Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Lack of process and security culture are chief factors leaving firms open to cyber attack

by The Gurus
August 17, 2016
in Editor's News
Share on FacebookShare on Twitter

A lack of understanding of how to mitigate employee negligence is leaving firms wide open to cyber-attacks, a whitepaper published by defence and security consultancy QinetiQ has warned. In an analysis of government data and work with its own clients, QinetiQ has identified a clear gap between employee knowledge and their actions, concluding that security training alone will not change employee behaviours, with QinetiQ advocating a more holistic approach to security, designed with the integration of people, process and technology in mind.
Recent government data has shown that 81% of large organisations that were victims of hacking in 2015 stated that the actions of their employees aided the attacker, with 90% of large organisations suffering some sort of overall breach. Despite widespread awareness of this threat, the security consultancy found that most organisations lack a clear understanding of the complex interaction between human behaviour, technology and organisational process. This often leaves cyber security processes below par, and creates an ideal route for attackers to cause serious damage and disruption to major companies and organisations.
QinetiQ’s paper presents a number of ways to address employee-aided routes for attackers, which can include phishing tactics, social engineering, device drops and social profiles.
The potential consequences of an attack can be devastating and span both financial and reputational damage as seen in the now infamous TalkTalk breach of 2015. Whilst many now acknowledge this threat to their business, QinetiQ suggests that businesses must recognise that there is no silver bullet to preventing an attack. Improving security culture throughout the business requires a long-term, diverse approach.
QinetiQ advises that technology alone cannot deliver sufficient security, rather businesses must address the issue at the heart of the company and create a natural environment for secure employee behaviour.
Advice includes:

  • Ensuring company best practice is written in plain English is of utmost importance. Policy should provide context and relevance to employee’s day to day lives, and be drafted and considered in line with the wider goals of the business. Analysis has shown that employees will often sign/agree to policy documents without reading the contents because of too much jargon, leading to situations where employees are unaware of protocol when they are most needed.
  • Human behaviour analysis should form the bedrock of any security strategy and should actively steer policy direction. A clear assessment process can give a 360-degree view, often yielding invaluable knowledge of where security is optimal or needs improvement. With this knowledge, businesses can save significant investment and maintain a clear view of the performance of security policies, such as monitoring recent training and how this has impacted employees across different sectors of the business.
  • Training must be designed to be regular, relevant, short, engaging and empowering to bolster its effectiveness and prevent employees from unwittingly (or deliberately) causing a security breach. The common pitfalls of training practices are often that it is long and laborious, but infrequent.

Simon Bowyer, Senior Consultant, Human Performance, QinetiQ and co-author of the paper said: “To educate and influence the behaviour of employees is to restrict the easiest attack route into a business. When employees have a natural inclination towards security by virtue of an integrated company ethos, they are motivated to remain alert to risks and unusual behaviours.
If firms are to stand a chance against cyber threats firms must design their security strategy taking into account human behaviour and propensity of employees to act in a security conscious fashion. Firms must work towards a vision, where employees recognise the importance of cyber security best practice and how even actions that we all take for granted, like checking a Facebook page at lunchtime, could provide cyber criminals with an avenue into a business.
“Cyber security is no longer the sole responsibility of the IT department. It is the responsibility of everyone. It needs to be closely integrated with the aims of the business and the entire employment lifecycle.”

ShareTweet
Previous Post

New Research Shows More than 30% of Employees Put Their Companies at Risk of Data Breach Due to Phishing Attacks

Next Post

Cyber attack recovery 300% dearer due to skills shortage

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol