The human side of cyber security: what the data is telling us
Author: Melonie Cole | Founder and CEO, Mindshift
Every year, the Kordia NZ Business Cyber Security Report gives us a detailed picture of where New Zealand organisations stand on cyber security. This year marks their tenth anniversary edition.
Employees accidentally exposing the business is the number one perceived threat, cited by 43% of business leaders for the third consecutive year. In that same report, 1 in 4 large businesses still have no cyber security awareness or training programme in place.
Those two things sitting alongside each other are worth pausing on. The risk is well understood. The gap is in what is being done about it.
In my experience, that’s the biggest challenge organisations face. Most already understand the risk but turning that understanding into action to effect behaviour change is the hard part. It also happens to be the part they have most influence over.
Why the pattern persists
At its core, cyber security is not just about technology, it’s about people. I spoke with Patrick Sharp, General Manager at Aura Information Security, who contributed to the Kordia report. He puts it plainly.
“Fundamentally, businesses run on the efforts of people. Computer systems can make those people more efficient, but we rely on people to make decisions, and we trust them with the critical functions of our business. Attackers know this and will always target people.”
Patrick Sharp, General Manager — Aura Information Security
It’s a point Patrick comes back to later in the report: “Most attackers don’t hack in, they log on.”
That pattern is unlikely to change until people receive the same sustained attention as technology has received for years. You can invest in better technology and tighter processes, but if your people haven’t built the right habits, the risk remains.
What is holding organisations back
If the risk is so clearly understood, why are so many organisations still not acting on it?
In our work at Mindshift, I see two consistent patterns. The first is leadership support. When cybersecurity culture and awareness is not a genuine priority at the top, it rarely gets the attention needed.
The second is a mistaken belief that people are a problem that cannot be solved and that containing the damage after a mistake or security incident is the best that can be done. That belief is both wrong and costly.
People are not just the risk, they are a critical part of information protection and security issue detection. The organisations making the most progress are the ones that have invested in building genuinely aware, confident teams. They detect incidents earlier, contain them faster, and recover more effectively.
Patrick Sharp, who sees this play out across organisations every day, puts it directly when asked what is holding organisations back from taking that first step.
“I think there are two main reasons. The first is the belief that it won’t happen to us - 40% of Boards don’t regularly discuss cyber security, they are not prepared themselves, so they are not preparing their staff.The second is that they may think people are a problem that can’t be solved.
Both of those perceptions are incorrect - at some point your business will be a victim of cyber-crime and while people make mistakes, they are also your most effective defensive, detective and response capability.”
Patrick Sharp, General Manager - Aura Information Security
When businesses were asked what they most want from government, the number one answer was expanded cyber security education and awareness. Businesses already know where the answer lies, the challenge is doing something about it.
AI is adding a new dimension
It goes without saying how quickly AI has become part of everyday work, often before organisations have had time to build the awareness, governance and habits needed to use it safely. That gap creates new exposure, for businesses of any size.
The Kordia report reflects this, stating that improper use of AI within the business has jumped from 16% to 24% as a top challenge year on year. Almost 1 in 6 cyber incidents now involve an AI vulnerability or misuse.
In my opinion, the principles of how to use generative AI responsibly from a security awareness perspective, are no different to the use of any third-party cloud service. Ask people to always consider confidentiality and what could happen with the information once it leaves your fingertips. Businesses who are not talking with their people about the risks of AI, at the same pace they are encouraging them to experiment and innovate, are those facing a fast-growing risk.
Where to start
For organisations that recognise the gap but are not sure where to begin, the answer is simpler than it might seem.
Start with what you are trying to protect.
That is always our first step at Mindshift. Before any content is created or any format decided, we work with organisations to identify the specific behaviours creating the most exposure. Without taking this step, you are not managing human cyber risk. You are hoping it manages itself.
Patrick’s advice is consistent with this, and his example makes it concrete.
“The first thing is to work out what you are trying to protect. A small business might recognise that a scammer trying to get your finance team to alter supplier bank details within your payment system, causing payments to be misdirected to an attacker instead of the legitimate supplier, is your number one threat.
Do your finance team know about this? What can they do to identify and prevent this type of attack? How do we embed that in process to make it stick?
What other kinds of threats can they conceive?” For larger businesses, your critical processes and assets are usually more complex, interconnected and custom.
And, expert guidance and prioritised approaches really benefit from an expert in cyber security or cyber awareness, to help you focus your defence on what really matters.”
Patrick Sharp, General Manager — Aura Information Security
The Kordia findings tell the same story they’ve been telling for several years. Human cyber risk isn’t inevitable. When organisations invest in their people in the same way they invest in technology, people become one of the strongest parts of their defence.
If the Kordia findings resonate and you are thinking about where to start, I would be happy to have a conversation. Get in touch at melonie@mindshift.kiwi