Accidental cyber breaches caused by employee error or third party suppliers accounted for 30% of the total breaches recorded in the first six months of 2017.
That is according to new research by Beazley Breach Response (BBR) Services, which reveals that these types of breaches were particularly prevalent in the healthcare sector, where they accounted for 42%.
However, hacking and malware attacks continue to dominate, and were responsible for 32% of the incidents that were experienced by organisations this year.
“Unintended breaches account for almost one-third of all data breach incidents reported to Beazley and show no signs of abating,” Katherine Keefe, global head of BBR Services, said.
“They are a persistent threat and expose organisations to greater risks of regulatory sanctions and financial penalties. Yet, they can be much more easily controlled and mitigated than external threats.
“We urge organisations not to ignore this significant risk and to put more robust systems and procedures in place.”
This comes after previous research from Willis Towers Watson (WLTW) earlier this year showed that companies are focusing on technology at the expense of people risks when trying to improve their cyber defence.
Its data shows that approximately 90% of all cyber claims are the result of some type of human error or behaviour, while employee negligence or malicious attacks account for 66% of cyber breaches.
By contrast, only 18% are driven by an external threat, and cyber extortion accounts for just 2%, with businesses now being urged to focus more on how their workforce could be leaving them vulnerable to cyber risks.
“Evidence suggests that many businesses are taking an overly technocratic approach to cyber risk and are in danger of missing the bigger picture,” WLTW global cyber risk head, Anthony Dagostino, said.
“While technology has an important role to play, it really needs to be linked with an understanding of the human element.
“The simple truth is that a data compromise is more likely to come from an employee leaving a laptop on the train than from a malicious criminal hack.
“We believe employees and companies with a strong culture and cyber-aware workforce are the first line of defence against cyber risk.”
An increasing reliance on data and IT systems has seen cyber incidents shoot to the top of the most pressing risks facing businesses worldwide, research by Allianz has uncovered.
17 January 2020
The majority of risk managers worldwide cannot adequately assess the threats posed by new technologies, research by Accenture has found.
10 December 2019
Financial institutions will save $7bn (£5.43bn) by 2024 thanks to blockchain technology and the automation of customer checks, a market research firm has predicted.
05 November 2019
Why InsurTech? A Pressured Insurance Value Chain
By Andrew Sagon, Andrew Johnston and Matthew Wong
InsurTech is a burgeoning phenomenon that is modernising the insurance industry. It is disrupting the traditional value chain whereby insurers offer loss protection, and shifting the emphasis to risk mitigation. Incumbents face disintermediation as investors in search of higher yields pour money into insurance-linked instruments in the capital markets. And entrepreneurial businesses are targeting friction costs and inefficiencies within every aspect of the traditional value chain.
Nimbleness and agility will unlock potential
By Elinor Friedman, Andrew Harley and Klayton Southwood
Recent Willis Towers Watson surveys in the U.S. have shown that P&C and life insurers in developed markets are taking seriously the potential of big data and predictive analytics to improve their businesses. Nimbleness and agility, rather than brute force, are likely to be key to realizing that potential.
Driven by technology, toolkits and talent
By Claudine Modlin and Graham Wright
Advanced analytics is helping some insurers offer innovative products and solutions. What do insurers need to know about the changing nature of analytics and whether it is worth the investment? Claudine Modlin and Graham Wright discuss technology, toolkits and talent — topics that may help you decide.
Risk transfer is part of a comprehensive solution
By Adeola Adele, Patrick Kulesa, Kevin Madigan and Alice Underwood
Given the dynamic nature of cyber-risk, taking a multidimensional approach that integrates board governance, technology solutions, behavioral change and risk transfer solutions can help reduce risk to a manageable level.