Research from STX Next has found that 59% of chief technology officers (CTOs) believe human error to be the biggest cyber security threat facing their organization. Human error, which can range from downloading a malware-infected attachment to failing to use a strong password, was found to be more threatening than the potential of both ransomware (48%) and phishing (40%) attacks.
In response, CTOs are deploying a range of tactics in order to protect their teams and wider organization and are taking advantage of the many solutions on the market. 94% of companies said that they have now deployed multi-factor authentication (MFA), 91% are using identity access management technology (IAM), 58% are using security information and event management (SIEM) technology, and 86% are using single sign-on (SSO) solutions.
These findings were taken from STX Next’s 2023 Global CTO Survey, which surveyed 500 global CTOs about the biggest challenges facing their organization.
Other key findings from the research include:
- A quarter (24%) of CTOs said that security was their biggest challenge across the organization.
- Despite the growing threat of attack, just less than half (49%) of companies surveyed said that they currently have a cyber insurance policy in place, while 59% of businesses have implemented a ransomware protection solution.
- In-house security teams are still in the minority: just 36% of companies have a dedicated team or department providing security services, whereas 53% of companies are using the services of external specialised companies for security.
While the threat of ransomware remains high, in many cases, cybercriminals aren’t in fact relying on incredibly advanced and sophisticated methods of attack, but on human error and social engineering techniques to gain access to an organization’s systems. And this method of attack is still the most popular and successful. In response, it’s crucial that management teams focus not only on educating staff to recognise and respond to new threats but also on periodically testing their resilience through simulated attacks or phishing and ransomware tests.
Krzysztof Olejniczak, CISO at STX Next






