Newsletter Subscribe
Enter your email address below and subscribe to our newsletter

With almost 88% of data breaches being caused by employee mistakes, a strong human risk management program with regular employee training and cybersecurity awareness is critical, says Carey van Vlaanderen, CEO of ESET Southern Africa.
Ask any cybersecurity specialist about their biggest network safety concern, and it’s likely that they’ll answer: the human element.
No matter how resilient or intelligent the cybersecurity solution is, it can only be as effective as its weakest link, and people are always a risk.
Whether it’s recycling passwords, a company laptop being stolen or lost with confidential client information, or intentionally overriding company security policies – humans are the biggest threat in the cybersecurity space.
Chief Security Officers, CIOs, and individuals in similar positions of responsibility spend a lot of their time worrying not about technology, but about people.
Humans make mistakes. These mistakes range from failure to properly delete data from devices to preventable errors like clicking on links in phishing emails, to misconfigured network devices and servers.
Humans are also capable of negligence, unfortunately. Data leaks that arise because of human error, such as failure to update security patches or correctly configure servers with known vulnerabilities, are on the rise and now occur almost as frequently as direct security attacks.
Then there’s insider threats, which are unimaginably difficult to detect. From malicious employees or an employee whose credentials have been compromised, all of these vulnerabilities share a common root: humans.
An effective program for managing human risk involves several key components. These include providing regular training and increasing employee awareness, establishing clear policies and procedures, maintaining efficient communication channels, developing plans to respond to security incidents, and conducting regular security assessments to identify and minimize potential risks.
Other necessary steps include implementing robust access controls, monitoring network activity, reviewing and updating security policies while fostering a culture that prioritizes security. Cybersecurity awareness and training work hand-in-hand to address the human element of risk in a number of ways:
Focusing on managing human risk and security training requires strong leadership from within. Leadership commitment is a key ingredient in achieving the organizational momentum needed to create an ongoing culture of learning and growth.
With executive buy-in, sustained investment is possible in the necessary training and development resources such as courses, workshops, and mentorship programs.
With the increasing tech talent shortage in Africa, CIOs are scrambling to ensure that employees brush up on skills and technologies that facilitate business agility and resilience, with cybersecurity knowledge topping the list, despite competing priorities.
Training and upskilling need to be a deliberate exercise, but small teams are often vulnerable to the delivery pressure created by the current needs of the business.
This means that critical training (such as cybersecurity training) takes second place behind current projects, which results in a short-term productivity gain at the expense of long-term skills progress. Creating a balance of short-term project delivery and upskilling/training as outputs to current projects is essential.
By providing regular cybersecurity training and increasing employee awareness, organizations can prevent human errors, detect incidents early, improve incident response, and create a deep culture of security.
As cyber threats increase in complexity and frequency, investing in security skills training is a critical step towards ensuring the protection of people, assets, and data from threats, both internal and external.
By Carey van Vlaanderen – CEO at ESET Southern AfricaÂ