Most breaches do not start with a genius hacker breaking through a firewall. They start with a person: a rushed click, a reused password, a file sent to the wrong address. Verizon’s 2025 Data Breach Investigations Report found the human element in 60% of confirmed breaches, and Stanford research puts employee mistakes behind as many as 88% of incidents. The numbers below show exactly how large a role people play, why it happens, what it costs, and the controls that actually move the needle.

Ask three research teams how often human error is behind a breach and you will get three different numbers, all of them large. The gap comes from how each group defines “human error,” not from any disagreement about the core finding. When people are part of the security system, people are part of the risk.
The most conservative, most rigorously measured figure comes from Verizon’s 2025 Data Breach Investigations Report, which analyzed tens of thousands of real incidents. It found a human element (a click, a socially engineered phone call, a misdelivered file, or misuse) in 60% of confirmed breaches. Stanford University research conducted with security firm Tessian, focused specifically on the psychology of mistakes, attributes 88% of breaches to employee error. The World Economic Forum has cited estimates as high as 95% for cybersecurity issues traceable to human factors.
How Different Studies Measure Human Error’s Role in Breaches
Different definitions produce different figures, but every credible source places human action at the center of breach risk.
The practical takeaway for a business owner is not the exact percentage. It is the direction. Whether the true number is 60% or 88%, the majority of breaches trace back to something a person did, and almost all of those actions were preventable. That is good news, because human behavior is something you can actually influence through training, better tools, and smarter system design.
Source: Verizon Data Breach Investigations Report 2025 | World Economic Forum Global Risks Report
See How CNiC Reduces Human-Error Risk for Businesses
“Human error” is a broad label. In breach data it covers a handful of distinct, recurring mistakes, most of them mundane. Understanding the categories helps you see where your own exposure sits, because the fix for a phishing click is different from the fix for a misconfigured cloud bucket.
Errors of judgment (falling for a scam) and errors of action (fat-fingering a setting or a recipient) both show up constantly in the data. Here is how the most common categories break down.
| Type of human error | What it looks like | Everyday example |
|---|---|---|
| Falling for phishing / social engineering | Clicking a malicious link, opening a weaponized attachment, or approving a fraudulent request | Approving a wire transfer from an email that looked like the CEO’s |
| Weak or reused passwords | Using the same password everywhere, so one leak unlocks many accounts | The same password on email, banking, and a breached shopping site |
| Misconfiguration | Leaving a cloud storage bucket, database, or permission set open by mistake | A file-sharing folder set to “anyone with the link” and indexed by Google |
| Misdelivery | Sending sensitive information to the wrong person | Autocomplete putting a client list in the wrong “David’s” inbox |
| Lost or stolen devices | An unencrypted laptop or phone with business data goes missing | A laptop left in a rideshare with saved passwords and no disk encryption |
| Skipping updates and patches | Ignoring or delaying security updates that close known holes | Clicking “remind me later” on a critical update for months |

Notice how few of these involve anything a normal employee would recognize as “hacking.” The Ponemon Institute’s finding that negligence drives 55% of insider incidents captures the reality: most damage comes from ordinary people doing ordinary work a little too fast. That is precisely why controls that assume mistakes will happen tend to outperform controls that assume people will be perfect.
Source: Verizon DBIR 2025 | Ponemon Institute Cost of Insider Risks 2023
Get a Security Policy Built Around How People Actually Work
If human error has a headline act, it is phishing. Social engineering skips the technical defenses entirely and targets the person, and it works because it exploits how the brain handles a busy day. The most sobering statistic in the whole field is not a dollar figure. It is a clock.
Once a user opens a phishing email and decides to act, the window to compromise closes fast. Verizon’s data shows a click in a median of 21 seconds, with credential entry following shortly after. There is no realistic training program that makes a human faster than a well-crafted lure every single time. That is the core argument for defenses that catch the mistake after it happens, not just before.
How Fast a Phishing Attack Works (median times, Verizon DBIR)
From open to stolen credentials in about a minute. Speed is why layered controls matter more than perfect vigilance.
Generative AI has tilted the field further toward the attacker. The grammar mistakes and awkward phrasing that once gave phishing away are gone. IBM found that AI has cut the time to draft a convincing lure from roughly 16 hours to 5 minutes, which means more attacks, better targeting, and fewer tells for your team to spot. The old advice to “look for spelling errors” is no longer a reliable defense.
Source: Verizon DBIR 2025 | IBM Cost of a Data Breach Report 2025
The pattern behind these numbers, and the volume of attacks driving them, is the subject of our companion report on phishing attack volume, cost, and AI trends.
Human error is not a soft, hard-to-measure risk. It has an invoice. Because the majority of breaches begin with a human action, the headline breach-cost figures are, in effect, the price tag on human error at scale.
The initial access vector drives much of the cost. IBM found phishing was both the most common way in (16% of breaches) and one of the most expensive, at an average of $4.8 million, while breaches that started with stolen credentials averaged $4.67 million. Business email compromise, a pure social-engineering play with no malware required, cost U.S. victims $2.77 billion in 2024 alone according to the FBI. Total reported cybercrime losses that year reached $16.6 billion, up 33% from the prior year.
Average Data Breach Cost by Scenario (IBM 2025)
The two most common human-error entry points, phishing and stolen credentials, are also among the costliest.
Combining two Tier 1 sources shows the stakes plainly. If the human element is present in 60% of breaches (Verizon DBIR 2025) and the average U.S. breach costs $10.22 million (IBM 2025), then for a typical U.S. organization roughly $6.1 million of expected breach cost per incident traces to a preventable human action (0.60 x $10.22M). Formula: human-element share x average U.S. breach cost. This frames security awareness training and multi-factor authentication not as IT line items, but as direct protection for the largest slice of breach risk. Calculation and interpretation original to CNiC Solutions.
Source: IBM Cost of a Data Breach Report 2025 | FBI Internet Crime Report 2024
Make Sure One Mistake Cannot Become a Catastrophe
Not every human-error breach comes from an outsider tricking your team. A large share originates inside the building, and the overwhelming majority of those are honest mistakes rather than sabotage. The Ponemon Institute tracks this category closely, and the data reframes how businesses should think about “insider threats.”
The word “insider” conjures a rogue employee stealing data on the way out the door. That happens, but it is the minority. Ponemon’s research found that 55% of insider incidents are the result of plain negligence: a missed setting, an ignored policy, a careless share. Those negligent incidents alone cost organizations an average of $7.2 million a year. The lesson is not to distrust your team; it is to build guardrails that keep a routine slip from turning into a reportable breach.
| Insider risk metric | Figure | Source |
|---|---|---|
| Share of insider incidents caused by negligence | 55% | Ponemon Institute 2023 |
| Average annual cost of insider risk per organization | $16.2M | Ponemon Institute 2023 |
| Annual cost of negligence-driven incidents | $7.2M | Ponemon Institute 2023 |
| Employees who admit a possible security mistake at work | ~50% | Stanford / Tessian |
| Business email compromise complaints filed with the FBI (2024) | 21,442 | FBI IC3 2024 |
Source: Ponemon Institute Cost of Insider Risks 2023 | FBI Internet Crime Report 2024
Catch Risky Activity Before It Becomes a Breach
Here is the encouraging part. Because human-error breaches follow predictable patterns, they respond to predictable defenses. The data shows a clear hierarchy of what works, and the highest-impact controls are neither expensive nor complicated.
Multi-factor authentication is the single highest-return control against human error, because it neutralizes the most common outcome of a mistake: a stolen password. Even if an employee hands over credentials to a convincing phishing page, MFA stops the attacker from using them. Microsoft’s research puts the block rate above 99.9% for automated attacks, and it is free on nearly every major platform.
Security awareness training is the second pillar, and the payoff is measurable. The SANS Institute found that untrained employees click phishing simulations at 30 to 40%, while well-trained teams drop below 5%. Just as important as the click rate is the report rate: a team that flags a suspicious message gives your defenders the early warning that turns a potential breach into a non-event. This is the awareness-training case in a nutshell, and it is where a managed provider earns its keep.
Phishing Click Rate: Untrained vs. Trained Employees
Training does not have to be perfect to pay off. Cutting clicks from a third of staff to one in twenty transforms your risk.
The rest of the defense-in-depth stack assumes mistakes will still slip through: password managers to kill reuse, least-privilege access so one compromised account cannot reach everything, tested backups so ransomware cannot hold you hostage, and network monitoring to catch the mistake that gets past the first two layers. No single control is perfect. Together, they make it so that no single human error can bring the business down. For a wider view of the threat landscape these controls defend against, see our full breakdown of current cybersecurity statistics.
Source: Microsoft Security Research | SANS Institute Security Awareness Research
Build a Managed Defense Around Your Team, Not Against It
Every headline statistic from this report in one place, with the primary source and year for each. Journalists and researchers are welcome to cite these figures with attribution to the original source listed.
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Breaches involving the human element | 60% | Verizon DBIR | 2025 |
| Data breaches caused by employee mistakes | 88% | Stanford / Tessian | 2022 |
| Cybersecurity issues traceable to human factors (upper estimate) | 95% | World Economic Forum | 2022 |
| Median time to click a phishing link | 21 sec | Verizon DBIR | 2025 |
| Full open-to-compromise window for phishing | ~60 sec | Verizon DBIR | 2024 |
| Breaches starting with phishing (top initial vector) | 16% | IBM Cost of a Data Breach | 2025 |
| Average cost of a phishing-initiated breach | $4.8M | IBM Cost of a Data Breach | 2025 |
| Average cost of a stolen-credential breach | $4.67M | IBM Cost of a Data Breach | 2025 |
| Time for AI to write a convincing phishing email | 5 min | IBM Cost of a Data Breach | 2025 |
| Global average cost of a data breach | $4.44M | IBM Cost of a Data Breach | 2025 |
| U.S. average cost of a data breach | $10.22M | IBM Cost of a Data Breach | 2025 |
| Business email compromise losses | $2.77B | FBI IC3 | 2024 |
| Total reported cybercrime losses | $16.6B | FBI IC3 | 2024 |
| Insider incidents caused by negligence | 55% | Ponemon Institute | 2023 |
| Average annual cost of insider risk | $16.2M | Ponemon Institute | 2023 |
| Employees admitting a possible security mistake | ~50% | Stanford / Tessian | 2022 |
| Automated account attacks blocked by MFA | 99.9% | Microsoft Security Research | 2024 |
| Phishing click rate, trained vs. untrained employees | <5% vs 30-40% | SANS Institute | 2024 |
All statistics in this report are drawn from Tier 1 primary sources only. No blog-to-blog citations are used, and no figures are invented or estimated by CNiC Solutions except the clearly labeled analysis box, which shows its formula and inputs. Sources include: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report 2025; FBI Internet Crime Complaint Center (IC3) 2024 Annual Report; Ponemon Institute Cost of Insider Risks Global Report 2023; Stanford University research with Tessian, The Psychology of Human Error; World Economic Forum Global Risks Report; Microsoft Security Research; and SANS Institute security awareness research. Phishing timing figures combine the Verizon DBIR’s most recent published medians (21 seconds to click, confirmed in the 2025 report; the roughly 60-second full-compromise window is drawn from the 2024 DBIR). Figures reflect the most recently published data available as of August 2026. Readers should consult the primary sources directly for full methodology and definitions.
IaaS, PaaS, and SaaS are the three ways businesses buy computing from the cloud, and the…
When your internet drops, slows to a crawl, or refuses to load a single page, rebooting…
To restart the graphics driver in Windows, press Windows + Ctrl + Shift + B. The…
Phishing is now the single most common way attackers break into a business, and it works…