Employee-Related Security Risks Are Addressed in our Latest Ponemon Institute Study

by Michael Bruemmer 3 min read June 1, 2016

What keeps your cyber security team up at night, and does it weigh equally on the minds of managers? Do they lose sleep worrying about malicious attacks from outside your organization? Or do they fear a careless employee will leave a laptop in an unlocked car or use an unsecured personal mobile device to access proprietary company information?

Employee-related security risks are the top concern for security professionals, our new study, Managing Insider Risk Through Training & Culture, found. The Ponemon Institute polled more than 600 information security professionals at companies that have a data protection and privacy training program. The study found that while 55 percent of those surveyed have already had a malicious or negligent employee cause a security incident, few are taking adequate steps to improve security from within.

Not on the same page

One reason for this could be the imbalance between how the IT department perceives employee risk and how the C-suite does. While 66 percent of security professionals view employee-related risk as the biggest security threat, just 35 percent of them say their senior managers share that view. They may also feel less able to catch slip-ups versus intentional acts; security pros are far more concerned that an employee will unintentionally cause an incident than they are about workers potentially perpetrating malicious attacks.

Often, companies focus their cyber security efforts on preventing, catching and remedying intentional attacks. And while they can do much to reduce the risk of employees unintentionally causing an incident, few companies are doing everything they can. Less than half (46 percent) of the surveyed companies require cyber security training for all employees, and 60 percent don’t make employees retrain after a data breach.

Actionable suggestions for teachable moments

The problem of employee-related security risks is not unsolvable. Companies need to take steps to create a culture of security at every level of their organizations. These steps should include:

  • Requiring mandatory advanced-level training for all full and part-time employees and contract workers.Typically, companies that do provide training don’t require it for all employees, or they take a tiered approach that fails to provide all employees with a comprehensive understanding of the risks. Our study found just 43 percent of companies provide only one basic course for all employees. Basic courses often omit significant risks that can lead to a data breach. What’s more, retraining needs to occur on an ongoing basis, as new threats emerge in the cyber security realm. Retraining is especially important following a breach, when employees’ awareness of cyber security risks is highest.
  • Establishing and enforcing a system of carrots and sticks.More than half (56 percent) of companies deal with an employee’s careless handling of data by having that employee meet one-on-one with a superior, and 51 percent have them meet with an IT security person. Less than half (45 percent) give formal reprimands, 19 percent demote the employee, and 16 percent cut salary, bonuses or incentives. However, sticks are only half the solution. Companies also need to incentivize employees to be cognizant of cyber security and few are doing a good job of it. In fact, 67 percent do nothing at all to encourage employees to proactively protect data.

Employees should be a company’s greatest asset. With the right training and an ongoing emphasis on cyber security, every member of your corporate team can help reduce your organization’s risk of a negligence-related cyber security incident.

Related Posts

Customer Spotlight: How Matrix Rental Solutions Strengthens Trust in Affordable Housing

Learn how Matrix continues to deliver a secure, trusted rental experience as fraud tactics evolve. Read more!

July 31, 2026 by Laura Burrows
What Is AI Decisioning?

Every business makes decisions about people and transactions all day long. Should we approve this loan? Is this purchase fraud? Which customer should get this offer, and what should it be? For a long time, those decisions were made in one of two ways: a person reviewed each case by hand, or the company wrote fixed rules, like "approve anyone with a credit score above 700." Both work. Both also leave value on the table. The manual review is slow and hard to scale. The fixed rule can turn away good applicants and is slow to adapt when the market shifts. AI decisioning is a third way. What makes AI decisioning work Instead of relying on a single reviewer or a rigid rule, automated decisioning uses models that learn from data — studying how thousands of past cases turned out, finding the patterns that predict an outcome, and applying them to each new decision, often in real time. The result is faster, more consistent decisions. But a model on its own isn't the whole story. Getting real value from AI decisioning takes good data to learn from, AI analytics to generate insights, the tools to act on it and the governance to keep it compliant. What we've found is that the pieces only pay off when they work together, and that is where we're built differently. A model is only as good as what it learns from, and we pair your data with one of the deepest views of consumer and commercial credit: decades of full-file history and vetted attributes. Then we give you the tools to act on it. Use cases across your business Whether you're trying to grow your customer base, reduce fraud, manage lending risk, or improve collections, automated decisioning brings all the pieces together to make more accurate, consistent and explainable decisions at scale. Fraud and Identity A fraudulent transaction that slips through costs money and erodes trust. Rules are static, and fraudsters move fast. They'll probe boundaries, find the blind spots and move to the next scheme. By the time the rules are updated, they're already three steps ahead. How AI decisioning changes this: AI fraud detection with real-time risk scoring and decisioning across transactions and customer interactions Intelligence that continuously learns from results to help adapt fraud strategies as threats evolve Reduced false positives and less friction for customers at account opening and checkout Identity verification tools that confirm someone is who they say they are without slowing down the experience Credit and Lending Loan approval is where the relationship begins. Credit risk decisioning helps lenders find that delicate balance between approving enough people to grow, but carefully enough to manage risk. Missing that balance means turning away good customers or taking on losses that are difficult to absorb. How AI decisioning changes this: Increased approval opportunities for creditworthy applicants without increasing overall risk Models you can update and deploy quickly as market conditions change, rather than waiting months Ability to run "what-if" scenarios to test how a new strategy would have performed on your historical data before putting it live Collections Which customer should your team reach out to today? Through which channel? What kind of message? If you reach out too aggressively, you push someone who might have recovered into default. If you wait too long, you lose them. If you call someone at work, they resent you; if you text, they might ignore it. If you offer a payment plan, they might accept it, but only if the terms make sense to their financial situation. How AI decisioning changes this: Optimized next-best-action and contact-channel strategies for each individual customer Improved recovery potential through better targeting Less time spent on accounts with a lower propensity to pay, freeing your team for higher-impact cases Ability to segment and test new strategies before rollout Customer Acqusition Finding the right customers is about reaching the right people with the right offer at the right time. To stay competitive, it’s now a requirement to balance growth with risk while creating a seamless experience converting prospects into customers. How AI decisioning changes this: More precise prospect targeting using credit, behavioral, and alternative data, where permitted, to identify consumers most likely to respond Personalized offers delivered in real time Dynamic decision strategies that can be updated quickly as market conditions and customer behavior change Ongoing testing and optimization of acquisition strategies to improve campaign performance and support customer lifetime value Driving results with AI decisioning Every customer interaction is a decision. Businesses that can adapt quickly will be better positioned to grow, manage risk, and deliver the experiences customers expect. The technology will continue to evolve, but the goal remains the same: making informed decisions that balance business objectives, risk, and customer experience. Learn more about our decisioning software

July 27, 2026 by Zohreen Ismail
Why Innovation Matters for Members First Credit Union

Learn how Members First Credit Union uses innovation and data-driven insights to better serve members and expand financial opportunity.

July 24, 2026 by Scarlet Nickel

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe