FAQ’s
Q: What is human-activated risk in cybersecurity?
A: Human-activated risk refers to the cybersecurity threats that involve the human element. Phishing and social engineering are identified as the top cyber threats facing companies today. A significant majority of all data breaches, specifically 68%, include the human element, and email alone accounts for 98% of the attack vectors used in social engineering.
Q: Why is human-activated risk a major cybersecurity concern for companies?
A: Human-activated risk is a major concern because no email security system is perfect, and technology is just one part of the overall security posture. Organizations need a platform that goes beyond traditional security to address risks stemming from human behaviour. The majority of C-level leaders now agree that building a strong security culture is a high priority.
Q: How can organisations effectively manage human-activated risk?
A: Organisations can effectively manage human-activated risk by focusing on strengthening their “human firewall”. This involves a comprehensive approach designed with human behaviour in mind, which can combine elements such as cloud email security, advanced risk scoring, awareness training, and real-time coaching. By aggregating data from security software and systems, organisations can implement integrated, personalised, and adaptive security controls that engage users as active participants in their cyber defences. Such systems should provide an adaptive experience that evolves with the threat landscape.
Q: What are key strategies to reduce human-related cybersecurity vulnerabilities?
A: Key strategies include:
-
- Educating users and making them an integral element of the cyber defence strategy.
- Implementing security awareness training, which on average can significantly reduce an organisation’s susceptibility to phishing (e.g., from over 30% to less than 5% after 12 months).
- Analysing and prioritising user-reported emails, transforming real-world phishing attempts into training opportunities.
- Delivering real-time security coaching to users when risky behaviour is detected, as immediate notifications reinforce comprehension and retention of security training and established policies.
- Utilising AI-driven agents to automate and enhance human risk management by generating realistic phishing templates and quizzes, and delivering personalised, adaptive training based on a user’s risk profile.
- Employing machine learning and neural networks to continuously assess human risk and dynamically adapt policy controls against inbound and outbound email threats, providing real-time “teachable moments” through dynamic, context-aware banners and prompts. This multi-pronged approach allows organisations to build a fully orchestrated and effective security culture.