Part of an executive team? You might be the biggest security risk to your business

CEO thought leader
(Image credit: Image credit: Pexels)

New research has found that executive leaders are putting their businesses at risk with much looser security practices than their underlings.

The study from Ivanti found executives are the most likely to be targeted by threat actors, making the possibility of a successful phishing campaign or malware attack even higher.

The shocking discrepancy between the security protocols practiced by cybersecurity professionals and their executive leadership can have real consequences.

Do as I say, not as I do

The company's Executive Security Spotlight report examined the security habits of office workers, security professionals and leadership executives from across the globe found that despite increasing support and investment in cybersecurity, 49% of executives have requested to bypass security protocols.

Moreover, executives are three times more likely to share their work devices with friends and family than office workers, and one in three admitted to accessing unauthorized data. But that's not all, 77% use birthdates, pet names, or other easy to remember information in their passwords.

Security professionals within businesses are struggling to combat the risks posed by executives due to a number of factors. Due to over-burdening and under-staffing, almost two thirds (60%) of CISOs said they had experienced burnout in the past 12 months. Combine this with executives frequently violating security protocols under the guise of ‘just-this-once-ism’ and it's understandable why security teams have difficulty improving executive behaviors.

It’s no wonder then, that executives are twice as likely to describe their interactions with their security team as ‘awkward’ and ‘embarrassing’ compared to other office workers. Executives are also four times more likely to use external, often unapproved, tech support rather than consult their own IT team.

The emergence of spear phishing attacks targeting executive level employees has potentially led to an increasing number of executives being targeted by these scams. Almost half (47%) of executives said they had been targeted by a phishing scam in the past 12 months, with 35% of those clicking on a phishing link or sending money to a scammer.

"There's a 100% chance your organization has been phished in the last year. It's the #1 way threat actors get that initial foothold in your network. We need to make sure that we account for that, and don't just assume people will 'know better' or that a phish will be overly obvious," noted Ivanti Chief Security Officer Daniel Spicer.

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
Cyber-security
Security leaders don't want to be held personally liable for attacks
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Cyber-security
Dealing with the issue of CISO stress
person at a computer
Many workers are overconfident at spotting phishing attacks
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Latest in Pro
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
An AI face in profile against a digital background.
Getting your data ready as the AI race heats up
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why