City
Epaper

Security violations by employees as harmful as hacking: Report

By IANS | Updated: November 24, 2023 12:00 IST

New Delhi, Nov 24 Employee violations of an organisation’s information security policies are as dangerous as external hacker ...

Open in App

New Delhi, Nov 24 Employee violations of an organisation’s information security policies are as dangerous as external hacker attacks, a report warned on Friday.

In terms of individual employee behaviour, the most common problem is that employees deliberately do what is forbidden and, conversely, they fail to perform what’s required.

In the last two years, 33 per cent of cyber incidents in businesses in Asia Pacific (APAC) occurred due to employees intentionally violating security protocol, according to the report by cyber-security firm Kaspersky.

A quarter (35 per cent) of cyber incidents in the last two years occurred due to the use of weak passwords or failure to change them in a timely manner. This is 10 per cent higher than the global result of 25 per cent.

“It is alarming to see that despite the several headline-grabbing data breaches and ransomware attacks that happened in the region this year, a lot of employees continue to intentionally breach basic information security policies,” said Adrian Hia, Managing Director for Asia Pacific at Kaspersky.

A multi-department approach to build a strong enterprise cybersecurity culture is urgently needed to address this human-factor gap that is definitely being exploited by cybercriminals, Hia advised.

Respondents from organisations in APAC claimed that intentional actions to break the cybersecurity rules were made by both non-IT and IT employees in the last two years.

They said policy violations such as these by senior IT security officers caused 16 per cent of the cyber incidents in the last two years, 4 per cent higher than the global average.

Other IT professionals and their non-IT colleagues brought about 15 per cent and 12 per cent of cyber incidents, respectively, when they breached security protocols.

Another cause of almost one third (32 per cent) of cybersecurity breaches were the result of staff in APAC visiting unsecured websites.

Another 25 per cent reported they faced cyber incidents because employees did not update the system software or applications when it was required.

Using unsolicited services or devices is another major contributor to intentional information security policy violations, said the report.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

NationalAssam : Woman Allegedly Kills Drunk Husband, Buries Body at Home in Guwahati

EntertainmentThe Depth in the Characters Is More Important Than Bold Scene: Rajniesh Duggal

BusinessEquity MFs reduce cash holdings in June, cash-to-assets ratio falls to 12-month low

NationalGovt to amend MPID Act to increase fine and punishment for financial establishments: Maha CM

NationalCBI books Nagaland University professor for bribery

International Realted Stories

InternationalNepal Federal Affairs Minister resigns after bribery allegations

International"Good to catch up": EAM Jaishankar meets Iranian Foreign Minister on sidelines of SCO meet

InternationalChinese President Xi Jinping meets SCO Foreign Ministers in Beijing, calls for stronger regional cooperation and stability

InternationalEAM Jaishankar meets Foreign Ministers of Russia and Iran in China's Tianjin

NationalTesla Model Y: Is It Cheaper in the US & China Than in India? Full Price Comparison Inside