Every third company (33 percent) in Germany generally trains all employees on IT security issues. Another 51 percent only train those in certain positions and areas.
In contrast, 15 percent of the companies do not conduct any IT security training at all. These are the results of a study commissioned by the digital association Bitkom, for which 1,002 companies with 10 or more employees across all sectors were representatively surveyed.
“IT security starts with the people. If you know how cyber attackers operate, you won't fall for their tricks so easily. And regularly trained employees can detect a successful attack earlier and thus limit the damage to the company”, explains Ralf Wintergerst, President at the digital association Bitkom.
Many companies that train all or at least part of their staff on IT security do not do so regularly. Only about one in four of these companies (24 percent) say they conduct training at least once a year. A further 37 percent offer corresponding training courses on a regular basis, but these take place less frequently than once a year. 70 percent of the companies also state that they train employees when necessary, 23 percent when they join the company.
Risk of IT threats is growing
Another result of the study shows why IT training for all employees is important: According to the study, 4 out of 10 companies (42 percent) have experienced attempts to prepare data theft, industrial espionage or sabotage with the help of social engineering in the past 12 months. 28 percent of the companies report isolated attempts, 14 percent even multiple attempts.
With social engineering, criminals try, for example, to impersonate a colleague from another department or a support employee on the phone in order to find out sensitive information such as passwords, but also basic information such as software used or names of other employees.
“Social engineering can seem harmless at first glance, but by using information from the inner workings of companies, cyber criminals can prepare their attacks in a targeted manner and massively increase their chances of success. The best protection against social engineering is vigilant and well-prepared employees”, says Ralf Wintergerst.