We’re launching a new series on the Association’s website — “Cybersecurity in Numbers.” Each installment breaks down a single statistic that helps clarify what’s actually driving cyber threats, without exaggeration or vague warnings. The first installment covers the most underestimated risk factor of all: the human element.
Where the number comes from
68% of breaches involve the human element — this figure comes from Verizon’s Data Breach Investigations Report (DBIR) 2024, one of the largest and most widely cited annual studies of security incidents in the world, based on an analysis of thousands of confirmed breaches globally. The 2026 edition of the report shows a slightly lower figure — 62% — but the human element has remained the leading contributing factor across nearly every recent edition of the report.
What “human element” actually covers
This doesn’t mean 68% of incidents are the result of malicious intent or blatant negligence. The category covers a much broader, more everyday set of situations:
Clicking a link in a phishing email
Using a weak or reused password
Accidentally sending a document to the wrong recipient
A former employee’s account that wasn’t deactivated in time
A misconfigured system or service (incorrect access rights, an exposed database)
Successful social engineering — where an employee was convinced to take an action through trust rather than a technical breach
Why this matters for businesses
Companies often invest primarily in technical defenses — firewalls, antivirus software, monitoring systems — and treat people as an afterthought. But if nearly seven out of ten incidents start with a human action, even the most expensive technology won’t protect a company from one careless click.
This isn’t an argument against technical protection — it remains essential. But without parallel investment in people, a company is only covering part of its real risk.
What actually reduces this percentage
Regular, not one-off, employee training — short quarterly case reviews are more effective than a single long course once a year
Clear processes for common high-risk actions — for example, requiring second-channel confirmation before changing payment details
Timely deactivation of access for employees who have left the company
Test phishing campaigns that reveal a team’s actual readiness rather than an assumed one
What’s next
Upcoming installments will break down other key figures — from the average cost of an incident for small businesses to attack-type statistics specific to Central Asia. Subscribe to our newsletter or follow our social channels to catch future editions.