New Report Reveals Critical Human Cyber Risks in the Digital Age

Date:

SANS Institute, the leading provider of cybersecurity training, has released the SANS 2023 Security Awareness Report®, titled ‘Managing Human Risk.’ With cyber threats becoming increasingly sophisticated, especially through AI-powered attacks such as phishing, vishing, and smishing, understanding and managing human cyber risks have become crucial. The report, based on insights from nearly 2,000 participants across 80 countries, highlights the escalating stakes in human cyber risks, especially considering that 20% of organizations globally reported security incidents involving remote workers in the past year.

Lance Spitzner, SANS Security Awareness Director and co-author of the report, emphasized the growing importance of the human element in cybersecurity. He stated, The digital world is expanding rapidly, and with it, the human element of cybersecurity becomes ever more important as it evolves as a primary target for cyber threats globally. The report is designed to guide organizations in understanding and proactively managing human cyber risks by providing data-driven insights and practical approaches.

One of the key findings of the report is the identification of the top human risks, which include phishing, vishing, and smishing attacks, along with risks related to passwords and authentication. The challenge of fostering a security culture for effective detection and reporting is also highlighted, as well as the risk of IT admin misconfigurations, especially in complex cloud environments.

The report also sheds light on the perspective of leadership regarding security awareness. It reveals that security awareness programs are often considered part-time commitments within organizations. In fact, around 70% of security awareness practitioners dedicate only half or less of their working time to these programs. This finding underscores the ongoing challenge of elevating the importance of continuous cybersecurity awareness in day-to-day organizational operations.

See also  Cisco Partners with NAMTECH to Provide Cybersecurity and AI Training for Manufacturing Industry, India

Interestingly, the report indicates that professionals specializing in human risk management earn up to 5% more than their peers in broader security roles, signaling an increasing demand for these skill sets in the industry.

To increase the success of security awareness programs, the report suggests several key action items. It advises speaking in terms of risk to change the perception that security awareness is merely a compliance effort. By focusing on human risk management, organizations can align their programs with strategic security priorities, gain leadership buy-in, and resonate with security teams. Additionally, the report emphasizes the importance of leadership support and dedicating time to collect metrics about the program’s impact and value.

Another notable recommendation is to address the imbalance between technical security and human-focused security. While organizations often prioritize technical security, the human side is often overlooked, leaving the workforce vulnerable to cyberattacks. To bridge this gap, the report suggests a starting point of a 10-to-1 ratio of technical to human-focused security professionals.

Spitzner emphasized the need for a shift from traditional compliance-focused training to more effective approaches. The traditional model of yearly compliance-focused training is inadequate in today’s cyber threat landscape, so we’ve included practical, actionable advice throughout the report, he stated. The report aims to equip organizations with the necessary tools to improve their human risk management strategies and ensure proactive investments in personnel, resources, and tools to address the human dimension of cybersecurity risks effectively.

By providing critical data-driven insights and actionable steps, the SANS 2023 Security Awareness Report® ‘Managing Human Risk’ serves as a compass for organizations navigating the complex landscape of human cyber risks. It empowers security professionals to mature their awareness programs, advance their careers, and benchmark their programs globally using the Security Awareness Maturity Model®. To access the full report and benchmark your program against industry standards, download the SANS 2023 Security Awareness Report® Managing Human Risk.

See also  OpenAI and Time Magazine Strike Content Deal to Enhance AI Capabilities

Frequently Asked Questions (FAQs) Related to the Above News

What is the SANS 2023 Security Awareness Report?

The SANS 2023 Security Awareness Report is a comprehensive report released by the SANS Institute, a leading provider of cybersecurity training. It focuses on managing human cyber risks, providing insights and practical approaches to help organizations understand and proactively address these risks.

What are some key findings of the report?

Some key findings of the report include the identification of top human risks such as phishing, vishing, and smishing attacks, as well as risks related to passwords and authentication. It also highlights the challenge of fostering a security culture, the risk of IT admin misconfigurations, and the perspective of leadership regarding security awareness.

How does the report emphasize the human element in cybersecurity?

The report emphasizes the growing importance of the human element in cybersecurity, as the digital world expands and makes humans a primary target for cyber threats globally. It provides data-driven insights and practical approaches to help organizations understand and manage human cyber risks effectively.

Why are security awareness programs often considered part-time commitments in organizations?

The report reveals that around 70% of security awareness practitioners dedicate only half or less of their working time to these programs. This finding highlights the ongoing challenge of elevating the importance of continuous cybersecurity awareness in day-to-day organizational operations.

How does the report bridge the gap between technical security and human-focused security?

The report suggests addressing the imbalance between technical security and human-focused security by recommending a starting point of a 10-to-1 ratio of technical to human-focused security professionals. This helps organizations prioritize the often overlooked human side of cybersecurity.

What are some recommendations provided by the report to increase the success of security awareness programs?

The report advises speaking in terms of risk to change the perception that security awareness is merely a compliance effort. It also emphasizes the importance of leadership support, dedicating time to collect metrics about the program's impact and value, and focusing on human risk management to align programs with strategic security priorities.

How does the SANS 2023 Security Awareness Report empower security professionals?

The report equips security professionals with critical data-driven insights and actionable steps to improve their human risk management strategies. It also allows them to benchmark their awareness programs globally using the Security Awareness Maturity Model® to advance their careers and implement industry standards.

How can I access the full SANS 2023 Security Awareness Report and benchmark my program?

To access the full report and benchmark your program against industry standards, you can download the SANS 2023 Security Awareness Report® Managing Human Risk from the SANS Institute's website.

Please note that the FAQs provided on this page are based on the news article published. While we strive to provide accurate and up-to-date information, it is always recommended to consult relevant authorities or professionals before making any decisions or taking action based on the FAQs or the news article.

Share post:

Subscribe

Popular

More like this
Related

Netflix Phases Out Affordable Plan, iPhone 16 Rumors, and Phil Schiller’s New Role on OpenAI – Daily Apple News

Stay updated on the latest Apple news with 9to5Mac Daily - Netflix's plan changes, iPhone 16 rumors, Phil Schiller's new role on OpenAI, and more!

China and Kazakhstan Strengthen Strategic Partnership for Economic Growth and Stability

China and Kazakhstan enhance strategic partnership for economic growth and stability, boosting bilateral trade and deepening cooperation.

Dubai Silicon Oasis Drives Future Mobility Innovation

Discover how Dubai Silicon Oasis drives future mobility innovation with AI-powered solutions and eco-friendly transportation options.