Data breaches reported to UK's ICO data protection watchdog in 2017, up 29% YoY, were seven times more likely to be caused by human error than hackers
Rebecca Hill / The Register :
Context & Ripple Effects
The ICO's 2017 numbers land just as the UK's disclosure regime tightens: weeks after this data was compiled, GDPR took effect and ICO privacy complaints more than doubled, meaning the watchdog now sees far more of what firms previously kept quiet. The headline finding — human error outcausing hackers seven to one — reframes the threat model away from external attackers.
The pattern has held since: the ICO later faulted the UK election authority for skipping basic data-protection steps before a state-backed attack on 40M voters' records, and FOI disclosures showed even the antitrust regulator itself logged 150 internal breaches in two years. Breach volume is rising not because attackers got better but because reporting became mandatory and mistakes became visible.
First-order effects
- Firms reporting breaches to the ICO now face scrutiny of internal process, not just intrusion defenses — the seven-to-one error ratio means most disclosed incidents trace to staff mistakes, lost devices, or misconfiguration rather than hacking.
- Security buyers can no longer justify spend purely on perimeter tools; the ICO data points budget toward training, access controls, and handling procedures for named workforces.
Second-order effects
- Insurers and auditors pricing cyber risk shift weight toward human-factor controls, since the dominant loss driver inside the ICO's numbers is employee error rather than sophisticated attack.
- Competing regulators across Europe, seeing complaint volumes climb alongside breach reports post-GDPR, gain evidence to push harmonized enforcement — the ICO's doubled complaint intake is the template France's 64% jump mirrors.
Third-order effects
- If disclosure regimes keep expanding visibility, 'breach' stops being an exceptional event and becomes a routine compliance category — with average costs already climbing per IBM's five-year trend — forcing boards to treat data handling as operational risk, not IT risk.
- Regulators' attention migrates from prosecuting hackers (largely outside their reach) to penalizing organizational negligence, as the election-authority case shows: the enforceable failure is the skipped basic step, not the attacker.
The trend: Mandatory breach disclosure is turning human error into the measurable core of data-security risk, shifting both regulatory enforcement and corporate spending from perimeter defense toward process and training.