Digital Checkmark single post

No, 90% of Breaches Are Not Human Error. Here Is What the 2026 DBIR Actually Says

Server rack panel with a single amber warning light among green ones

If you have sat through a security pitch in the last five years, you have heard the number. Ninety per cent of breaches are caused by human error. Sometimes it is ninety five. Sometimes it is attributed to Verizon, IBM or Stanford, depending on who is selling.

We went and read the source. The 2026 Verizon Data Breach Investigations Report, built on 19,905 breaches, says the human element was present in 62% of them. Not ninety. And “present in” is not the same as “caused by”.

Where the 90% comes from

Nowhere, as far as any current primary source goes. The figure circulates because it is useful: it is high enough to alarm a business owner and vague enough that nobody checks it. We had it on our own site until we audited our pages and pulled it.

What the report actually says is more interesting than the myth. The human element sits at 62%, and it went up from 60% the year before, which is the part worth paying attention to. Security tooling improved and the number still rose.

The part that changes where you spend

Here is the finding that should reorganise a small business budget. For the first time in the report’s history, exploitation of vulnerabilities is the most common way into an organisation, at 31%. Credential abuse, the previous champion, is down to 13%.

In other words: the single most likely way an attacker gets in is not by tricking your staff. It is through a machine you own, running software with a known hole, that nobody got around to patching.

And the patching numbers are worse than the intrusion numbers. Of the vulnerabilities that are known to be actively exploited, listed publicly in the CISA catalogue, only 26% were fully remediated last year, down from 38%. The median time to close one went from 32 days to 43 days.

Three quarters of the critical holes stay open, on machines that belong to somebody.

So is awareness training a waste of money?

No, and this is where the honest version beats the scary version. The median click rate on simulated email phishing is 1.4%. That is not the one in five you may have been quoted either. But 1.4% of a hundred people, receiving attempts every week, is still somebody clicking every month.

Two things make training worth doing, and neither of them is the 90% myth:

What we would actually do first

If you run a small business and you have limited money and attention, the order that the evidence supports is roughly this:

  1. Patch what is being exploited. Not everything, not by score. The CISA catalogue exists precisely so you can sort by what attackers are using right now. This is our patch and vulnerability work.
  2. Authenticate your domain. SPF, DKIM and DMARC taken to reject, so nobody can send mail as you. You can check yours in a minute, free.
  3. Find the credentials already leaked. Training does nothing about a password exposed three years ago in somebody else’s breach. Check whether yours are circulating.
  4. Then train, continuously and including the phone. That is our awareness work, and we report the rate rather than the attendance.

Why we care about a number

Because an inflated statistic sends money to the wrong place. If you believe 90% of your risk is your staff, you buy training and feel finished. The report says your most likely breach starts on an unpatched server while everyone is asleep.

We would rather quote a smaller number that is true. If a provider gives you a figure, ask which report and which year. It takes ten seconds to check, and it tells you a lot about who you are dealing with.

Sources: Verizon 2026 Data Breach Investigations Report. Figures quoted as published.