Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    • Certification

      Validate your skills with the gold standard in HR

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Education Programs

      Expert-led training for real workplace change

      • eLearning
      • Essentials of HR
      • Seminars
      Specialty Credentials

      Go deep in your niche. Stand out in your field.

      • AI + HI Specialty Credential
      • People Manager Qualification (PMQ)
      Executive Voices

      Bring our experts to your stage.

  • Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Tiers
      • Professional
      • Student
      • Global
      • Executive
      • Business
      Membership Benefits
  • Learning
    back
    Learning
    • Certification

      Validate your skills with the gold standard in HR

      • Choosing Your Certification
      • SHRM-CP
      • SHRM-SCP
      • How to Get Certified
      • Prepare for the Exam
      • Recertification
      Education Programs

      Expert-led training for real workplace change

      • eLearning
      • Essentials of HR
      • Seminars
      Specialty Credentials

      Go deep in your niche. Stand out in your field.

      • AI + HI Specialty Credential
      • People Manager Qualification (PMQ)
      Executive Voices

      Bring our experts to your stage.

  • Attend
    back
    Attend
    • Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM26 Annual Conference & Expo
      • The AI+HI Project 2026
      • Talent 2026
      • Linkage Institute 2026
      • BLUEPRINT 2025
      State Conferences

      Attend a SHRM state event to network with other HR professionals and learn more about the future of work.

      Seminars

      Stand out from among your HR peers with the skills obtained from a SHRM Seminar.

      Webinars

      Learn live and on demand. Earn PDCs and gain immediate insights into the latest HR trends.

  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
      Educational Programs

      Designed and delivered by HR experts to empower you with the knowledge and tools you need to drive lasting change in the workplace.

  • Community
    back
    Community
    • Find a SHRM Chapter

      Easily find a local professional or student chapter in your area.

      • SHRM Northern California
      SHRM Connect

      Post polls, get crowdsourced answers to your questions and network with other HR professionals online.

      Membership Councils

      Learn about SHRM's five regional councils and the Membership Advisory Council (MAC).

      Volunteers

      Learn about volunteer opportunities with SHRM.

  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Ask an HR Advisor
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Workplace News & Trends
  3. Data Breach Report Emphasizes Cybersecurity's Human Element
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Data Breach Report Emphasizes Cybersecurity's Human Element

June 15, 2021 | Drew Robb

A man's face is shown on a computer screen.


​For all the millions of dollars an organization might spend on security technology, its employees' decisions and actions do the most to keep the company safe, according to the annual Verizon Data Breach Investigations Report.

The report examined about 80,000 incidents from 2020—described as events that compromise the integrity, confidentiality or availability of an information asset—and more than 5,000 confirmed data breaches.

Phishing attacks to trick employees into revealing login and personal information came up as the top avenue of incursion (more than 30 percent of all incidents). Overall, 85 percent of breaches included a human element and 61 percent related to stolen or misused credentials.

Ransomware was found in 13 percent of human-related breaches, and that's where the pain really comes in. In addition to locking organizational systems, about 10 percent of the ransomware attacks cost organizations an average of $1 million, which included the cash paid out in the ransom, the price tag for remediation and lost revenue.

The statistics indicated that ransomware attacks doubled in frequency over the past year. These attacks are expected to jump again in 2021. Some are straightforward, demanding organizations hand over the cash to regain access to their data. But there are other tactics. Some bad actors gain access, exfiltrate data and threaten to reveal it publicly if the victim does not pay. Others contact competitors or mega-investors to see how much they might be willing to pay for a peek at the files.

Gangsters, Not Geeks

The movies would have us believe that hackers are typically unemployed geeks operating from their parents' homes. To relieve the boredom, they decide to break into the NSA and vandalize the site. If ever that was the case, those days are behind us.

Organized crime is behind 4 out of 5 breaches, and their goal is financial gain, not notoriety. HR heads should be aware that these cybercriminals are actively targeting any organization that might reap big rewards, whether those be monetary, intellectual property, sensitive information or the avoidance of brand damage. Yes, cybercriminals will lock random companies out of their network and demand payment. But they have raised the stakes and now want millions in ransom, rather than thousands.

"The conversation about data leakage has flipped from 'if' to 'when' a company will be breached by malicious actors," said Masha Arbisman, behavioral engineering manager at Verizon Media. "The fight against cyber breaches continues to depend on an organization's ability to train and adapt its members' behaviors to protect against actions such as credential theft, social engineering and user error."

Internal Threats

Another common misconception is that internal actors are a major menace. They are a problem, but damage from a company's own employees is dwarfed by external threats from the criminal fringe. Currently, less than 20 percent of breaches are inside jobs, and only a tiny fraction of 1 percent are from an organization's partners.

"Most internal actors are motivated by greed—they're trying to cash in on the data they steal," said Herbert Stapleton, deputy assistant director in the FBI's Cyber Division. "A much smaller percentage are in it for the laughs. Fewer still are holding a grudge against their employer. And finally, we get to those who are doing this to start a competing business or benefit their next employer."

HR should work closely with IT security and risk management teams to ensure resources are allocated accordingly. The bulk of attention should be levied at external threats. More attention should be paid to proofing up the workforce against social engineering tricks (phishing and other ploys) than to rooting out internal menaces or partner-based incursions. 

The FBI recommends that any organization under attack should go to the Internet Crime Complaint Center and file a report.

"Over the past decade, the cyber threat has grown exponentially with nation-state and cyber criminals increasing the scale, scope and level of sophistication of their cyberattacks," Stapleton said. "Addressing this kind of complex and agile environment requires a more comprehensive response than any one single government agency, business, technology or data source can provide."

Simple Fix

HR should reach out to IT to make sure the department is well-staffed and keeping up with routine tasks such as deploying patches to prevent security incursions.

Hackers are now using automation to quickly zero in on known security holes, according to the Verizon report.

"As such, it's important to limit your public-facing attack surface through asset management, defensive boundaries and intelligent patching," Arbisman said. "One might think that more recent vulnerabilities would be more common. However, as we saw last year, it is actually the older vulnerabilities that are leading the way. These older vulnerabilities are what the attackers continue to exploit."

Drew Robb is a freelance writer in Clearwater, Fla., specializing in IT and business.

HR Technology
Privacy & Security Compliance
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview

  • About SHRM
  • Careers at SHRM
  • Press Room
  • Contact SHRM
  • Post an HR Job
SHRM Named to Newsweek's 2026 America's Top Online Learning Provider List
Advocacy

  • SHRM Advocacy
  • Federal Policies
  • State Affairs
  • Global Policy
  • Take Action
  • SHRM E2 Initiative
Brand Partnership

  • Partnership Opportunities
  • Advertise with Us
  • Exhibit & Sponsorship
  • Recertification Providers
  • Book a Speaker
Member Resources

  • Ask an HR Advisor
  • SHRM Newsletters
  • SHRM Flagships
  • Topics & Tools
  • Find an HR Job
  • Vendor Directory

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Feedback

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

  4. Privacy Policy

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive professional content resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive professional premium resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive executive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now