New Report Reveals Critical Human Cyber Risks in the Digital Age

Date:

SANS Institute, the leading provider of cybersecurity training, has released the SANS 2023 Security Awareness Report®, titled ‘Managing Human Risk.’ With cyber threats becoming increasingly sophisticated, especially through AI-powered attacks such as phishing, vishing, and smishing, understanding and managing human cyber risks have become crucial. The report, based on insights from nearly 2,000 participants across 80 countries, highlights the escalating stakes in human cyber risks, especially considering that 20% of organizations globally reported security incidents involving remote workers in the past year.

Lance Spitzner, SANS Security Awareness Director and co-author of the report, emphasized the growing importance of the human element in cybersecurity. He stated, The digital world is expanding rapidly, and with it, the human element of cybersecurity becomes ever more important as it evolves as a primary target for cyber threats globally. The report is designed to guide organizations in understanding and proactively managing human cyber risks by providing data-driven insights and practical approaches.

One of the key findings of the report is the identification of the top human risks, which include phishing, vishing, and smishing attacks, along with risks related to passwords and authentication. The challenge of fostering a security culture for effective detection and reporting is also highlighted, as well as the risk of IT admin misconfigurations, especially in complex cloud environments.

The report also sheds light on the perspective of leadership regarding security awareness. It reveals that security awareness programs are often considered part-time commitments within organizations. In fact, around 70% of security awareness practitioners dedicate only half or less of their working time to these programs. This finding underscores the ongoing challenge of elevating the importance of continuous cybersecurity awareness in day-to-day organizational operations.

See also  Perception Point launches advanced AI solution to counter AI-based BEC attacks

Interestingly, the report indicates that professionals specializing in human risk management earn up to 5% more than their peers in broader security roles, signaling an increasing demand for these skill sets in the industry.

To increase the success of security awareness programs, the report suggests several key action items. It advises speaking in terms of risk to change the perception that security awareness is merely a compliance effort. By focusing on human risk management, organizations can align their programs with strategic security priorities, gain leadership buy-in, and resonate with security teams. Additionally, the report emphasizes the importance of leadership support and dedicating time to collect metrics about the program’s impact and value.

Another notable recommendation is to address the imbalance between technical security and human-focused security. While organizations often prioritize technical security, the human side is often overlooked, leaving the workforce vulnerable to cyberattacks. To bridge this gap, the report suggests a starting point of a 10-to-1 ratio of technical to human-focused security professionals.

Spitzner emphasized the need for a shift from traditional compliance-focused training to more effective approaches. The traditional model of yearly compliance-focused training is inadequate in today’s cyber threat landscape, so we’ve included practical, actionable advice throughout the report, he stated. The report aims to equip organizations with the necessary tools to improve their human risk management strategies and ensure proactive investments in personnel, resources, and tools to address the human dimension of cybersecurity risks effectively.

By providing critical data-driven insights and actionable steps, the SANS 2023 Security Awareness Report® ‘Managing Human Risk’ serves as a compass for organizations navigating the complex landscape of human cyber risks. It empowers security professionals to mature their awareness programs, advance their careers, and benchmark their programs globally using the Security Awareness Maturity Model®. To access the full report and benchmark your program against industry standards, download the SANS 2023 Security Awareness Report® Managing Human Risk.

See also  Google AI Overview Sparks Backlash with Flawed Results: What You Need to Know

Frequently Asked Questions (FAQs) Related to the Above News

What is the SANS 2023 Security Awareness Report?

The SANS 2023 Security Awareness Report is a comprehensive report released by the SANS Institute, a leading provider of cybersecurity training. It focuses on managing human cyber risks, providing insights and practical approaches to help organizations understand and proactively address these risks.

What are some key findings of the report?

Some key findings of the report include the identification of top human risks such as phishing, vishing, and smishing attacks, as well as risks related to passwords and authentication. It also highlights the challenge of fostering a security culture, the risk of IT admin misconfigurations, and the perspective of leadership regarding security awareness.

How does the report emphasize the human element in cybersecurity?

The report emphasizes the growing importance of the human element in cybersecurity, as the digital world expands and makes humans a primary target for cyber threats globally. It provides data-driven insights and practical approaches to help organizations understand and manage human cyber risks effectively.

Why are security awareness programs often considered part-time commitments in organizations?

The report reveals that around 70% of security awareness practitioners dedicate only half or less of their working time to these programs. This finding highlights the ongoing challenge of elevating the importance of continuous cybersecurity awareness in day-to-day organizational operations.

How does the report bridge the gap between technical security and human-focused security?

The report suggests addressing the imbalance between technical security and human-focused security by recommending a starting point of a 10-to-1 ratio of technical to human-focused security professionals. This helps organizations prioritize the often overlooked human side of cybersecurity.

What are some recommendations provided by the report to increase the success of security awareness programs?

The report advises speaking in terms of risk to change the perception that security awareness is merely a compliance effort. It also emphasizes the importance of leadership support, dedicating time to collect metrics about the program's impact and value, and focusing on human risk management to align programs with strategic security priorities.

How does the SANS 2023 Security Awareness Report empower security professionals?

The report equips security professionals with critical data-driven insights and actionable steps to improve their human risk management strategies. It also allows them to benchmark their awareness programs globally using the Security Awareness Maturity Model® to advance their careers and implement industry standards.

How can I access the full SANS 2023 Security Awareness Report and benchmark my program?

To access the full report and benchmark your program against industry standards, you can download the SANS 2023 Security Awareness Report® Managing Human Risk from the SANS Institute's website.

Please note that the FAQs provided on this page are based on the news article published. While we strive to provide accurate and up-to-date information, it is always recommended to consult relevant authorities or professionals before making any decisions or taking action based on the FAQs or the news article.

Share post:

Subscribe

Popular

More like this
Related

Obama’s Techno-Optimism Shifts as Democrats Navigate Changing Tech Landscape

Explore the evolution of tech policy from Obama's optimism to Harris's vision at the Democratic National Convention. What's next for Democrats in tech?

Tech Evolution: From Obama’s Optimism to Harris’s Vision

Explore the evolution of tech policy from Obama's optimism to Harris's vision at the Democratic National Convention. What's next for Democrats in tech?

Tonix Pharmaceuticals TNXP Shares Fall 14.61% After Q2 Earnings Report

Tonix Pharmaceuticals TNXP shares decline 14.61% post-Q2 earnings report. Evaluate investment strategy based on company updates and market dynamics.

The Future of Good Jobs: Why College Degrees are Essential through 2031

Discover the future of good jobs through 2031 and why college degrees are essential. Learn more about job projections and AI's influence.