KnowBe4 report links training to fewer data breaches
KnowBe4, a cybersecurity platform focused on human risk management, has released a white paper detailing how security awareness training (SAT) can significantly reduce data breaches. The report analyses data from over 17,500 data breaches sourced from the Privacy Rights Clearinghouse database alongside KnowBe4's customer statistics to evaluate the impact of SAT on organisational cybersecurity.
The findings reveal that organisations with robust SAT programmes are 8.3 times less likely to be listed in public data breach records annually. Remarkably, 97.6% of KnowBe4's current U.S. clients have not encountered a public data breach since 2005. Further, those clients who have suffered breaches were 65% less likely to experience subsequent breaches after engaging with KnowBe4's services. An additional observation was that 73% of breaches among current KnowBe4 customers occurred before they implemented the company's SAT.
KnowBe4 suggests that organisations implement SAT programmes that incorporate quarterly training sessions and simulated phishing tests. The report underscores that frequent engagement typically results in heightened mitigation of cybersecurity risks. The study addresses a pivotal question within cybersecurity: Does security awareness training tangibly lessen an organisation's susceptibility to cyberattacks? The analysis reveals evidence that organisations participating in ineffective SAT witness notable reductions in human-induced risks and fewer security compromises.
Roger Grimes, KnowBe4's Data-Driven Defense Evangelist, highlighted the significance of the findings: "If you add up all other causes for successful cyberattacks together, they do not come close to equalling the damage done by social engineering and phishing alone. The evidence is compelling and clear. Effective security awareness training, with regular simulated phishing exercises, educates employees and significantly reduces the human risk of cybersecurity threats." His statement underscores the crucial role regular training plays in reducing susceptibility to threats predominant in the data breach landscape, where social engineering and phishing constitute 70% to 90% of such breaches.
KnowBe4 defines an effective SAT programme as incorporating monthly training and simulated phishing exercises. The comprehensive analysis in the white paper "Effective Security Awareness Training Really Does Reduce Breaches " is a valuable resource that elucidates the strategic value of SAT in contemporary cybersecurity efforts.