Skip to main content

CNiC Solutions

Distracted office worker at a laptop late in the day, illustrating human error in cybersecurity

Most breaches do not start with a genius hacker breaking through a firewall. They start with a person: a rushed click, a reused password, a file sent to the wrong address. Verizon’s 2025 Data Breach Investigations Report found the human element in 60% of confirmed breaches, and Stanford research puts employee mistakes behind as many as 88% of incidents. The numbers below show exactly how large a role people play, why it happens, what it costs, and the controls that actually move the needle.

Key Takeaways

  • The human element was involved in 60% of confirmed breaches in 2025, according to the Verizon DBIR, and broader studies estimate up to 88% (Stanford) or even 95% (World Economic Forum).
  • The median time to click a phishing link is just 21 seconds after opening the email, and credentials are often entered within a minute.
  • Phishing became the top initial attack vector in 2025 at 16% of breaches, averaging $4.8 million per incident (IBM).
  • The average breach costs $4.44 million globally and $10.22 million in the United States (IBM 2025).
  • 55% of insider incidents come from ordinary employee negligence, not malicious intent (Ponemon Institute).
  • Multi-factor authentication blocks over 99.9% of automated account attacks, and training cuts phishing click rates from 30 to 40% down to under 5%.
  • Human error is a systems problem, not a people problem: blame-free reporting and layered controls beat finger-pointing every time.

What’s in This Report

 

 

Infographic of four key human error cybersecurity stats: 60% human element, 88% employee mistake, 21 seconds to click, $4.44M breach cost
The four headline figures on human error in cybersecurity (Verizon DBIR, Stanford/Tessian, IBM).

 

 

The Big Picture: How Much of a Role Does Human Error Really Play?

Ask three research teams how often human error is behind a breach and you will get three different numbers, all of them large. The gap comes from how each group defines “human error,” not from any disagreement about the core finding. When people are part of the security system, people are part of the risk.

The most conservative, most rigorously measured figure comes from Verizon’s 2025 Data Breach Investigations Report, which analyzed tens of thousands of real incidents. It found a human element (a click, a socially engineered phone call, a misdelivered file, or misuse) in 60% of confirmed breaches. Stanford University research conducted with security firm Tessian, focused specifically on the psychology of mistakes, attributes 88% of breaches to employee error. The World Economic Forum has cited estimates as high as 95% for cybersecurity issues traceable to human factors.

60%
of confirmed breaches involved a human element in 2025 (Verizon DBIR 2025)
88%
of data breaches are caused by an employee mistake (Stanford / Tessian, Psychology of Human Error)
95%
upper-bound estimate of cybersecurity issues traceable to human factors (World Economic Forum)

How Different Studies Measure Human Error’s Role in Breaches

Verizon DBIR 2025 (human element)
60%

Stanford / Tessian (employee mistake)
88%

World Economic Forum (human factors)
95%

Different definitions produce different figures, but every credible source places human action at the center of breach risk.

The practical takeaway for a business owner is not the exact percentage. It is the direction. Whether the true number is 60% or 88%, the majority of breaches trace back to something a person did, and almost all of those actions were preventable. That is good news, because human behavior is something you can actually influence through training, better tools, and smarter system design.

Myth: “Human error means one careless employee is to blame.” The Stanford research is blunt on this point: mistakes happen because people are distracted, tired, and under pressure, not because they are reckless. Treating every incident as an individual failure drives people to hide mistakes instead of reporting them, which makes breaches worse. Human error is a systems problem to be engineered around, not a person to be punished.

Source: Verizon Data Breach Investigations Report 2025 | World Economic Forum Global Risks Report

See How CNiC Reduces Human-Error Risk for Businesses

What Counts as Human Error in Cybersecurity

“Human error” is a broad label. In breach data it covers a handful of distinct, recurring mistakes, most of them mundane. Understanding the categories helps you see where your own exposure sits, because the fix for a phishing click is different from the fix for a misconfigured cloud bucket.

~50%
of employees are “very” or “pretty” certain they have made a security mistake at work (Stanford / Tessian)
55%
of insider incidents are caused by negligence, not malice (Ponemon Institute, Cost of Insider Risks 2023)
88%
of attacks against web applications relied on stolen credentials, often harvested through human mistakes (Verizon DBIR 2025)

Errors of judgment (falling for a scam) and errors of action (fat-fingering a setting or a recipient) both show up constantly in the data. Here is how the most common categories break down.

Type of human error What it looks like Everyday example
Falling for phishing / social engineering Clicking a malicious link, opening a weaponized attachment, or approving a fraudulent request Approving a wire transfer from an email that looked like the CEO’s
Weak or reused passwords Using the same password everywhere, so one leak unlocks many accounts The same password on email, banking, and a breached shopping site
Misconfiguration Leaving a cloud storage bucket, database, or permission set open by mistake A file-sharing folder set to “anyone with the link” and indexed by Google
Misdelivery Sending sensitive information to the wrong person Autocomplete putting a client list in the wrong “David’s” inbox
Lost or stolen devices An unencrypted laptop or phone with business data goes missing A laptop left in a rideshare with saved passwords and no disk encryption
Skipping updates and patches Ignoring or delaying security updates that close known holes Clicking “remind me later” on a critical update for months

 

 

Infographic showing 55% of insider incidents come from negligence and the six most common human-error types
Most insider incidents are negligence, not malice: 55% (Ponemon Institute 2023).

 

 

Notice how few of these involve anything a normal employee would recognize as “hacking.” The Ponemon Institute’s finding that negligence drives 55% of insider incidents captures the reality: most damage comes from ordinary people doing ordinary work a little too fast. That is precisely why controls that assume mistakes will happen tend to outperform controls that assume people will be perfect.

Source: Verizon DBIR 2025 | Ponemon Institute Cost of Insider Risks 2023

Get a Security Policy Built Around How People Actually Work

Phishing and Social Engineering: Why People Click

If human error has a headline act, it is phishing. Social engineering skips the technical defenses entirely and targets the person, and it works because it exploits how the brain handles a busy day. The most sobering statistic in the whole field is not a dollar figure. It is a clock.

21 sec
median time for a user to click a phishing link after opening the email (Verizon DBIR)
16%
of breaches began with phishing, now the top initial attack vector, at an average cost of $4.8M (IBM 2025)
5 min
time for generative AI to write a convincing phishing email, down from about 16 hours (IBM 2025)

Once a user opens a phishing email and decides to act, the window to compromise closes fast. Verizon’s data shows a click in a median of 21 seconds, with credential entry following shortly after. There is no realistic training program that makes a human faster than a well-crafted lure every single time. That is the core argument for defenses that catch the mistake after it happens, not just before.

How Fast a Phishing Attack Works (median times, Verizon DBIR)

Time to click the link
21 sec

Time to then enter credentials
28 sec

Full open-to-compromise window
~60 sec

From open to stolen credentials in about a minute. Speed is why layered controls matter more than perfect vigilance.

Generative AI has tilted the field further toward the attacker. The grammar mistakes and awkward phrasing that once gave phishing away are gone. IBM found that AI has cut the time to draft a convincing lure from roughly 16 hours to 5 minutes, which means more attacks, better targeting, and fewer tells for your team to spot. The old advice to “look for spelling errors” is no longer a reliable defense.

Source: Verizon DBIR 2025 | IBM Cost of a Data Breach Report 2025

The pattern behind these numbers, and the volume of attacks driving them, is the subject of our companion report on phishing attack volume, cost, and AI trends.

 

CNiC Solutions — Cybersecurity

 

What a Human-Caused Breach Actually Costs

Human error is not a soft, hard-to-measure risk. It has an invoice. Because the majority of breaches begin with a human action, the headline breach-cost figures are, in effect, the price tag on human error at scale.

$4.44M
global average cost of a data breach in 2025 (IBM Cost of a Data Breach Report 2025)
$10.22M
average cost of a data breach for U.S. organizations in 2025 (IBM 2025)
$2.77B
reported losses from business email compromise in 2024, across 21,442 complaints (FBI IC3 2024)

The initial access vector drives much of the cost. IBM found phishing was both the most common way in (16% of breaches) and one of the most expensive, at an average of $4.8 million, while breaches that started with stolen credentials averaged $4.67 million. Business email compromise, a pure social-engineering play with no malware required, cost U.S. victims $2.77 billion in 2024 alone according to the FBI. Total reported cybercrime losses that year reached $16.6 billion, up 33% from the prior year.

Average Data Breach Cost by Scenario (IBM 2025)

U.S. average breach
$10.22M

Phishing-initiated breach
$4.8M

Stolen-credential breach
$4.67M

Global average breach
$4.44M

The two most common human-error entry points, phishing and stolen credentials, are also among the costliest.

Source: IBM Cost of a Data Breach Report 2025 | FBI Internet Crime Report 2024

Make Sure One Mistake Cannot Become a Catastrophe

Negligent Insiders: The Threat From the Inside

Not every human-error breach comes from an outsider tricking your team. A large share originates inside the building, and the overwhelming majority of those are honest mistakes rather than sabotage. The Ponemon Institute tracks this category closely, and the data reframes how businesses should think about “insider threats.”

$16.2M
average annual cost of insider risk per organization (Ponemon Institute, Cost of Insider Risks 2023)
$7.2M
annual cost of insider incidents driven specifically by employee negligence (Ponemon 2023)
$16.6B
total reported cybercrime losses in 2024, up 33% year over year (FBI IC3 2024)

The word “insider” conjures a rogue employee stealing data on the way out the door. That happens, but it is the minority. Ponemon’s research found that 55% of insider incidents are the result of plain negligence: a missed setting, an ignored policy, a careless share. Those negligent incidents alone cost organizations an average of $7.2 million a year. The lesson is not to distrust your team; it is to build guardrails that keep a routine slip from turning into a reportable breach.

Insider risk metric Figure Source
Share of insider incidents caused by negligence 55% Ponemon Institute 2023
Average annual cost of insider risk per organization $16.2M Ponemon Institute 2023
Annual cost of negligence-driven incidents $7.2M Ponemon Institute 2023
Employees who admit a possible security mistake at work ~50% Stanford / Tessian
Business email compromise complaints filed with the FBI (2024) 21,442 FBI IC3 2024
Watch for: the blame trap. When employees fear punishment, they hide mistakes, and hidden mistakes are the ones that fester into major breaches. The Stanford research found that roughly half of employees are already fairly sure they have slipped up, yet many never report it. A blame-free reporting culture is not a soft nicety. It is a hard control that shortens the time to contain an incident.

Source: Ponemon Institute Cost of Insider Risks 2023 | FBI Internet Crime Report 2024

Catch Risky Activity Before It Becomes a Breach

What Actually Reduces Human Error

Here is the encouraging part. Because human-error breaches follow predictable patterns, they respond to predictable defenses. The data shows a clear hierarchy of what works, and the highest-impact controls are neither expensive nor complicated.

99.9%
of automated account attacks blocked by multi-factor authentication (Microsoft Security Research)
<5%
phishing click rate for well-trained employees, versus 30 to 40% for untrained staff (SANS Institute)
~20%
benchmark rate at which trained users report a suspicious email, the metric that matters most (Verizon DBIR)

Multi-factor authentication is the single highest-return control against human error, because it neutralizes the most common outcome of a mistake: a stolen password. Even if an employee hands over credentials to a convincing phishing page, MFA stops the attacker from using them. Microsoft’s research puts the block rate above 99.9% for automated attacks, and it is free on nearly every major platform.

Security awareness training is the second pillar, and the payoff is measurable. The SANS Institute found that untrained employees click phishing simulations at 30 to 40%, while well-trained teams drop below 5%. Just as important as the click rate is the report rate: a team that flags a suspicious message gives your defenders the early warning that turns a potential breach into a non-event. This is the awareness-training case in a nutshell, and it is where a managed provider earns its keep.

Phishing Click Rate: Untrained vs. Trained Employees

Untrained employees
30-40%

Well-trained employees
under 5%

Training does not have to be perfect to pay off. Cutting clicks from a third of staff to one in twenty transforms your risk.

The rest of the defense-in-depth stack assumes mistakes will still slip through: password managers to kill reuse, least-privilege access so one compromised account cannot reach everything, tested backups so ransomware cannot hold you hostage, and network monitoring to catch the mistake that gets past the first two layers. No single control is perfect. Together, they make it so that no single human error can bring the business down. For a wider view of the threat landscape these controls defend against, see our full breakdown of current cybersecurity statistics.

Source: Microsoft Security Research | SANS Institute Security Awareness Research

Build a Managed Defense Around Your Team, Not Against It

Human Error in Cybersecurity: The Numbers at a Glance

Every headline statistic from this report in one place, with the primary source and year for each. Journalists and researchers are welcome to cite these figures with attribution to the original source listed.

Statistic Figure Source Year
Breaches involving the human element 60% Verizon DBIR 2025
Data breaches caused by employee mistakes 88% Stanford / Tessian 2022
Cybersecurity issues traceable to human factors (upper estimate) 95% World Economic Forum 2022
Median time to click a phishing link 21 sec Verizon DBIR 2025
Full open-to-compromise window for phishing ~60 sec Verizon DBIR 2024
Breaches starting with phishing (top initial vector) 16% IBM Cost of a Data Breach 2025
Average cost of a phishing-initiated breach $4.8M IBM Cost of a Data Breach 2025
Average cost of a stolen-credential breach $4.67M IBM Cost of a Data Breach 2025
Time for AI to write a convincing phishing email 5 min IBM Cost of a Data Breach 2025
Global average cost of a data breach $4.44M IBM Cost of a Data Breach 2025
U.S. average cost of a data breach $10.22M IBM Cost of a Data Breach 2025
Business email compromise losses $2.77B FBI IC3 2024
Total reported cybercrime losses $16.6B FBI IC3 2024
Insider incidents caused by negligence 55% Ponemon Institute 2023
Average annual cost of insider risk $16.2M Ponemon Institute 2023
Employees admitting a possible security mistake ~50% Stanford / Tessian 2022
Automated account attacks blocked by MFA 99.9% Microsoft Security Research 2024
Phishing click rate, trained vs. untrained employees <5% vs 30-40% SANS Institute 2024

Frequently Asked Questions

What percentage of cybersecurity breaches are caused by human error?

Verizon’s 2025 Data Breach Investigations Report found that the human element was involved in 60% of confirmed breaches, whether through a mistaken click, social engineering, or misuse. Broader studies put the figure higher: Stanford research with Tessian attributes 88% of data breaches to employee mistakes, and the World Economic Forum has cited estimates as high as 95%. The range reflects different definitions, but every credible source agrees that human actions are the single largest factor in real-world breaches.

What is the most common type of human error in cybersecurity?

Falling for phishing and social engineering is the most common and costly human error. Employees click a link, open an attachment, or approve a fraudulent request. Other frequent errors include using weak or reused passwords, misconfiguring cloud settings, sending sensitive data to the wrong recipient (misdelivery), and losing devices. The Ponemon Institute found that 55% of insider incidents stem from simple negligence rather than malicious intent.

How quickly do employees fall for phishing emails?

Very quickly. Verizon’s DBIR found the median time for a user to click a phishing link is just 21 seconds after opening the email, and users who go on to enter credentials typically do so within about a minute of opening the message. That speed is why prevention and layered defenses matter more than expecting people to always catch every attack. Generative AI has made phishing emails faster to produce and harder to spot.

How much does a human-error breach cost a business?

IBM’s 2025 Cost of a Data Breach Report put the global average breach cost at $4.44 million and the U.S. average at $10.22 million. Phishing was the most common initial attack vector at 16% of breaches and an average cost of $4.8 million. Business email compromise alone caused $2.77 billion in reported losses to the FBI in 2024. Because most of these breaches begin with a human action, the cost of human error is measured in millions.

How can businesses reduce human error in cybersecurity?

The most effective steps are multi-factor authentication, which Microsoft found blocks over 99.9% of automated account attacks, and regular security awareness training, which cuts phishing click rates from 30 to 40% for untrained staff down to under 5% for well-trained teams. Password managers, least-privilege access, network monitoring, and a blame-free reporting culture round out the defenses. The goal is to design systems so a single mistake cannot cause a catastrophic breach.
Methodology and Sources

All statistics in this report are drawn from Tier 1 primary sources only. No blog-to-blog citations are used, and no figures are invented or estimated by CNiC Solutions except the clearly labeled analysis box, which shows its formula and inputs. Sources include: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report 2025; FBI Internet Crime Complaint Center (IC3) 2024 Annual Report; Ponemon Institute Cost of Insider Risks Global Report 2023; Stanford University research with Tessian, The Psychology of Human Error; World Economic Forum Global Risks Report; Microsoft Security Research; and SANS Institute security awareness research. Phishing timing figures combine the Verizon DBIR’s most recent published medians (21 seconds to click, confirmed in the 2025 report; the roughly 60-second full-compromise window is drawn from the 2024 DBIR). Figures reflect the most recently published data available as of August 2026. Readers should consult the primary sources directly for full methodology and definitions.

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog