91心頭

With cyberattacks up, you need to know what poses the biggest security risk

Date:

Share post:

Seventy-nine percent of organizations suffered a cyberattack within the last 12 months, up 11 percentage points from 2023, and about half (47%) of all educational organizations faced unplanned expenses to fix security gaps due to a security incident, by Netwrix Research Lab.

While incognito hackers and dangerous malware tend to occupy our imagination when it comes to cybersecurity, one surprising stakeholder was identified as IT professionals’ biggest risk to their cloud and on-premise infrastructure: company employees.

“Threats from business users usually involve mistakes or negligence, rather than malicious actions,” says Dirk Schrader, vice president of security research at Netwrix.

IT workers in education a lack of budget and being understaffed as their top data security challenges. However, employee mistakes or negligence have become an equally concerning security issue across all industries studied, preoccupying nearly half of all respondents (47%). Phishing and user account compromise were the two most common security incidents in the education sector alone. Worldwide, 55% of IT professionals reported cyberattack incidents associated with account compromise, a 39-percentage-point spike since 2020.

“The survey trends confirm what industry experts have been saying for years: Identity is the new perimeter,” said Ilia Sotnikov, security strategist at Netwrix. “Attackers will continue to target them andsooner or latersucceed.”


More from 91心頭: Take this leaders advice on bringing AI to the classroom


However, defenders are also increasing detection capabilities, Sotnikov added. Business executives are becoming more aware of the business risks of security incidents, heightening transparency and influencing the number of reported incidents. Multi-factor authentication, backups and password management techniques continue to be the most highlighted measures to protect company data.

“The best approach to mitigating the associated risks is to implement guardrails for end users and admins that keep mistakes from causing serious consequences,” Schrader says.

This trend is correlated to growing cloud adoption and the rise in remote and hybrid work. Over 80% of educational institutions have a hybrid IT architecture, compared to 74% across other industries.

“To enable research and collaboration, while staying on budget, educational institutions often provide a variety of shared devices and systems exposed to the internetcreating a massive attack surface,” Schrader said. “To mitigate risk, it is crucial to enforce strong password policies that prevent the use of weak and compromised passwords, implement multi-factor authentication (MFA), and adhere to the least privilege principle.”

Alcino Donadel
Alcino Donadel
Alcino Donadel is a 91心頭 staff writer and Florida Gator alumnus. A graduate in journalism and communications, his beats have ranged from Gainesville's city development, music scene, and regional little league sports divisions. He has triple citizenship from the U.S., Ecuador, and Brazil.

The Always-On Insight and Networking Platform for Superintendents and Their Teams

AI-driven insights peer-to-peer collaboration and more build exclusively fot K-12 Superintendents and thier leaders
Built for the uniqueness of the superintendent role and their supporting team.Most platforms treat all K12 leaders the same. 91心頭+ recognizes that superintendents face a unique level of pressure, complexity, visibility, and responsibilityand gives them a space designed specifically for the demands of the top job.
A community where you dont have to explain the context.Skip the backstory. 91心頭+ understands the job, the politics, the stakes, and the pace.
Your decisions shape communities.Find the tools and peer insight to make them with confidence here.
Leadership tailored to the realities of running a district.From board relations to budgets, crisis response to community trust91心頭+ focuses on the challenges only superintendents navigate each day.
Built for superintendents.Powered by superintendents. Trusted by superintendents. If you run a district, you belong here.

Related Articles