Your staff are your biggest security risk: AI is making it worse
好的,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要通读整篇文章,抓住主要信息。 文章主要讲的是内部安全事件的成本在过去两年里上升了20%,平均每个组织每年损失1950万美元。这个数据来自Ponemon Institute和DTEX的报告。里面提到的主要原因是员工的疏忽或错误,而非恶意行为。特别是影子AI的使用,员工未经批准与AI工具共享内部资料,导致问题频发。此外,尽管投入增加,但应对时间仍需改进。 接下来,我需要把这些要点浓缩成一句话,不超过100字。要确保涵盖成本增长、原因、影子AI的影响以及应对情况。 可能的结构是:成本增长+原因+影子AI+应对情况。这样既全面又简洁。 最后检查字数和表达是否流畅,确保信息准确传达。 </think> 内部安全事件成本两年内增长20%,达1950万美元/年/组织。员工疏忽或错误为主要原因,影子AI滥用加剧风险。尽管投入增加使应对时间缩短至67天,但仍有较大提升空间。 2026-2-26 21:21:23 Author: www.fortra.com(查看原文) 阅读量:0 收藏

A new report claims that the cost of insider security incidents has surged 20% in two years, reaching an average of US $19.5 million per organization annually, with no sign that the alarming figure is flattening.

That is one of the findings of the "Cost of Insider Risks Global Report" for 2026 from the Ponemon Institute and DTEX, which claimed that the main culprit is not malicious employees.

According to the study, which polled 8,750 IT practitioners at 354 organizations that had experienced one or more material insider-related incidents, the average annual cost of insider risk security incidents was US $16.2 million in 2023, rising to $17.4 million, and now $19.5 million.

On average, each company suffered 25 such incidents per year.

Of the 7,490 incidents reported from the study group in 2025, 53% were caused by negligent or mistaken employees. In other words, ordinary people make ordinary mistakes.

As Infosecurity reports, that category alone accounts for US $10.3 million of the average annual loss for each company, up 17% year-on-year.

Malicious insiders, by comparison, are costing US $4.7 million per year according to the report.

The difference in the figures is easy to explain: negligence is far more frequent than malice.

According to the report, shadow AI is the fastest-growing reason for this insider negligence. Workers across industries are sharing internal documents, source code, legal materials, and strategy plans with AI tools without approval or proper safeguards.

Meanwhile, AI-powered meeting assistants are generating records of sensitive internal discussions and sometimes leaving them publicly accessible.

The driver for this appears to be well-intentioned employees attempting to get more work done at speed, unaware that they may be exposing company secrets.

The study reports that some 92% of organizations acknowledge that AI has fundamentally changed how their staff handles information, and yet only 18% have formally integrated AI governance into their insider risk programs.

The good news is that investment is improving response times. As insider risk budgets have grown from 8.2% of IT security spend in 2023 to 19% in 2025, the average time to contain a breach (stopping or limiting damage once an insider incident has been identified) has decreased from 86 days to 67 days.

That, of course, is still far from ideal. The report notes that incidents resolved within 30 days average US $14.2 million per year, while those that drag past 90 days average US $21.9 million. Currently, only 13% of incidents are contained within 30 days.

With costs rising 20% in two years and the shadow AI problem still largely being poorly governed (if governed at all), the gap between organizations with mature programs and those without is only going to get wider.


Editor’s Note: The opinions expressed in this and other guest author articles are solely those of the contributor and do not necessarily reflect those of Fortra.


文章来源: https://www.fortra.com/blog/your-staff-are-your-biggest-security-risk-ai-making-it-worse
如有侵权请联系:admin#unsafe.sh