All blogs

Only 42% of employees follow the company's security measures. How to prevent a looming problem?

2022-02-21 | 5 min Cyber Security

In September 2021, the study "Cybernetic security at a distance" was carried out by Sophos in the Czech Republic, Poland and Hungary. The study on a sample of 800 respondents for each country talks about how employees navigate their company's security policy.

Only half of the employees consider security measures important and understand them

For example, in the Czech Republic, according to the study, roughly half of the employees have a positive attitude towards measures to ensure cyber security. According to 52% of employees, security rules in companies are important for protecting data and company resources. However, only 46% of employees declare their knowledge and compliance. Almost a fifth consider security measures even an obstacle to their work, and 7% admit to deliberately not following policies.

In Hungary, only 45% of employees know and follow their company's security measures, and in Poland even only 42% of employees.

Almost a quarter of employees are not familiar with their company's security policy

More than half of the respondents are aware of the importance of security measures, but less than half follow them. Every tenth employee claims that they are aware of the safety principles in their company, but no one has explained them to them.

Up to 13% of employees do not know their company's security policy, 7% claim that their company has no security policy. 6% of respondents believe that security measures are not necessary because the company has not yet experienced an attack, and one in ten believes that cybersecurity policies have no impact on their work.

Do employees know what to do with suspicious email?

Every twelfth respondent in the Czech Republic and Hungary is not sure whether they would recognize a threat or do not know what to do when they notice a suspicious email, event or program. In Poland, not even every tenth employee has this knowledge.

In the Czech Republic, 72% of employees would report a suspicious event to the appropriate person in the IT department, while every fifth (20%) would ignore the situation or delete the suspicious email. Hungarians are a little better off, but only 58% of employees report the incident to Poland, and a third would ignore the situation.

58% of employees do not follow cyber security measures in their company. A fifth even consider them an obstacle to their work. Almost a third of the employees ignore the suspicious event.

Room for great improvement

The human factor is still a key and problematic part of measures to ensure IT security. The survey shows that companies still have room for improvement in the field of employee training.

In order to be able to follow the security principles, they must first of all know why they are such an important part of protecting the company against a cyber attack. In addition to implementing a cybersecurity policy, it is essential to show employees how their daily behavior affects the company's security.

Slovakia and IT security

Although the survey is not based on data from the Slovak Republic, it is naive to believe that they would be diametrically better than data from the Czech Republic, Hungary or Poland.

According to the National Cyber ​​Security Center SK-CERT, up to 60% of Slovaks between the ages of 15 and 34 recognize the importance of cyber security. Slovaks list among the main security violations: theft of money from an account, misuse of login data, leakage or publication of sensitive photos or personal data, hacking of a profile and compromise on a social network, and leakage of sensitive communication.

Instructions on how to change it - internal educational workshops

ANASOFT is a software company, one of whose pillars is the cyber protection of companies. That's why it decided to devote a relatively large part to the education of its own employees precisely on the topic of cyber attacks.

Peter Roth, CIO of ANASOFT: "We have chosen the form of short, regular internal trainings, which speak to our ANASOFT employees in a humorous and light-hearted way every month. Through online broadcasting, we always talk about one of the topics that affect our company and also private IT security.

These are topics such as social engineering, phishing, ransomware, safe use of the Internet and security of mobile devices. We called this series of workshops "I take it personally" because the attacks that lie in wait for us in the company can equally affect our privacy, our personal sensitive data or even our bank account.

Each meeting is enriched with a real, sometimes sadly ending story from real life, presented by the main guest of the broadcast. After this example, we will talk about how to prevent a similar case, and when the situation does occur, how to minimize potential damage."

Fun internal campaigns

Together with internal mini-trainings, visual mini-campaigns that remind people of everyday dangers are part of the strategy to combat cyberattacks. One of them was, for example, the production of T-shirts printed with safety sayings.

"Thanks to these activities, IT security has become a favorite and not an unwanted topic at ANASOFT. The activities carried out are fun, easy to understand and sometimes bring a gift for the employee. In addition to educating all employees, ANASOFT also has a Security Division that takes care of the security of large and demanding clients. We have developed our own DECEUS product, which offers cyber deception technology.

If we talk about cyber attacks, the question is not if they will happen, but when. I am therefore very happy that our clients can feel safe thanks to the fact that awareness of protection against cyberattacks is a very often and appropriately inflected topic at ANASOFT," adds Peter Roth.