Skip to main content

In 2024, human risk surpassed technology gaps as the biggest cybersecurity challenge facing organisations worldwide. Despite billions spent on sophisticated technology stacks, breaches continue unabated because security isn’t just a technology problem, it’s fundamentally a human one.

The Human Factor in Cybersecurity

The statistics paint a stark picture: 95% of data breaches involve human error. Insider threats, credential misuse, and user-driven errors now account for most security incidents. Attackers increasingly target the human layer with precision, leveraging AI-powered phishing, exploiting collaboration tools, and bypassing traditional authentication methods.

Two-thirds of security decision-makers interviewed by Mimecast believe it’s inevitable or likely their organisation will suffer a negative business impact from a major security incident, an attack linked to email or collaboration tools in 2025. This prediction follows one of 2024’s most disruptive breaches—the Transport for London (TfL) cybersecurity incident in September 2024—which was caused by human error after an employee fell victim to a sophisticated phishing attack. The breach led to significant service disruptions across London’s transit network, affecting over 4 million daily commuters and costing TfL an estimated £35-£50 million in recovery costs, compensation claims, and lost revenue.

The incident underscored the critical need for enhanced security awareness training, as over 90% of cyberattacks still begin with phishing emails, according to the UK’s National Cyber Security Centre (NCSC).

Key Findings from the 2025 Survey

Mimecast’s research, which surveyed 1,100 IT security and IT decision makers across six countries, reveals several critical trends:

  • 43% of organisations reported an increase in internal threats or data leaks initiated by compromised, careless, or negligent employees in the past year
  • 66% expect data loss from insiders to increase in the next 12 months
  • The average cost of an insider-driven data exposure is approximately £10.75 million
  • 95% of respondents still expect email security challenges in 2025
  • 44% have seen an increase in collaboration tool threats
  • 79% agree that collaboration tools introduce new security vulnerabilities requiring urgent attention

The Rise of Human Risk Management (HRM)

Human Risk Management (HRM) represents a strategic shift from traditional security approaches. Rather than focusing solely on technological defences, HRM addresses the human element through comprehensive frameworks that identify, assess, and mitigate risks associated with human behaviour.

A key insight from the report shows that just 8% of employees account for 80% of security incidents, highlighting the need for targeted intervention rather than one-size-fits-all approaches. HRM platforms provide visibility into both external and internal risks, helping organisations monitor collaboration tools, identify vulnerable employees, and prevent unauthorised data sharing before breaches occur.

Budget Challenges and AI Impact

While 85% of organisations reported cybersecurity budget increases in the past year, only 3% feel their budgets are sufficient. The majority still require additional investment for staffing (57%), collaboration tool security (52%), and email security (47%).

AI emerges as both threat and a solution. An alarming 95% of organisations are using AI to defend against cybersecurity attacks, yet 81% remain concerned about potential sensitive data leaks via generative AI tools. More concerning, 55% are not fully prepared with specific strategies for AI-driven threats.

Cybercriminals increasingly leverage AI to create more convincing phishing emails, generate deepfakes, and automate vulnerability scanning, greatly decreasing the time needed to discover potential exploits.

Building Security-Conscious Cultures

While 87% of organisations train employees quarterly to spot cyberattacks, 33% still fear mistakes and human error in handling email threats, and 27% worry about vigilance lapses due to fatigue. Traditional security awareness approaches are evolving into more sophisticated, personalised programs that focus resources on high-risk users.

Effective HRM involves creating security-positive environments where protection becomes second nature rather than obligation. Leading organisations implement interactive training, risk-based approaches, and continuous measurement to create lasting behavioural change.

Moving Forward

The future of human risk management lies in integrated platforms that unify various security functions while balancing security with productivity. As organisations face increasingly sophisticated threats, focusing on the human element, (their most vulnerable asset), offers the greatest opportunity to strengthen their security posture.

By addressing human risk through modern, integrated approaches that combine AI-powered analysis, behavioural monitoring, and personalised training, organisations can transform their workforce from their biggest vulnerability into their strongest defence against cyber threats.

Conclusion: Strengthening Your Security Fabric

The Cyber Essentials requirements update in April 2025 directly addresses the findings from the State of Human Risk report. As human risk surpasses technology gaps as the primary cybersecurity challenge, organisations must adapt their approach to include both technical defences and human factors.

To prepare effectively, we recommend:

  • Assessing your human risk profile, focusing on the critical 8% of users responsible for most security incidents
  • Prioritising cloud services and collaboration tools security, where 79% of organisations report new vulnerabilities
  • Implementing continuous security awareness beyond quarterly training
  • Developing incident response plans that address both technical and human-error scenarios

Need a partner that enhances your business communications while strengthening your security posture? We’re here to support your journey toward compliance with the new requirements while protecting your organisation from the ever-growing threat landscape.

Contact us today to discuss your specific compliance and security needs.

Leave a Reply