All systems operational · Ormskirk, North West England

Are Your Employees Your Security’s Weakest Link?

65% of employees admit they follow cyber security rules only sometimes or never. Here is what that means for your business and what you can do about it.

The Human Element in Cyber Security

You may have invested in firewalls, password policies, and software updates. But what happens when those measures are bypassed through the behaviour of your own staff? Research shows that more than 65% of employees claim to follow cyber security rules only sometimes or never. That gap between policy and practice is where most breaches begin.

Four out of five employees working remotely use personal devices for work. Personal devices typically lack the security controls of business-managed equipment: weak passwords, outdated software, and connections to unprotected Wi-Fi networks. Two out of five employees admit to downloading sensitive work data onto personal devices. Each of those actions creates exposure that your technical controls cannot address on their own.

The Password Problem

Nearly half of employees reuse the same password across multiple business accounts. Over a third use identical passwords for both work and personal accounts. A compromised personal account can therefore become a direct route into business systems, with no technical attack required.

65% of employees follow cyber security rules only sometimes or never. Policy without understanding does not change behaviour.

What Businesses Can Do

Make rules easy to follow

Employees do not usually break security rules out of malice. They do so because the secure option is less convenient than the alternative. Password managers remove the friction from strong password use. Clear guidance on approved devices and email handling removes ambiguity. The easier the right behaviour is, the more consistently it will be followed.

Run regular, practical training

A one-off briefing is not enough. Regular short sessions that cover current threats and real-world examples keep security front of mind. Simulated phishing exercises that let staff experience realistic attacks in a safe environment are particularly effective.

Recognise good behaviour

When a staff member flags a suspicious email or raises a security concern, acknowledge it. Encouraging vigilance as a positive behaviour shifts the culture away from seeing security as someone else’s problem.

Use technical controls as a backstop

Multi-factor authentication, device management policies, and email filtering reduce the impact when human judgement lapses. These tools do not replace awareness but they limit the damage when mistakes happen.

Support Across the North West

Blowfish Technology provides cyber security awareness training and managed security services to businesses across the North West, including IT Support Manchester, IT Support Liverpool, IT Support Chester, IT Support Ormskirk, IT Support Southport, and IT Support Preston.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.