Shortcuts create new cyber exposures
One in five employees have shared work login details or passwords with someone outside their organisation, amid new fears that human error remains the biggest cyber risk to business.
Research by broker Gallagher, has raised new concerns that everyday shortcuts in the workplace could be making businesses more vulnerable to cyber-attacks.
This could include sharing passwords with family or friends to allow them to use devices or sharing logins for social media accounts, client portals, subscriptions and admin systems with freelancers, suppliers, agencies and IT providers.
The findings come after recent high-profile cyber incidents affecting major UK retailers placed renewed focus on human behaviour and internal processes in cyber resilience. Recent reports suggested attackers used social engineering tactics to target IT help desks and reset employee passwords at these firms, showing how criminals can exploit people and processes, not just technical weaknesses.
Andrew Marvin, client service director at Gallagher, said: “Most employees are not intentionally trying to put their organisation at risk, but everyday shortcuts can create exactly the kinds of openings cyber criminals look for. Sharing passwords, reusing login details or moving company data onto personal devices may feel harmless, but these behaviours can quickly undermine even robust cyber security systems.”
According to Gallagher’s research, almost half (45%) said they always or often use the same or similar passwords across personal and work accounts, creating a risk that credentials compromised through phishing or data breaches could be used to exploit workplace systems.
These behaviours may appear minor in isolation, but they can create the access points cyber criminals need to compromise systems, disrupt operations and expose businesses to significant financial and reputational fallout. Recent Gallagher and CEBR analysis found this fallout can be substantial, with cyber-attacks costing large UK businesses an estimated £11.7 billion in 2025, including £5.4 billion in operational disruption and £3.7 billion in litigation costs.
The litigation risk is heightened for businesses when the cause of an incident can be linked back to preventable employee actions or weak internal controls. With human error reported to have contributed to 95% of data breaches in 2024, Gallagher’s findings suggest behaviours such as sharing passwords externally, reusing login details or moving company data onto personal devices could leave businesses more exposed if a cyber incident leads to legal action.
The research also points to a wider pattern of employees prioritising convenience over these safeguards.
More than a quarter (26%) said they had moved company data onto personal devices or storage accounts to make their work easier. While this may seem like a harmless shortcut, it can make it harder for businesses to know where sensitive information sits, who has access to it and what may have been compromised if an incident occurs.
Then broker added the lack of visibility can make cyber incidents slower and more expensive to manage. Gallagher and CEBR research estimated that large UK businesses spent £51.2 million in staff time responding to cyber incidents in 2025, alongside £226.7 million in direct response costs, including investigation, containment, remediation and external specialist support.
At the same time, one in four (25%) workers regularly delay installing security updates on work devices, even though software patches are often designed to fix known vulnerabilities that cyber criminals may already be exploiting.
The findings also suggest that employees may be underestimating newer areas of cyber risk. More than one in four (28%) viewed the use of cloud services or AI tools involving company data as low risk, despite growing concerns around data leakage, unauthorised access and the handling of confidential business information.
Marvin added: “The challenge for businesses is that cyber risk is no longer just about defending against sophisticated attacks. It is also about making sure employees understand how routine decisions can expose the organisation to disruption, data loss and reputational damage. Training, clear policies and strong controls all have an important role to play. But businesses should also understand what happens if those controls fail, including how their insurance would respond if human error contributed to a cyber incident.”







