Key Takeaways
- 80% of organisations identify people-related factors as a major cyberattack risk.
- IT and security team workload was cited by 24% of respondents.
- Another 24% pointed to insufficient cybersecurity expertise.
- 24% identified low employee security awareness as a major risk.
- In India, 28% of organisations highlighted low employee security awareness.
Cybersecurity defences are becoming more advanced, but organisations continue to face a fundamental vulnerability: people.
A new study by Kaspersky’s internal Market Research Center finds that 80% of organisations consider people-related factors to be the biggest driver of potentially successful cyberattacks. Human behaviour is emerging as a bigger concern than weaknesses in technical controls, with employee awareness, staff expertise and workload all influencing an organisation’s ability to withstand cyber threats.
The study identifies three human-related risks that received almost equal shares of responses: high workloads among IT and security teams, insufficient expertise among cybersecurity professionals, and low security awareness among employees.
High workload was identified as a major risk by 24% of organisations. The concern is even higher among medium-sized businesses, at 27%, and large enterprises, at 26%. As IT and security teams handle growing numbers of systems, alerts and processes, stretched resources can leave less time for proactive threat detection and response. This increases the possibility of missed alerts, configuration errors and delayed action.
Another 24% of respondents pointed to a lack of expertise and experience among IT and security professionals. The problem can make it harder for organisations to identify sophisticated attacks, assess their impact and respond quickly. The concern was particularly high in Mexico, Colombia, Turkey and Germany.
Employee awareness is another significant weak point. Twenty-four per cent of organisations identified low security awareness among staff as a factor that could increase the likelihood of a successful attack.
The concern is particularly visible across parts of the Asia-Pacific region. In India, 28% of organisations identified low employee security awareness as a major cyber risk. The figure was higher in Vietnam at 35%, Thailand at 33% and China at 30%.
The findings highlight why cybersecurity can no longer be treated purely as a technology issue. Attackers increasingly use social engineering to persuade employees to disclose information, click malicious links or take other risky actions. At the same time, overloaded security teams can miss alerts or fail to respond quickly enough to emerging threats.
“Advanced security technologies” alone may therefore not be sufficient, according to Kaspersky. The company’s incident analysis indicates that high-impact attacks frequently involve a human weakness, whether it is a successful social-engineering attempt or an overlooked alert during periods of heavy workload.
For businesses, the implication is clear: strengthening the human layer of cybersecurity needs to become part of the overall security strategy. This includes regular employee awareness programmes, continuous training for IT and security professionals, and practical exercises that allow teams to test their response to simulated attacks.
Organisations facing cybersecurity talent shortages can also consider managed security services and incident-response capabilities to supplement their internal teams.
As cyberattacks become more sophisticated, the weakest link may not always be the firewall, endpoint or network. It could simply be an employee who is overloaded, insufficiently trained or unaware of the risk.

