---
title: "Human error identified as the #1 reason behind most cyberattacks"
description: A survey of 612 Chief Information Security Officers suggests CISOs have a tough road ahead in an ongoing climate of high-profile data breaches.
image: https://businessinsights.bitdefender.com/hubfs/code.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Filip Truta**](https://businessinsights.bitdefender.com/author/filip-truta) / Jan 16, 2018

# Human error identified as the #1 reason behind most cyberattacks

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks&utm_medium=social&utm_source=facebook)

A [survey](http://www.opus.com/2018-ciso-survey-ponemon-institute/) of 612 Chief Information Security Officers suggests CISOs have a tough road ahead in an ongoing climate of high-profile data breaches.

The survey, sponsored by Opus and conducted by Ponemon Institute, shows 67% of CISOs and Chief Information Officers (CIOs) believe their companies will likely fall victim to a cyberattack or data breach in 2018. And 60% are concerned that a partner or vendor will be to blame.

The most threatening factors named by CISOs, in this order, are:

- The human factor (70% cited "lack of competent in-house staff")
- Inadequate in-house expertise (cited by 65% of respondents)
- Careless employee falling for a phishing scam (65% chance)
- A malware attack, a data breach or a cyberattack (unspecified percentage)
- Inability to protect sensitive and confidential data from unauthorized access (59%)
- Inability to keep up with the sophistication of the attackers (56%)
- Failure to control third parties' use of sensitive data (51%.)
- Disruptive technologies – i.e. Internet of Things (IoT) devices (60% of respondents considered these the most challenging to secure)
- Mobile (54%)
- Cloud (50%)

As readers may have already noticed, the first three bullet points actually represent the same factor: **human error**. Many other studies also point to the same key factors (in a similar order of importance) as responsible for most data breaches and cyberattacks.

And CISOs should know. Starting this year, their job [depends](https://businessinsights.bitdefender.com/how-a-data-breach-left-two-equifax-executives-jobless-and-eroded-public-trust-overnight?hsLang=en-us) on jumping over these hurdles. 45% of them fear job loss in the event of a data breach this year, and 69% anticipate their roles will be even more stressful.

The survey results don’t mention the EU General Data Protection Regulation, but the GDPR is likely a key reason behind these concerns. Starting May 25, when the new regulation goes into effect, the GDPR will compel data processing companies to protect that data, [or else](https://businessinsights.bitdefender.com/six-in-10-us-employees-clueless-about-gdpr-survey?hsLang=en-us).

Money could be another reason. According to the same poll, less than half of CISOs believe their IT security budgets will increase – a finding that [constantly crops up](https://businessinsights.bitdefender.com/security-struggles-smbs?hsLang=en-us) in such studies since 2016.

"It's not an easy time to be a CISO – there's a lot of pain obvious in these survey results,” said Dr. Larry Ponemon, Chairman of Ponemon Institute. “Data breaches and cyberattacks continue to plague organizations and the responsibility of protecting sensitive data stops with the CISO. It's critical that companies support CISOs and reduce risk by implementing standard processes, including policy review and documentation, senior leadership and board member oversight, as well as other safeguards to reduce their vulnerability."

It's not all bad news, though. Looking ahead, more than a third of respondents say they “see a path” to a stronger cybersecurity culture, and half say their boards are starting to get more involved in IT security.

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/cisos-have-an-opportunity-to-shine-as-regulations-enforce-change-gartner-says?hsLang=en-us>

### [CISOs Have an Opportunity to Shine as Regulations Enforce Change, Gartner Says](https://businessinsights.bitdefender.com/cisos-have-an-opportunity-to-shine-as-regulations-enforce-change-gartner-says?hsLang=en-us)

<https://businessinsights.bitdefender.com/warranty-service-provider-security?hsLang=en-us>

### [Cyber Warranties Could Be Next Big Service Provider Differentiator](https://businessinsights.bitdefender.com/warranty-service-provider-security?hsLang=en-us)

<https://businessinsights.bitdefender.com/security-flaws-public-cloud-encryption?hsLang=en-us>

### [UK CISOs fear security flaws in the public cloud, yet only one company in five encrypts all data](https://businessinsights.bitdefender.com/security-flaws-public-cloud-encryption?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Filip Truta",
    "url" : "https://businessinsights.bitdefender.com/author/filip-truta"
  },
  "datePublished" : "2018-01-16T11:37:36.000Z",
  "headline" : "Human error identified as the #1 reason behind most cyberattacks",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/code.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/human-error-identified-as-the-1-reason-behind-most-cyberattacks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```