International Cyber Expo International Cyber Expo
  • About Us
Thursday, 17 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

When Everyday Habits Become an Invisible Security Risk

by Lara Joseph
September 17, 2026
in Featured, Opinion
When Everyday Habits Become an Invisible Security Risk
Share on FacebookShare on Twitter

By James Mackay, CEO, MetaCompliance

When security teams think about their organisation’s attack surface, they’re usually focused on technology. Where could an attacker get in? What’s exposed? What hasn’t been updated or configured correctly? An attack surface refers to all the possible ways a cyber attacker can gain access to an organisation, including unpatched security software, misconfigured cloud storage, open system connections, and traditional phishing emails containing fraudulent links.

However, organisations also have an invisible attack surface sitting behind the everyday behaviours of their employees. Our latest research found that more than two thirds of CISOs see their employees as their organisation’s biggest cyber security risk. Not because employees are careless or malicious, but because routine workplace habits can unintentionally create opportunities for attackers.

Unlike a misconfigured server or unpatched system, these behaviours don’t always look like vulnerabilities, they’re simply part of the everyday ways people work.

Small Details Can Give Attackers a Much Bigger Picture

The clearest example is the out-of-office (OOO) reply. An automated message that goes out to anyone who emails a colleague on leave, no matter who they are, can give an attacker the information they need to build a bigger picture of an organisation and its employees before making a move.

Standard OOO replies confirm that the email address an attacker is contacting is correct and usually tells them how long the person won’t be monitoring that inbox for. It potentially names another employee to get in contact with, along with their role and their direct email address. Sometimes it even explains where the person has gone. In just four or five lines, an attacker receives a verified target, a defined window in which that person can’t be easily reached to check anything, and a partial map of the organisational chart.

OOO replies are only one example. Other routine workplace practices can reveal similarly valuable information. Email signatures or automated messages that supply names, titles and direct contact numbers can make an impersonation attempt incredibly convincing. Calendars shared to show full meeting details reveal who is meeting who, and often what about. In isolation, these actions can seem harmless but combined, they can provide a surprisingly detailed picture of an organisation.

Access is Only as Secure as the Habits Around It

Shared drives are another example of how everyday working practices can quietly expand an organisation’s attack surface. While they’re designed to make collaboration easier, they often accumulate broad access permissions over time. Employees move roles, projects end, teams change, yet access rights frequently remain in place. Old project folders, expired contracts, meeting notes and spreadsheets can also all sit there long after anyone needs them.

The content in these drives tends to be exactly what an attacker is hoping to find – customer records, supplier contracts, financial reports, HR documents, organisational charts. Leaving a folder shared with the entire department may not have been viewed as a security decision at the time, but it becomes a big one the moment someone’s password is compromised. What starts as access to a single user can quickly provide visibility into far more of the business than intended.

When an Employee Leaves, their Access Shouldn’t Stay Behind

Employee offboarding has a part to play here too. Over several years, an employee builds access to dozens of systems: shared folders, cloud platforms, and third-party applications.

When people leave, these accounts need to be disabled, and permissions removed. Otherwise, access that was once legitimate can become an overlooked route into the organisation.

Credentials that have been stolen or compromised are among the most common ways attackers get into organisations, and a dormant account belonging to an employee who has left may take longer to be noticed.

The Wider Human Attack Surface

Security awareness training often concentrates on key security topics like phishing and strong password practices. These are essential foundations of any cyber security programme, helping employees recognise common threats and protect access to systems and data. However, the human attack surface extends beyond fraudulent emails and compromised credentials to include the everyday habits and decisions that can unintentionally expose information, create unnecessary access or provide attackers with valuable context about how an organisation operates.

If employees don’t understand how an OOO reply reads to a threat actor, or the risk created by a forgotten third-party login belonging to an ex-employee, they may continue behaviours that increase the organisation’s exposure to risk. This is why security awareness needs to move beyond teaching people to identify individual threats. Employees need to understand how their everyday actions can affect the organisation’s wider security posture.

Upgrading security awareness starts with building a culture where people understand why their behaviour matters, and how they can apply that judgement to situations that aren’t explicitly covered by a policy or training module.

Building that culture takes sustained backing, and this is where many organisations struggle. Our research found that nearly four in five CISOs say leadership support for security education initiatives fades over time. The initial push happens, the training is rolled out, and attention moves elsewhere.

A culture of security awareness has to start at the top. If senior decision-makers don’t fully understand the cyber risk posed by employees, it becomes very hard to secure the sustained attention these habits require. None of the issues here are failures of technology – they’re habits that can be changed with the right behaviours built into the culture of the business.

ShareTweet
Previous Post

Could an Email You Never Read Hijack Your AI Assistant?

Recent News

When Everyday Habits Become an Invisible Security Risk

When Everyday Habits Become an Invisible Security Risk

September 17, 2026
Could an Email You Never Read Hijack Your AI Assistant?

Could an Email You Never Read Hijack Your AI Assistant?

September 17, 2026
The AI Boom Is an Energy Boom: Kelcy Warren on How Data Centers Are Reshaping Natural Gas Demand

Salt Security expands CrowdStrike integration to tackle AI agent security

September 17, 2026
Two in Five Organisations Hit by AI-Related Compliance Failures in Past Year, Research Finds

Two in Five Organisations Hit by AI-Related Compliance Failures in Past Year, Research Finds

September 17, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol