ITSecurityGuru

When Everyday Habits Become an Invisible Security Risk


By James Mackay, CEO, MetaCompliance

When security teams think about their organisation’s attack surface, they’re usually focused on technology. Where could an attacker get in? What’s exposed? What hasn’t been updated or configured correctly? An attack surface refers to all the possible ways a cyber attacker can gain access to an organisation, including unpatched security software, misconfigured cloud storage, open system connections, and traditional phishing emails containing fraudulent links.

However, organisations also have an invisible attack surface sitting behind the everyday behaviours of their employees. Our latest research found that more than two thirds of CISOs see their employees as their organisation’s biggest cyber security risk. Not because employees are careless or malicious, but because routine workplace habits can unintentionally create opportunities for attackers.

Unlike a misconfigured server or unpatched system, these behaviours don’t always look like vulnerabilities, they’re simply part of the everyday ways people work.

Small Details Can Give Attackers a Much Bigger Picture

The clearest example is the out-of-office (OOO) reply. An automated message that goes out to anyone who emails a colleague on leave, no matter who they are, can give an attacker the information they need to build a bigger picture of an organisation and its employees before making a move.

Standard OOO replies confirm that the email address an attacker is contacting is correct and usually tells them how long the person won’t be monitoring that inbox for. It potentially names another employee to get in contact with, along with their role and their direct email address. Sometimes it even explains where the person has gone. In just four or five lines, an attacker receives a verified target, a defined window in which that person can’t be easily reached to check anything, and a partial map of the organisational chart.

OOO replies are only one example. Other routine workplace practices can reveal similarly valuable information. Email signatures or automated messages that supply names, titles and direct contact numbers can make an impersonation attempt incredibly convincing. Calendars shared to show full meeting details reveal who is meeting who, and often what about. In isolation, these actions can seem harmless but combined, they can provide a surprisingly detailed picture of an organisation.

Access is Only as Secure as the Habits Around It

Shared drives are another example of how everyday working practices can quietly expand an organisation’s attack surface. While they’re designed to make collaboration easier, they often accumulate broad access permissions over time. Employees move roles, projects end, teams change, yet access rights frequently remain in place. Old project folders, expired contracts, meeting notes and spreadsheets can also all sit there long after anyone needs them.

The content in these drives tends to be exactly what an attacker is hoping to find – customer records, supplier contracts, financial reports, HR documents, organisational charts. Leaving a folder shared with the entire department may not have been viewed as a security decision at the time, but it becomes a big one the moment someone’s password is compromised. What starts as access to a single user can quickly provide visibility into far more of the business than intended.

When an Employee Leaves, their Access Shouldn’t Stay Behind

Employee offboarding has a part to play here too. Over several years, an employee builds access to dozens of systems: shared folders, cloud platforms, and third-party applications.

When people leave, these accounts need to be disabled, and permissions removed. Otherwise, access that was once legitimate can become an overlooked route into the organisation.

Credentials that have been stolen or compromised are among the most common ways attackers get into organisations, and a dormant account belonging to an employee who has left may take longer to be noticed.

The Wider Human Attack Surface

Security awareness training often concentrates on key security topics like phishing and strong password practices. These are essential foundations of any cyber security programme, helping employees recognise common threats and protect access to systems and data. However, the human attack surface extends beyond fraudulent emails and compromised credentials to include the everyday habits and decisions that can unintentionally expose information, create unnecessary access or provide attackers with valuable context about how an organisation operates.

If employees don’t understand how an OOO reply reads to a threat actor, or the risk created by a forgotten third-party login belonging to an ex-employee, they may continue behaviours that increase the organisation’s exposure to risk. This is why security awareness needs to move beyond teaching people to identify individual threats. Employees need to understand how their everyday actions can affect the organisation’s wider security posture.

Upgrading security awareness starts with building a culture where people understand why their behaviour matters, and how they can apply that judgement to situations that aren’t explicitly covered by a policy or training module.

Building that culture takes sustained backing, and this is where many organisations struggle. Our research found that nearly four in five CISOs say leadership support for security education initiatives fades over time. The initial push happens, the training is rolled out, and attention moves elsewhere.

A culture of security awareness has to start at the top. If senior decision-makers don’t fully understand the cyber risk posed by employees, it becomes very hard to secure the sustained attention these habits require. None of the issues here are failures of technology – they’re habits that can be changed with the right behaviours built into the culture of the business.



Source link