Office workers and CISOs really aren’t on the same page when it comes to security


There appears to be a lack of cybersecurity awareness amongst many office workers, despite most believing that they have been adequately trained, new research has claimed.
A survey from Encore of 100 C-level executives, 100 Chief Information Security Officers (CISOs) and 500 office workers in the US and the UK found a significant security knowledge gap between IT teams and workers.
Some of the more worrying findings include the failure of over half (57%) of staff to properly define what a phishing attack is, yet 90% of C-Suite executives believe they provide adequate cyber awareness training, and 80% of staff agree.
Bad practices
If this is the case, though, it seems none of that training has sunk in. Basic security practices are seemingly being ignored, as over a third of employees use the same password for both work and personal devices, and 37% use personal devices for work purposes.
Again, though, leaders appear blind to this fact. 71% of executives are confident that they deploy enough safeguards to secure their business, including from human error.
21% aren’t confident in their safeguards though, and 8% think that their workers pose no risk at all.
“Despite hundreds of reported breaches making the headlines each year – often featuring news of an exploited user account or an exposed password – it’s concerning that nearly a third of organizations have insufficient defenses around the workforce,” says Encore CTO Lior Arbel.
Arbel believes that firms treat cybersecurity training as a box-ticking exercise, and that as threats continue to evolve, keeping pace with adequate training is hard.
“Business leaders trust that their staff are being well trained, and each individual trusts that their employers are providing them with all the knowledge and tools they need… however, a gap between perceptions and reality has formed – and it needs bridging immediately,” Arbel concludes.
Other research has found similar failings among workers, such as the prevalence of malicious links in emails being opened, unaware that they are used as part of phishing attacks to elicit passwords and other credentials from businesses, or otherwise infect the target system with malware.
There appears to be a lack of cybersecurity awareness amongst many office workers, despite most believing that they have been adequately trained, new research has claimed. A survey from Encore of 100 C-level executives, 100 Chief Information Security Officers (CISOs) and 500 office workers in the US and the UK…
Recent Posts
- Andor is on the offensive in latest season 2 trailer
- Apple’s latest iOS update improves CarPlay, but not everyone will be able to access it
- Google is replacing Gmail’s SMS authentication with QR codes
- A new era for VPN testing? ATMSO publishes the first-ever testing standards in an “important milestone”
- 10 Best Laptop Stands for Any Setup, Tested and Reviewed (2025)
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010