Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 17 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Forcepoint survey reveals European CISOs face major challenge protecting employees against data breaches and insider threats

by The Gurus
March 27, 2017
in Editor's News
Data Breach Cyber attack code
Share on FacebookShare on Twitter

Global cybersecurity leader Forcepoint™ today unveiled research showing that 35% of employees across the UK, France, Germany and Italy admit to have been involved in a security breach, presenting regional CISOs with a significant challenge when it comes to protecting company data, particularly in light of the forthcoming European General Data Protection Regulation will come into effect in early 2018. The new legislation will not only make it a requirement to notify of a breach within 72-hours, but also levy strict new penalties of up to 4% of worldwide annual turnover for serious failings.
While high profile incidents and reports have helped to shine a light on the insider threat security problems facing European CISOs, there has been little in the way of comprehensive Europe-wide research investigating the issue in greater detail. This is why Forcepoint commissioned an independent survey of over 4,000 office workers across the UK, France, Germany and Italy – to better understand attitudes toward data protection and the number of insider threats, malicious and accidental, facing organisations across these territories.
View the results here
The findings are the result of both intentional and accidental employee activity, with malicious intent, staff negligence, limited security awareness and ineffective corporate policies all emerging as reasons for security breaches. In particular, the research reveals worrying levels of risky behaviour from employees within enterprises:

  • 14% of employees would jeopardise their job by selling work log-ins to an outsider, and 40% of those would do so for less than £200 – 55% of surveyed employees in the UK would part with credentials for that amount.
  • Just under a third (29%) of survey respondents have purposefully sent unauthorised information to a third party, while 15% of European staff have taken business critical information with them from one job to another. 59% planned to use it in their next job.

Yet the results also show a severe lack of employee awareness of how their behaviour increases the data security risks facing an organisation:

  • Nearly half (43%) of European employees do not believe their organisation is currently vulnerable to a security threat caused by insiders, while 32% are either unaware of or are unsure about the consequences of a data breach.
  • Nearly a quarter (22%) either do not believe data breaches incur a cost to their employers, or are unsure; with France and the UK representing the nations with the lowest levels of awareness of these costs and consequences.
  • 39% of European employees report to have received no data protection training and over a quarter (27%) of organisations either lack security policies to prevent data loss or fail to enforce them.

The survey also uncovers some interesting trends across Europe:

  • Italian respondents (45%) are most likely to be involved in a security breach, compared to just 27% of UK respondents.
  • French workers (36%) are most likely to feel that their organisation is vulnerable to security threats from hijacked systems, rogue insiders, stolen credentials or negligent end users, more than those in Italy (33%) and the UK (22%), and more than twice as likely as German employees (15%);
  • The cloud represents an area of significant uncertainty when it comes to security. In the UK, 55% aren’t sure if their data is more or less secure in the cloud and 38% do not consider security before uploading files. France was not far behind at 52% and 33% respectively, with lower but consistently significant statistics generated in Italy (33% and 17% respectively) and Germany (33% and 21% respectively);
  • The need for data protection training is widespread. Nearly half (47%) of French employees have never received training, with the figure at 41% in the UK, 37% in Germany and 31% in Italy.

Mike Smart, Product & Solutions Director at Forcepoint commented: “Research has consistently shown that breaches caused by employees are among the most damaging around in terms of their financial and reputational impact. Organisations that ignore the potential security risks that can be caused by employees and other insiders miss an opportunity to strengthen their security posture and protect their companies more broadly.”

Tags: BreachCyberdatasecurityTechnology
ShareTweet
Previous Post

Switzerland to Build AI Cognitive Security Ops Centre to Protect Banks

Next Post

With DDoS attacks on the rise, enterprises are pointing fingers in the wrong direction

Recent News

KnowBe4 Appoints Alex Callihan as Chief Technology Officer

KnowBe4 Appoints Alex Callihan as Chief Technology Officer

June 16, 2026
One Copied Command. Eleven Compromised Machines. Inside a ClickFix Attack That Took Over an Entire Network

One Copied Command. Eleven Compromised Machines. Inside a ClickFix Attack That Took Over an Entire Network

June 16, 2026
AI Appreciation Day: Celebrating Progress, Embracing Responsibility

AI-Powered Attackers Force Security Teams to Rethink Speed of Response

June 16, 2026
US Tech Dependence Is Becoming a Data Security Risk; and Consumers Are Waking Up to It

US Tech Dependence Is Becoming a Data Security Risk; and Consumers Are Waking Up to It

June 16, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol