Cybersecurity continues to prompt government action. Whether it’s the proposed federal backstop to help insurers stay solvent after a catastrophic cyberattack, or the new cybersecurity disclosure rules adopted by the Securities and Exchange Commission that require public companies to disclose cybersecurity incidents within four days of deeming them material.
Perhaps less well known are the critical actions that HR professionals can exert to mitigate cyber breaches within their organizations. Today, 85% of all cyber incidents include a human element. In fact, some experts estimate that 78% of all work-related cyber claims start with phishing exercises, i.e., the fraudulent practice of sending emails, invitations or texts to employees purporting to be from reputable sources. By working with IT on awareness building, training, policies and pre-breach planning, HR has a significant role to play in stopping bad actors from breaching organizations.
