Editorial

Human Error + Shadow IT

The perfect storm waiting to happen inside your business 

Monday, June 01, 2026 | 5 MINS

In most cases, the weakest link is your employees.  Depending on the size of your organisation, that can mean hundreds of humans operating your devices, data, systems and applications. 

Research by Stanford University has found that 88% of data breaches can be attributed to human error.


As a security professional, you’ll be painfully aware of just how poor some employees can be at maintaining security best practices. You can put them through as much training as you want: they’ll still set passwords as ‘password123’ and use them on every account and application. And they’ll still merrily click away at suspicious-looking links in emails they weren’t expecting to receive.

Now consider those gaping vulnerabilities in the context of shadow IT. More and more businesses are adopting software outside traditional security and governance controls. This ranges from browsers and specialist software to SaaS applications and AI platforms, often deployed without the knowledge of IT and security teams, let alone their approval.

There are substantial volumes of applications being deployed that bypass security, with protection left in the hands of employees who may not think about protecting data in the same way you do. With no traditional controls in place and best practices potentially absent too, these shadow IT applications represent a huge opportunity for cyber criminals to breach systems and wreak havoc.

This means now is the time to consider a major overhaul not only in how your security and governance processes are applied, but also in how your workforce engages with those processes. 

This topic is sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.


"Rock Solid Foundations"

This handy Infographic "Rock Solid Foundations", contains lots of interesting statistics and facts to aid your research.

Download

This topic sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.

Also in this section

}());