Lack of Security Awareness Tops List of Obstacles to Cyber Defense

Most organizations cite low security awareness among employees as the biggest barrier to defending against cyberattacks, according to a new survey by CyberEdge Group.
“This result reinforces the idea that in cybersecurity, as in so many other areas of business and life, people challenges trump technology issues every time,” the researchers write.
“Without doubt, although computers speed up every year, people don’t (and some days we suspect they are getting slower). But the data serves as a reminder that we should be investing more in educating end users and training our cybersecurity teams.”
The top four threats cited by organizations were malware, phishing, ransomware, and account takeovers. These threats often overlap—for example, most ransomware incidents begin with phishing attacks and involve preliminary malware staging.
The report also found that the number of organizations hit by ransomware declined, although the average ransom demand increased. Additionally, only half of the organizations that paid the ransom were able to recover their data. The researchers note, “the reduction in the number of organizations victimized by ransomware has been partially offset by a trend toward targeting larger enterprises that can afford larger ransom payments.”
Notably, the survey found that 82 percent of organizations were hit by cyberattacks last year, but only 64 percent expect to be hit in 2025, suggesting a false sense of confidence.
Additionally, IT teams cited employees’ mobile devices as the most difficult assets to secure.
“Threat actors employ web and mobile application attacks to steal credentials and personal information, which they can then use to impersonate victims to carry out data breaches, identity theft, and other crimes,” the researchers write. “The problem is made worse when people reuse the same passwords for multiple personal and work accounts.”
New-school security awareness training can give your organization an essential layer of defense against cyberattacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
CyberEdge Group has the story.
Request A Demo: Security Awareness Training
New-school Security Awareness Training is critical to enabling you and your IT staff to connect with users and help them make the right security decisions all of the time. This isn’t a one and done deal, continuous training and simulated phishing are both needed to mobilize users as your last line of defense. Request your one-on-one demo of KnowBe4’s security awareness training and simulated phishing platform and see how easy it can be!
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/one-on-one-demo-partners?partnerid=001a000001lWEoJAAW