by Tom DelFranco
Technology plays a critical role in protecting an organization from current and emerging threats in the cyber security space. However, even with the most sophisticated tools and services protecting an organization’s data, it is important not to overlook the human factor when considering cybersecurity. A single uninformed or careless user can put an entire organization at risk, it is equally important to ensure that all users in an organization are up to date with best practices when it comes to cybersecurity.
Most security events are triggered by human error. Even with the best detection and intrusion prevention systems, a single human error can compromise an entire organization. Human errors, such as weak password practices, phishing attempts, and data leaks can make an organization vulnerable to outside attacks and malicious actors. Some of the most significant security breaches in 2023 and 2024 were not the result of sophisticated hacking attempts, but instead they were caused by human error. The best example of this is the recent breach of the MGM Resort in Las Vegas. A malicious actor called into an organization’s Help Desk and pretended to be one of the staff members, this exposed credentials and granted access to the bad actor. This single event resulted in the loss of millions of dollars.
Overlooking the human factor can result in considerable damage and downtime to an organization. Like other types of security breaches, these mistakes can lead to irreversible damage and can shut down an organization for weeks at a time. As seen in the infamous breach at MGM Resorts, this could have been avoided if the practice followed a simple policy of verifying that the requesting user was an authorized individual. The cost of implementing practices to improve user education is practically nothing when you consider the potential cost of a system breach. User Education can also play a role in reducing organizations cyber insurance policy.
Reducing an organization’s human-induced risks can be very cost effective and straightforward to implement. Technology companies, such as Southridge Technology, can help secure your organization while having little to no downtime at all during the process. If you or anyone at your organization would like to know more about improving user education for your company, please call us at 203-431-8324 or reach out to support@southridgetech.com