Connect with us

Hi, what are you looking for?

HEADLINES

Only 12% of employees are fully aware of company’s IT security policies – Kaspersky Lab

A lack of IT security awareness remains a worrying reality for businesses around the world, according to a recent study of consumers conducted by Kaspersky Lab and B2B International. The research found that just one tenth (12%) of employed respondents are fully aware of the IT security policies and rules set in the organizations they work for. 

Security is a trickier challenge. Worried that packets will be intercepted? That’s relatively easy: Use encryption, such as SSL. This leaves it to the programmers to acquire and maintain the digital certificates. IMAGE FROM PIXABAY.COM

A lack of IT security awareness remains a worrying reality for businesses around the world, according to a recent study of consumers conducted by Kaspersky Lab and B2B International. The research found that just one tenth (12%) of employed respondents are fully aware of the IT security policies and rules set in the organizations they work for.  This, combined with the fact that half (49%) of employees consider protection from cyberthreats a shared responsibility, presents additional challenges when it comes to setting the right cybersecurity framework.  

IMAGE FROM PIXABAY.COM

The study of 7,993 full-time employees which asked about policies and responsibilities for corporate IT security also revealed that 24% of employees believe there are no established policies in their organizations at all. Interestingly, it seems that ignorance of the rules is no excuse, as around half (49%) of the respondents think all employees, including themselves, should take responsibility for protecting corporate IT assets from cyberthreats.

However, as another study from Kaspersky Lab proved, sometimes staff do exactly the opposite. According to the report “Human Factor in IT Security: How Employees are Making Businesses Vulnerable from Within”, careless personnel contributed to the attack in 46% of cybersecurity incidents within the last year.

This discrepancy could be particularly dangerous for smaller businesses, where there is no dedicated IT security function and responsibilities are distributed among IT and non-IT personnel. Neglecting even basic requirements, such as changing passwords or installing necessary updates, could jeopardize overall business protection. According to Kaspersky Lab experts, top management, HR and finance specialists who have access to their company’s critical data are usually most at risk of being targeted.

To deal with this problem, small and medium-sized businesses would benefit from regular IT security awareness training for staff and from products tailored to their specific needs. For example, Kaspersky Endpoint Security Cloud includes features such as preconfigured security settings, immediate protection across all devices and easy management capabilities that do not require in-depth expertise from its administrator, thereby reducing the burden on overstretched IT teams.

“The issue of unaware staff can be a major challenge to overcome, especially for smaller businesses where a cybersecurity culture is still being developed. Not only can employees themselves fall victims of cyberthreats, but they are also obliged to guard their company from those threats in the first place. In this regard, businesses should pay attention to educating staff and introducing easy to use and manage, but still powerful solutions that make this achievable for those who are not experts in IT security,” said Vladimir Zapolyansky, head of SMB business at Kaspersky Lab.

Advertisement. Scroll to continue reading.

Kaspersky Lab’s SMB portfolio includes products that cover the various needs of very small, small and medium-sized businesses. Smaller businesses would benefit from the combination of powerful protection and ease of management in Kaspersky Small Office Security and Kaspersky Endpoint Security Cloud, while larger companies may find more use in the advanced security settings and targeted applications for enhanced mobile, server and email protection found in the Kaspersky Endpoint Security for Business suite.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

HEADLINES

Password guessing and valid account misuse rank among the most effective tactics used by cyber criminals in 2025. This trend reflects a strategic shift,...

Advertisement