Employees in IT Security: Human Behavior as Major Risk
Cybersecurity rarely fails at technology. According to Kaspersky (2025), 31 percent of incidents in Germany are enabled by careless employee behaviour. Net-D-Sign puts employees at the center of the security strategy.
Partner contribution with Net-D-Sign
Cybersecurity rarely fails today because of missing technology – it fails at the human factor. A recent study shows: in roughly one third of cybersecurity incidents at German companies, the behaviour of the organisation’s own employees played a decisive role. According to Kaspersky (2025), 31 percent of cases were enabled by careless actions – for example, clicking manipulated links or using weak passwords.
Key Takeaways
- According to Kaspersky (2025), careless employee behaviour enables 31 percent of cybersecurity incidents in German companies.
- Firewalls and antivirus tools often stay ineffective when the risk comes from user behaviour – security leads see the technical attack but not the triggering action.
- Net-D-Sign shifts IT security to the point where risk actually emerges: to the employees. A central platform captures security-relevant actions, scores them and triggers automated responses.
- The effect: early detection instead of damage control, targeted training instead of blanket measures, measurable security instead of assumptions.
The implication is clear: employees are already part of the attack surface. Modern security concepts start exactly there.
The human as weak spot – and opportunity
Phishing emails, social engineering, or insecure access to corporate systems: attack strategies target human error by design. Classic security measures like firewalls or antivirus tools are often powerless when risks stem from user behaviour.
The problem: many companies lack transparency about where exactly those risks emerge. Security leads see the technical attacks – but not the behaviour that enables them.
Missing transparency prevents effective countermeasures
In practice, security-critical situations often stay undetected:
- Employees click on suspicious links
- Security policies get circumvented or ignored
- Risks emerge in everyday workflows – without central capture
These “blind spots” mean companies only react once damage has already occurred. A proactive approach is missing.
IT security rethought: engage employees actively
An effective security concept has to start exactly where risk emerges: at employee behaviour.
That means:
- Create visibility for security-relevant actions in day-to-day work
- Raise awareness by involving users deliberately
- Improve response time before incidents escalate
This is exactly the perspective shift Net-D-Sign pursues with its new approach.
More transparency on human risk
With its new service, Net-D-Sign deliberately puts employees at the centre of the IT security strategy. The goal: make security-critical behaviour visible and actively manageable.
The solution provides a central platform that:
- captures and scores security-relevant user actions
- identifies potential risks early
- enables automated responses for critical events
- documents every incident traceably
The decisive difference: not only technical threats get analysed, but also the human factors behind them.
Relevance for companies: from reactive to preventive protection
Companies benefit from a clear perspective shift:
- Early detection instead of damage control
- Targeted training instead of blanket measures
- Measurable security instead of assumptions
When employees are treated not only as a risk but as a controllable part of the security strategy, the overall concept becomes significantly more robust.
IT security starts with people
The numbers are unambiguous: without the human factor, any security strategy stays incomplete. Companies that actively involve their employees and make their behaviour transparent reduce risks sustainably.
Now is the right moment to question existing processes and rethink them.
Info paper by Net-D-Sign
Employee security under control
More information on Net-D-Sign’s new service – including an IT baseline check – is available directly in the info paper.
Frequently Asked Questions
How large is the share of cybersecurity incidents enabled by employee behaviour?
According to a Kaspersky study from 2025, employee behaviour plays a decisive role in about one third of cybersecurity incidents at German companies – in 31 percent of cases, an attack was enabled by careless actions.
Which typical mistakes enable cybersecurity incidents?
Classic patterns include opening manipulated links and attachments, circumventing or ignoring security policies, and using weak passwords. On top of that come insecure accesses to corporate systems that often go unnoticed in daily work.
Why are firewalls and antivirus tools no longer sufficient?
Classic security measures secure the technical layer but do not take effect when risks stem from user behaviour. Social engineering and phishing aim directly at human error – and many companies lack transparency about the behaviour that actually triggered an incident.
What is the core of the Net-D-Sign approach?
Net-D-Sign deliberately puts employees at the centre of the IT security strategy. A central platform captures security-relevant user actions, scores them, identifies potential risks early and enables automated responses for critical events – including traceable documentation.
What does preventive instead of reactive protection mean in practice?
Preventive means: early detection instead of damage control, targeted training instead of blanket measures, and measurable security instead of assumptions. Employees are treated not only as a risk, but as a controllable part of the security strategy.
Editor’s Picks
IT Security Spending in Germany: Double-Digit Growth
More from the MBF Media Network
Cyber Insurance 2026: What Insurers Really Check
Deepfake Protection for the C-Level: The CEO Isn’t Real
Managed Services for the Mid-Market: Outsourcing IT Instead of Building In-House
Image source: Pexels / Tima Miroshnichenko (px:5380618)

