Concern that an employee will trigger a data breach remains the enterprise’s top security fear. Yet, a study suggests, few corporations are effectively managing this risk.

This assumption comes from a Ponemon Institute survey of 601 individuals in companies that have a data protection and privacy training who are knowledgeable about their employer’s security program. The Institute is part of the security consulting firm Experian Data Breach Resolution.

What the study found was that, 55 percent of these companies have experienced a significant security breach, and 60 percent of respondents said their employees are essentially clueless about security risks. Yet just 35 percent agreed that their senior management team “believes it is a priority that employees are knowledgeable about how data security risks affect their organization.”

Conclusion? “Concern around the issue of employee security risks is not necessarily making companies any more effective at addressing it,” Experian says. “Additionally, the study showed a lack of concern by C-suite executives. This illustrates a clear gap between companies' awareness of the issues caused by employee negligence and their actions.”

Additional key findings from the study:

  • 46 percent of surveyed companies make training mandatory for all employees;

  • 60 percent of companies do not require employees to retake security training courses following a data breach;

  • Only half of companies agree or strongly agree that current employee education programs actually reduce noncompliant behaviors;

  • 43 percent of companies provide only one basic course for all employees, and often these courses don't cover a number of large risks that lead to data breaches.

Read: Many businesses unprepared for cyberattacks

Complete your profile to continue reading and get FREE access to BenefitsPRO, part of your ALM digital membership.

Your access to unlimited BenefitsPRO content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking benefits news and analysis, on-site and via our newsletters and custom alerts
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the property casualty insurance and financial advisory markets on our other ALM sites, PropertyCasualty360 and ThinkAdvisor
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.

Dan Cook

Dan Cook is a journalist and communications consultant based in Portland, OR. During his journalism career he has been a reporter and editor for a variety of media companies, including American Lawyer Media, BusinessWeek, Newhouse Newspapers, Knight-Ridder, Time Inc., and Reuters. He specializes in health care and insurance related coverage for BenefitsPRO.