Digital dangers from within: employee behaviour and cyber risk
Aug 2025
Recent research by cybersecurity firm CyberArk has shed light on growing internal vulnerabilities within organisations, driven by employee behaviour, which could jeopardise organisational security. Nearly half (49%) of employees admitted to knowingly posting content on social media that could result in reputational or financial damage to their employer. Compounding this risk, 73% of workers disclosed having experienced a cyberattack. The research highlights the growing risks businesses face from inside their own organisations, especially as workplace and personal digital boundaries continue to blur.
The research also found that 80% of UK workers access corporate applications from personal devices lacking proper security controls, while half reuse the same login credentials across multiple platforms. These practices dramatically increase vulnerability to cyber threats. David Higgins, Senior director of field technology at CyberArk, stressed that monitoring every employee’s digital footprint is unrealistic and unsustainable. Instead, he advocates for a strategic focus on employee education, enforceable policy standards, and fostering a culture of shared responsibility for cybersecurity. In today’s threat landscape, building digital resilience starts with people, not just technology.