The human element of cybersecurity

All the high-tech armour in the world can't guard against one naïve or disgruntled employee, warn lawyers from Herbert Smith Freehills.
Prefer the Global Legal Post on Google

alphaspirit

Though the landscape of corporate privacy and data security may be evolving, the number one source of cybersecurity and data risk remains the same—human beings. This is the message being hammered home in a recent blog post published by HSF partners Andrew Moir and Christine Young and special counsel Fiona Austin.

The message doesn't appear to be lost on data privacy and security professionals. A recent First Advantage survey of HR, risk management and C-suite executives found that the majority agree that employees remain the number one concern for internal and external security risks. However, with the battleground between employee privacy and corporate security growing ever-more tense and the liability stakes for breaches getting bigger by the day, the HSF team argue that companies (and their lawyers) need to be taking pro-active steps to manage human-based security risks.

In their article, the HSF team offer ten suggestions for pro-actively managing the risk of a staff member accidentally or willfully leaking confidential data. Number one among them, they suggest, is to ensure that you have the 'right people' working in your organisation. Conducting thorough background checks on new employees, including behavioural assessments for personality profile, decision-making and ethics, can go a long way to preventing the possibility of an intentional leak in the future. In First Advantage's survey, 60 per cent of respondents said that conducting thorough background checks on employees was more important to their data security efforts than firewalls or anti-malware software.

On the legal side, contracts can also play an important role in managing employee-related security risks. The HSF team recommend that all employment contracts should impose appropriate obligations to comply with company policies and procedures regarding security, as well as clear consequences for non-compliance. More broadly, contracts should clearly define what constitutes 'confidential information', leaving no room for assumption or misinterpretation.

The full list of recommendations can be found in the original post published on The In-house Lawyer.

Email your news and story ideas to: [email protected]

The Global Legal Post

© 2026 The Global Legal Post. All Rights Reserved

Top