Whoops, human error does it again

21.04.2006
The "whoops factor" and the "non-deliberate insider" are just two user profiles responsible for the vast majority of global organizations being hit by a virus or worm in the past 12 months.

The annual Computing Technology Industry Association (CompTIA) survey of 574 global organizations on information security and workforce impressions of information security found nearly 60 percent of information security breaches were caused by human error through lax security training. Last year, "human error" was responsible for 47 percent of security breaches.

Brian McCarthy, CompTIA chief operating officer, said a level of "enterprise complacency" in regard to employee security procedures may be setting in.

"As we get better from a technology standpoint, many organizations seem to believe that technology solutions alone are sufficient to turn back all attack," McCarthy said.

"The primary cause of security breaches, human error, is not being adequately addressed and the person behind the PC continues to be the primary area where weakness is exposed.

"The fact remains that no technology on its own can be completely successful without an equally strong commitment to information security awareness and training throughout every level of the organization."