Zürich, 21.09.2026 (PresseBox) - erizon’s 2026 Data Breach Investigations Report (DBIR) once again highlights the importance of the human factor in cybersecurity: 62% of the breaches analysed involved an unintentional human contribution. This does not mean that people are the sole cause of security incidents. It does, however, confirm that technical controls alone cannot eliminate risks related to credentials, errors, social engineering and access rights.
For Validato, a European provider of background checks and Human Risk Management, the conclusion is clear: technical security controls should be complemented by proportionate human-risk management. “Cybersecurity does not end at the firewall. For sensitive roles, it can also be relevant – within the applicable legal framework – to verify whether a person’s identity, qualifications and relevant professional history are consistent with the level of trust and access required by the role,” says André Naef, CEO of Validato.
Validato recommends that Spanish CISOs work with HR to define in advance which checks are necessary and proportionate for each role. In Spain, any processing of personal data in recruitment and employment requires a valid legal basis and must comply with the GDPR and LOPDGDD principles of purpose limitation, data minimisation, transparency and proportionality. Data relating to criminal convictions and offences is subject to additional restrictions and cannot be checked routinely without a specific legal basis.
About Validato: Validato is an international provider of background checks and Human Risk Management, headquartered in Zurich, Switzerland, and operating internationally. Its modular, ISO 27001-certified platform enables companies to configure candidate and employee checks according to the role and within the applicable legal framework. Core data is processed and stored in Switzerland and the EU and, under Validato policy, deleted within a maximum of 120 days. No minimum volumes and no setup fees.
-
IT-Awards
Aktuelle Beiträge aus "IT-Awards"
-
Bedrohungen
Aktuelle Beiträge aus "Bedrohungen"
- Netzwerke
-
Plattformen
- Schwachstellen-Management
- Betriebssystem
- Server
- Endpoint
- Storage
- Physische IT-Sicherheit
- Verschlüsselung
- Allgemein
- Cloud und Virtualisierung
- Mobile Security
Aktuelle Beiträge aus "Plattformen" -
Applikationen
Aktuelle Beiträge aus "Applikationen"
-
Identity- und Access-Management
- Benutzer und Identitäten
- Authentifizierung
- Biometrie
- Smartcard und Token
- Access Control / Zugriffskontrolle
- Blockchain, Schlüssel & Zertifikate
- Zugangs- und Zutrittskontrolle
- Passwort-Management
- Allgemein
Aktuelle Beiträge aus "Identity- und Access-Management" -
Security-Management
- Compliance und Datenschutz
- Standards
- Sicherheits-Policies
- Risk Management / KRITIS
- Notfallmanagement
- Awareness und Mitarbeiter
- Sicherheitsvorfälle
- Allgemein
- Digitale Souveränität
Aktuelle Beiträge aus "Security-Management" -
Specials
Aktuelle Beiträge aus "Specials"
- eBooks
- Security Visionen 2026
- Zukunft der IT-Sicherheit 2024
- Kompendien
- Anbieter
- Cyberrisiken 2025
- Bilder
- CIO Briefing
-
IT Security Best Practices
Aktuelle Beiträge aus "IT Security Best Practices"
-
mehr...