Skip to content

Human error remains the biggest weakness in cyber security

Man focused on laptop screen at desk in modern office with colleagues talking in background.

Even with major strides in cyber security, one vulnerability continues to eclipse the rest: human error.

Study after study finds that mistakes made by people account for most successful cyber attacks. One recent report estimates the share at 68%.

However sophisticated our technical safeguards become, the human factor is still likely to be the weakest point in the cyber security chain.

This problem touches everyone who uses digital devices, yet conventional cyber education and awareness efforts - and even newer, more ambitious legislation - do not properly tackle it.

So what can be done about cyber security challenges that are driven by people?

Understanding human error

In cyber security, human error generally falls into two broad categories.

The first is skills-based error. This happens during routine tasks, particularly when someone is distracted or rushing.

For instance, you may fail to back up data stored on your desktop computer. You understand that you ought to do it and you know the steps (because you’ve done it before).

But if you are trying to leave early, can’t remember when you last ran a back-up, or are buried under emails, you may not get around to it. If a cyber attack occurs, this can leave you more vulnerable to a hacker’s demands because there may be no other way to recover the original data.

The second is knowledge-based error. This is more common when less experienced users make cyber security mistakes because they do not have key information or they fail to follow specific rules.

For example, you might open a link in an email from an unfamiliar sender even though you are unsure what it will do. That link could contain harmful malware, potentially resulting in your accounts being compromised and you losing both money and data.

Traditional approaches fall short

To reduce human error, organisations and governments have poured resources into cyber security education programmes. Even so, the outcomes have been inconsistent at best.

One reason is that many initiatives are technology-led and apply a one-size-fits-all model. They tend to concentrate on discrete technical actions, such as better password hygiene or rolling out multi-factor authentication.

What they often miss are the psychological and behavioural factors that shape how people actually behave.

In practice, shifting human behaviour is much harder than simply sharing information or insisting on certain procedures - and cyber security is no exception.

Public health efforts show what tends to work. The “Slip, Slop, Slap” sun safety campaign in Australia and New Zealand is a good example.

Over the four decades since it began, melanoma rates in both countries have dropped substantially. Sustained behavioural change depends on continuous investment in awareness.

The same lesson applies to cyber security education. Knowing the right steps does not guarantee people will follow them consistently, particularly when time is tight or other tasks feel more urgent.

New laws fall short

The Australian government’s proposed cyber security law targets several areas, including:

  • tackling ransomware attacks
  • improving information sharing between businesses and government agencies
  • boosting data protection across critical infrastructure sectors, such as energy, transport and communications
  • widening investigative powers for cyber incidents
  • setting minimum security requirements for smart devices.

These steps matter. But, as with many traditional cyber security education programmes, they focus mainly on technical and procedural dimensions of cyber security.

The United States is approaching the issue differently. Its Federal Cybersecurity Research and Development Strategic Plan places “human-centred cybersecurity” as the first and highest priority.

The plan says

A greater emphasis is needed on human-centered approaches to cybersecurity where people's needs, motivations, behaviours, and abilities are at the forefront of determining the design, operation, and security of information technology systems.

3 rules for human-centric cyber security

How, then, can human error in cyber security be addressed more effectively? Based on the latest research, three strategies stand out.

  1. Minimise cognitive load. Cyber security practices should feel intuitive and require as little effort as possible. Training should prioritise making difficult ideas easier to grasp and embedding security habits naturally into day-to-day work.
  2. Foster a positive cyber security attitude. Rather than leaning on fear-based messaging, education should highlight the benefits that come from good cyber security practices. This can encourage people to improve their cyber security behaviour.
  3. Adopt a long-term perspective. Changing attitudes and behaviour is not a one-off exercise; it is ongoing. Cyber security education needs to be continuous, with regular updates that keep pace with changing threats.

In the end, a genuinely secure digital environment demands a joined-up approach: strong technology, sensible policy, and - crucially - people who are well informed and security conscious.

If we better understand the causes of human error, we can build training and security practices that align with human nature instead of fighting against it.

Jongkil Jay Jeong, Senior Research Fellow in the School of Computing and Information System, The University of Melbourne

This article is republished from The Conversation under a Creative Commons licence. Read the original article.

Comments

No comments yet. Be the first to comment!

Leave a Comment