×
Friday, October 9, 2026

Should employers or employees shoulder the blame for a cyberattack? - Raconteur

Imagine your football team has just narrowly lost a game. Who’s responsible for the defeat? Is it the goalkeeper who let the ball slip through their fingers in the first half, or the striker who missed a sitter in the closing minutes? Maybe it’s the manager’s fault for failing to devise and implement a successful gameplan?

Now take this analogy and apply it to a business trying to assign blame in the aftermath of a cyber attack. Does the blame lie with the IT department for failing to put effective cyber defences in place, or is it the fault of the CEO for not implementing a culture of cyber awareness? Perhaps the employee who clicked the link that contained malicious software should take responsibility?

Many businesses opt for the latter choice. Research from security company Tessian found that 21% of the 2,000 US and UK workers they surveyed have lost their job in the past year after making a mistake that compromised their company’s security.

Impact of remote working

Irina Brass is associate professor in regulation, innovation and public policy at University College London. She says the figures show “a knee-jerk reaction. There’s a lot more organisations can do to become more resilient before placing the blame on employees.”

One option is a refreshed cybersecurity training programme that reflects post-pandemic working patterns. While many businesses provide such training to their employees, often these overlook the new vulnerabilities exposed by the technologies that...



Read Full Story: https://www.raconteur.net/technology/cybersecurity/employee-or-employer-whos-...