Confronting Information Security's Elephant, The Unintentional Insider Threat
April 2020

Individuals within organizations are significant threats to information security, not only due to malicious actions but also because of unintentional human errors. Despite recent reports highlighting human error as a central cause of security breaches, it remains an underemphasized aspect in security discussions. This paper reviews data on error-based breaches across organizations and introduces a new taxonomy and nomenclature for classifying and understanding human errors in information security. By applying concepts from safety research, the goal is to improve Security Education, Training, and Awareness (SETA) programs and address the daily demands placed on employees to reduce the risk of error-related breaches.
Authors:
Matthew Canham, Clay Posey, and Patricia S. Bockelman