Digital security consultants @stake reports that corporate employees who fail to implement basic security procedures are the biggest single cause of digital security breaches within the organizations it has worked with. To help companies address these problems, @stake has created a list of the most common security errors committed by employees who often unknowingly put the integrity of corporate systems at risk. Although this list shows some of the most common security errors, @stake warns that each company must identify their unique risk of security exposure and assess the level of security needed.
Royal Hansen, practice director for @stake Europe, said, “Too many companies believe that IT [Information Technology] security is a product issue—in fact, human beings are the weakest link in any security system. Expensive and elaborate security measures are often completely undone by a company’s failure to enforce even the most simple precautions, opening up the entire corporate infrastructure to malicious attack. We have published our list of security errors in the hope that more companies will take the simple steps that will protect their business data.”
The ways employees compromise security at corporate sites are:
- Writing their passwords on Post-It notes and leaving them on or near their machines.
- Setting their default passwords to be the same as their primary password.
- Entering an existing password when the system prompts for a password to be changed.
- Loading encrypted discs onto a system, failing to remove them, and leaving the password open.
- Plugging modems straight into servers and bypassing multi-level corporate security systems.
- Plugging servers straight into the Internet, bypassing routers that may be acting as firewalls.
- Issuing security certificates with blank passwords.
- Failing to enter a password into Microsoft’s server administration system, thus leaving a blank default password that compromises the whole corporate system.
- Carrying (and subsequently losing) laptop computers loaded with company secrets (also applies to government employees).
- Failing to keep up-to-date with and implement newly released patches issued by software vendors as breaches are discovered.
Based on a report from @stake

