Zivver

102 stats1 reports

All Statistics

81% of employees say security practices and technologies that are more user-friendly will result in better security outcomes

39% of IT leaders prioritize human error prevention / DLP for email security investment.

41% of employees in France say they frequently use IT policy workarounds to “get the job done” and save time or effort.

60% of employees in financial services say they frequently use IT policy workarounds to “get the job done” and save time or effort.

43% of IT leaders prioritize phishing prevention for email security investment.

Advanced threat protection and malware detection (50%), employee training and awareness programs (48%), and phishing prevention (43%) are the top priorities for email security investment, according to IT leaders. These are followed by email encryption (42%), certified email authentication and access control (41%), human error prevention/data loss prevention (DLP) (39%), and post-delivery protection (24%).

25% of IT leaders say limited security resources / lack of security skills is among the biggest security vulnerabilities in organizations

When asked about their primary email security focus for the next two to three years, 11% will focus more on outboud security solutions

More than a third (34%) of workers in large organizations with more than 1,000 employees agree, “I’m not clear on our company policy around email security,” increasing to 41% among smaller businesses with 250-999 employees.

58% of employees say it’s too easy to make errors when using email

53% of employees in legal services say they frequently use IT policy workarounds to “get the job done” and save time or effort.

Only 24% of IT leaders believe their security spending is "very well aligned" with actual risks, while 53% think it is "quite well aligned," 20% feel it is "not particularly aligned," and 3% say it is "not at all aligned."

41% of IT leaders prioritize certified email authentication and access control for email security investment.

While IT leaders estimate that only 34% of outbound email incidents are formally reported, many employees handle mistakes informally—50% say they would notify the unintended recipient directly, while just 9% would report the incident to IT

67% of IT leaders claim that email doesn’t get the security attention it deserves.

While 64% of employees report receiving training on email security, more than a third in large organizations find it ineffective or are dissatisfied with how training is delivered

Employees frequently send the wrong attachment (33%), misaddress emails to unintended recipients (32%), or misuse CC and BCC fields (20%). These mistakes are more likely to happen when employees are tight on time (54%), when they are stressed (40%), or when they feel overwhelmed by too many messages (40%).

38% of leaders cite increased sharing of data and sensitive information over email as their motivation for change in their security focus

30% of employees said they would be able to focus more on the quality of their work, 28% stated they would be more productive, and another 28% mentioned they would feel trusted by their employer invested in email security technology

63% of employees in the UK say they frequently use IT policy workarounds to “get the job done” and save time or effort.

49% of employees in Germany say they frequently use IT policy workarounds to “get the job done” and save time or effort.

Organizations recognize the importance of email security training, with 95% of IT leaders confirming its availability within their companies

Only 24% of IT leaders are highly confident in the current alignment of security investments with the most pressing threats facing their organization

48% of IT leaders prioritize employee and awareness programs for email security investment.

Phishing continues to dominate as one of the most prevalent and sophisticated cyber threats, accounting for over 80% of reported security incidents in 2024

38% of IT leaders rank "employee misunderstanding of security policies" among their top vulnerabilities, while 60% of employees report using workarounds to bypass policy measures, highlighting a potential gap between IT leaders’ assumptions and the reality on the ground

When asked about their primary email security focus for the next two to three years, 28% aimed to find an "all-encompassing" solution for both inbound and outbound security.

26% of leaders cite cost reduction pressures as their motivation for change in their security focus

Malicious attacks, or “inbound” threats, are considered the biggest threat vector to email amongst IT leaders, with 47% stating that inbound threats are a bigger concern to them than outbound email security

52% of employees say they are clear on their company's policy around email security, 45% say they are not clear, and 3% say they don't know

23% of IT leaders have email security training on inbound threats only

16% of employees say group training sessions over Zoom/Teams is the most engaging/effective email security training format

59% of employees say that they are worried that AI will make it harder for them to know if an incoming email or link is legitimate.

65% of IT leaders agree they lose more data every year through employee error than through any kind of malicious inbound threat

While 47% of IT decision-makers identify phishing and malware as top threats to their data, only 20% prioritize outbound risks and just 39% of IT leaders point to data loss prevention/human error as an investment priority for email security

Averagely, 66% of IT leaders admit that employee mistakes in outbound emails result in more significant data loss than malicious inbound attacks.

65% of IT leaders in the US admit that employee mistakes in outbound emails result in more significant data loss than malicious inbound attacks.

56% of IT leaders in Netherlands admit that employee mistakes in outbound emails result in more significant data loss than malicious inbound attacks.

IT leaders identify the biggest risks for potential data loss as inbound email threats (47%), outbound email threats (20%), and both presenting an equally significant risk (33%).

68% of IT leaders in France agree that outbound email security doesn’t get as much attention beyond compliance, but it is the silent security killer

58% of IT leaders in Germany agree that outbound email security doesn’t get as much attention beyond compliance, but it is the silent security killer

38% of IT leaders say employees using unauthorised platforms is among the biggest security vulnerabilities in organizations

35% of IT leaders say increasing number of data sharing and collaboration tools being used by employees is among the biggest security vulnerabilities in organizations

33% of IT leaders say increase in data access points is among the biggest security vulnerabilities in organizations

29% of IT leaders say expanding and more complex data security threats is among the biggest security vulnerabilities in organizations

15% of IT leaders say lack of visibility or reporting of security incidents in your organization is among the biggest security vulnerabilities in organizations

When asked about their primary email security focus for the next two to three years, 13% will focus more on inbound security solutions

45% of leaders cite increasing threat levels with AI as their motivation for change in their security focus

37% of leaders cite regulations and compliance as their motivation for change in their security focus

32% of leaders cite increased focus on risk mitigation as their motivation for change in their security focus