Most UK businesses have suffered cyber attacks due to employee error

A study by Gallagher has found that 60% of cyber attacks on UK businesses have been caused by employee error.
Of the employee error-related cyber attacks on UK businesses, 14% of incidents resulted in customer data being stolen.
30% of respondents affected said that their company’s system went down for four to five days, while a third said their business was out of action for up to three days.
Additionally, one in seven (14%) of respondents said that the cyber attack or data breach impacted their business’s reputation, while one in eight (12%) experienced a financial impact.
A further 14% said that an attack resulted in customer data being stolen, and despite the risk of fines under the EU General Data Protection Regulation (GDPR), only 39% of UK decision makers have invested in expert advice to assist them in mitigating security issues.
“Virtually all businesses are at risk of a cyber attack, and as this research shows, it is often an employee mistake which causes the problem,” said Tom Draper, head of cyber at Gallagher. “Cyber criminals have become increasingly sophisticated with ways of trying to obtain access to data or a company’s system, and it’s hard to remove the risk of human error entirely.
“However, by businesses taking a comprehensive, multi-layered approach to cyber security – including ensuring they have the appropriate insurance in place, establishing effective training programmes for employees and implementing technologies that secure the most sensitive data – they can save both money and resources in the long run, while also helping to mitigate the potential threat of an attack.”
Despite the high proportion of UK businesses experiencing cyber attacks caused by employee error, 71% of respondents stated that human error when it comes to security is a worry, while 64% said that they remind employees regularly about the risk of cyber crime.
In addition, 42% of business leaders said that they have installed off-the-shelf preventative technology, while 39% opted for a tailored product.
In regards to what kinds of attacks UK businesses encountered as a result of employee error, malware (39%) was the most common, followed by phishing emails (35%) and data breaches (28%).
1000 UK business leaders were surveyed by Gallagher for this study.
source informationage
Industry: Cyber Security

Latest Jobs
-
- Senior Presales Consultant | Managed Security Services | London
- London
- N/A
-
Senior Presales Consultant – Managed Security Services Location: London-commutable (Hybrid) A well-established cyber consultancy is seeking a Senior Presales Consultant to drive growth across its managed security services / advisory portfolio. This hybrid role bridges commercial and technical expertise supporting solution design, shaping customer proposals, and guiding conversations from scoping through to delivery. Key experience: Background in managed security services, including SOC operations and threat detection Strong knowledge of cloud and on-prem security tooling (SIEM, EDR, IAM) Penetration testing Proven ability to translate technical concepts into clear business value Confident in customer-facing engagements and pre-sales delivery Experience contributing to bids, proposals, and RFI/RFP responses To find out more contact me on 07884666351 Visa sponsorship is unfortunately not available for this role.
-
- New Business | Cyber Security | Overlay sales (UK Based- London commutable)
- London
- N/A
-
New Business Sales Hunter needed | Cybersecurity (UK Based- London commutable) Are you looking for uncapped commission, a fun and sociable team that drives success with no politics? If so...You must Have a demonstrable history of sales success in Cyber Security Follow Weatons law. The role: Seeking a proven New Business Sales Hunter to join an established, successful and expanding team. New business focused - £500-750 GP Sell a blend of security services & professional services. Ideal experience selling some or all of the following Cyber strategy & risk management Managed detection & response (MDR) Penetration testing Compliance & audit support You: Strong cybersecurity/IT services sales track record. Confident selling into mid-market & enterprise. UK based - London commutable Hunter mindset, full sales cycle ownership. Don't just send an email to apply give me a call on 07884666351
-
- New Business Sales Hunter | Cyber Security (UK Based)
- London
- To attract the right person
-
New Business Sales Hunter needed | Cybersecurity (UK Based) Are you looking for uncapped commission, a fun and sociable team that drives success with no politics? If so...You must Be UK based - and able to achieve UK SC clearance. (sorry no visas) Have a demonstrable history of sales success in Cyber Security Follow Weatons law. The role: Seeking a proven New Business Sales Hunter to join an established, successful and expanding cyber security firm. New business focused - £1m GP year one target (ramped). Sell a blend of security services & professional services. Ideal experience selling some or all of the following Cyber strategy & risk management Managed detection & response (MDR) Penetration testing Compliance & audit support You: Strong cybersecurity/IT services sales track record. Confident selling into mid-market & enterprise. UK based - London commutable 1x per week. Hunter mindset, full sales cycle ownership. Don't just send an email to apply give me a call on 07884666351