Back to the threat counter
Threat brief

Human error. The weakest link.

A firewall cannot stop a convincing email, and encryption does not help when somebody hands over the password. Human psychology remains the most exploited weakness in security.

The headline number

74%

of breaches involve human error

Social engineering involved
98%
Weak or reused passwords
81%
Phishing as entry point
36%

74%

Breaches involving human error

98%

Attacks using social engineering

81%

Breaches involving weak passwords

34%

Incidents from insiders

The pattern

Unglamorous mistakes, expensive consequences

Human error still causes the majority of data incidents recorded in the United Kingdom. The recurring patterns are unglamorous: a misdirected email, a mis-typed cloud storage policy, an accidental deletion on a shared drive, a lost laptop, or a support agent pasting a customer record into the wrong ticket. None of these are exotic attacks, and all of them are cheap to make and expensive to remediate.

The blast radius of any mistake tracks the reach of the account that made it. In a modern environment a single identity often holds read access across production, staging, backups and analytics at the same time. One accidental action can therefore expose or destroy considerably more than the operator ever intended. Reducing standing permissions is the single highest leverage control an organisation can apply against accidental disclosure and accidental loss.

Offline Secure Storage® caps the damage by keeping crown jewel data physically offline. A misdirected email cannot attach a file that lives inside a disconnected vault. An accidental delete on a connected system does not touch the offline copy. A misconfigured cloud policy has no effect on hardware that has no route to the internet. The mistake still happens, it just does not become a headline.

Attack vectors

How people are exploited

Four routes account for the overwhelming majority of incidents that begin with a person rather than a payload.

Phishing Attacks

36%

Deceptive emails that trick employees into revealing credentials or downloading malware. Attackers impersonate trusted sources like executives, IT support, or vendors.

  • CEO fraud emails
  • Fake invoice attachments
  • Password reset scams

Weak Passwords

81%

Password123, company name + year, or reused credentials across systems. Weak passwords can be cracked in seconds, giving attackers full system access.

  • Password reuse across sites
  • Simple dictionary passwords
  • Default credentials left unchanged

Social Engineering

98%

Manipulation tactics that exploit human psychology. Attackers build trust, create urgency, or impersonate authority figures to bypass security measures.

  • Pretexting calls to help desk
  • Tailgating into buildings
  • Baiting with infected USB drives

Insider Threats

34%

Employees, contractors, or partners with legitimate access who misuse it, whether maliciously or through negligence.

  • Disgruntled employee data theft
  • Accidental data sharing
  • Shadow IT usage
Real cases

Large organisations, simple mistakes

These were not sophisticated zero day exploits. They were phone calls and emails.

MGM Resorts

£79 million2023

A 10-minute phone call to the help desk. Attackers impersonated an employee using LinkedIn info to reset credentials.

Uber

57M users exposed2016

Social engineering attack on a contractor. The hacker simply asked for access and was given it.

Twitter

£200K+ in Bitcoin stolen2020

Spear phishing employees via phone, convincing them to hand over internal tool access.

You cannot train away human nature.

Awareness training helps, but it cannot eliminate mistakes. The reliable way to protect data from human error is to remove day to day access by keeping the copy physically offline.

    Get started