, according to a cyber security company NordVPN, 68% of people canโt identify a phishing website. Regarding tools and solutions to keep employees and businesses safe, matters could be better, as research reveals that more thanย 70% of companies believe that they wasted 25โ100% of their cybersecurity budget.
What are employees doing?
The figures above demonstrate how important it is for organizations to pay attention to employeesโ online behavior. Carlos Salas, head of engineering at NordLayer, underlines the following most common employee cybersecurity habits that may impose a risk to businesses:
- Weak passwords. People tend to prioritize convenience over security, often reusing weak passwords on all of their accounts. The latest research by NordPass demonstrates what the most common passwords are and how often they are being reused.
- Keeping business data on personal devices. With company networks expanding rapidly, more employees use unsupervised devices for business purposes, making it harder to ensure the security of sensitive information.
- Clicking before thinking. Fast-paced work environments require employees to communicate and act quickly, often leading to them clicking on malicious phishing links โ especially if they lack sufficient cybersecurity training.
- Leaving work equipment unattended. Doing so can be especially dangerous if a person is working remotely or in a public place because company data can be exposed to strangers.
- Not taking cybersecurity responsibly. The most advanced technological solutions are helpless against human factor-induced mistakes, such as falling victim to social engineering.
What can companies do to help employees avoid mistakes?
โCybersecurity is crucial, and negligence might be costly for businesses. This is why itโs in the best interest of companies to treat employee cyber awareness seriously. One of the most effective ways to do so is to organize regular cybersecurity awareness training,โ says Salas. โItโs important to inform employees about every possible threat they can encounter and raise awareness about the shared collective responsibility for the companyโs security. Spreading awareness is one step towards a whole new organizational culture.โ
Sigita Jurkynaitฤ, an information security manager at Nord Security, agrees with Salas and gives the following advice to businesses:
โThe worst takeaway would be to start treating your employees as the weakest link. Thatโs the opposite of what you should be doing because treating your employees as partners and investing in their cybersecurity awareness can pay back tenfold. However, it shouldnโt be done just โcheck the boxโ. The process should be a continuous one โ make it engaging and fun, and avoid resorting to punishments if an employee fails a test.โ ย
ABOUT NORDLAYER
NordLayer is an adaptive network-access security solution for businesses. It helps organizations of all sizes to fulfill scaling and integration challenges. Moving towards an ever-evolving SASE ecosystem, NordLayer is quick and easy to implement with existing infrastructure, is hardware free, and is designed for scaling. As a cloud-native solution with an easy-to-use interface, NordLayer offers protection to businesses of any size, complexity, or work model, including remote or hybrid workplaces. More information can be found onย www.nordlayer.com
You might also be interested in reading how to create a cybersecurity assessment.