Human error. The weakest link.
A firewall cannot stop a convincing email, and encryption does not help when somebody hands over the password. Human psychology remains the most exploited weakness in security.
74%
of breaches involve human error
- Social engineering involved
- 98%
- Weak or reused passwords
- 81%
- Phishing as entry point
- 36%
74%
Breaches involving human error
98%
Attacks using social engineering
81%
Breaches involving weak passwords
34%
Incidents from insiders
Unglamorous mistakes, expensive consequences
Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks, and all of them are cheap to make and expensive to remediate.
The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest leverage control an organisation can apply against accidental disclosure and accidental loss.
Offline Secure Storage® caps the damage by keeping crown jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens, it just does not become a headline.
How people are exploited
Four routes account for the overwhelming majority of incidents that begin with a person rather than a payload.
Phishing Attacks
36%Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.
- CEO fraud emails
- Fake invoice attachments
- Password reset scams
Weak Passwords
81%Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.
- Password reuse across sites
- Simple dictionary passwords
- Default credentials left unchanged
Social Engineering
98%Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.
- Pretexting calls to help desk
- Tailgating into buildings
- Baiting with infected USB drives
Insider Threats
34%Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.
- Disgruntled employee data theft
- Accidental data sharing
- Shadow IT usage
Large organisations, simple mistakes
These were not sophisticated zero day exploits. They were phone calls and emails.
MGM Resorts
A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.
Uber
Social engineering attack on a contractor. The hacker simply asked for access and was given it.
Spear phishing employees via phone, convincing them to hand over internal tool access.
You cannot train away human nature.
Awareness training helps, but it cannot eliminate mistakes. The reliable way to protect data from human error is to remove day to day access by keeping the copy physically offline.