Інформація надається виключно з ознайомчою метою та не є закликом до участі в азартних іграх чи рекламою азартних розваг.

Mykhailo Zborovskyi Cosmobet (ex-beneficiary): Why the weakest link in cybersecurity is the employee

 Companies spend billions on technical protection, but regularly ignore the most vulnerable link in the system, the person. Mykhailo Zborovskyi Cosmobet (ex-beneficiary of the brand), an expert in iGaming product development, cites data according to which up to 95% of cyber incidents in 2024 occurred due to human actions or inaction. His argument is that cybersecurity has long gone beyond technology and has become a matter of psychology, education and corporate culture.

One click is more expensive than billions of investments in protection

Mykhailo Zborovskyi starts with a illustrative example. One error in the development or testing process caused a global collapse of the IT infrastructure and the following consequences:

 

  • 4 billion dollars in losses;
  • Canceled flights and hospitals shut down;
  • Millions of affected users worldwide.

 

“The human factor is the main threat to information security,” emphasizes Mykhailo Zborovskyi.

 

No technical perfection of the system can compensate for one human error at a critical point in the process. That is why, according to him, this case should be considered not as an exception, but as a typical illustration of how fragile even the most expensive infrastructure can be.

The human factor in numbers

The expert’s argument is based not only on individual cases, but also on industry statistics. According to Mimecast, in 2024, up to 95% of cyber incidents occurred due to human actions or inaction, and according to various estimates, from 68% to 95% of attacks occur due to an employee’s mistake, ignorance or negligence. At the same time, “123456” still remains the most popular password in the world.

 

In the 2010s, attacks were mostly technical, such as Trojans, code vulnerabilities, and viruses, while today attacks increasingly start not with code, but with someone opening the wrong email or clicking the wrong link.

 

“A person becomes actively interested in cyber hygiene only after they themselves fall into the trap of scammers,” notes Mykhailo Zborovskyi.

 

Often this happens too late, when data has already been lost, and customers’ trust has to be restored for months.

The Psychology of Phishing

According to Mykhailo Zborovskyi analysis, attackers systematically exploit four behavioral patterns that have little to do with technology and a lot to do with human psychology:

 

  • Urgency and fear as the impression that you need to act immediately, otherwise there will be consequences;
  • Authority and trust as a disguise as a well-known brand or company management;
  • Curiosity and temptation as promises of gifts, prizes, or exclusive information;
  • Cognitive biases as the habit of trusting acquaintances and acting automatically without checking the details.

 

In parallel, new technical attack formats are developing. Kwishing through malicious QR codes, smishing through text messages, vishing through calls. According to the expert, these formats are evolving faster than protection technologies can react to them.

Cyber education

According to the expert's argument, businesses are gradually realizing that staff training is a necessity, not an additional option. According to Cybersecurity Ventures, global spending on staff training in cybersecurity will exceed $ 10 billion by 2027, and more than 90% of incidents could be avoided if employees knew how to act during an attack.

 

A practical tool that Mykhailo Zborovskyi highlights is phishing simulations. Studies show that after five simulations, the proportion of employees who click on malicious links drops from 70% to single digits, and according to Microsoft, employees who have undergone phishing simulation training are 50% less likely to be attacked in real life.

Fatigue as a vulnerability

“Fatigue, burnout, and lack of focus are as much a vulnerability as an unsecured server,” says Mykhailo Zborovskyi.

 

To truly reduce human risk, a systemic approach is needed, not a one-time training session once a year. It includes ongoing training of the team to recognize threats, clear data handling policies, a security culture without fear of admitting one’s own mistake, regular access audits, and the use of AI to detect anomalies before they become a problem.

 

According to him, cybersecurity should become part of school education, while currently most people learn these rules after the fact, after the first serious incident.

Questions and Answers

Why, according to Mykhailo Zborovskyi, is a person the weakest link in cybersecurity?

Because 68% to 95% of cyber incidents occur due to human actions or inaction - phishing, weak passwords, negligence, and not due to technical vulnerabilities of protection systems.

 

Which industries have the highest risk from the human factor?

Healthcare, the financial sector, government agencies and gambling are areas where a cyberattack immediately hits the trust, finances or license of a company, and not just causes a technical failure.

 

What most effectively reduces the risks of the human factor?

A combination of measures: regular phishing simulations, constant team training, clear data handling policies, a security culture without fear of admitting a mistake and attention to the condition of people.

Похожие публикации


Наверх