What…..one in five UK Employees admit sharing Passwords on External Note

IT-professional

A recent cybersecurity study has revealed a concerning trend among employees in the United Kingdom: One in every five workers admits to writing down or sharing their passwords on external notes, creating significant security risks for businesses. The findings come from research conducted by Gallagher, a human resources and consulting firm based in Illinois, United States, highlighting how everyday workplace habits can leave organizations vulnerable to cyber threats.

According to the study, many employees place convenience above good cybersecurity practices. Instead of creating secure methods to manage passwords, some choose to write them on paper, sticky notes, or other external locations that can easily be accessed by unauthorized individuals. While this may seem like a simple solution for remembering complex passwords, it significantly increases the risk of sensitive company information being exposed.

The report also found that nearly half of the respondents from the United Kingdom and Ireland reuse the same password for both their personal and professional accounts. Cybersecurity experts have long warned against this practice because it allows attackers to gain access to multiple accounts if just one password is compromised. For example, if a personal email or social media account is breached, cybercriminals may use the same password to attempt access to workplace systems, potentially exposing confidential business information.

Another alarming finding is that around 26 percent of employees transfer corporate data to their personal devices to make working outside the office more convenient. While this may improve flexibility and productivity, it also increases the likelihood of sensitive business data being lost, stolen, or accessed through unsecured personal devices. Without proper security controls, confidential company information can become vulnerable to cyberattacks, accidental leaks, or unauthorized access.

The financial consequences of poor cybersecurity practices are substantial. Gallagher’s report, together with separate research conducted by the Centre for Economics and Business Research (CEBR), estimates that UK businesses spent approximately £52 million in 2025 on employee time dedicated to responding to cyber incidents. In addition to lost productivity, organizations incurred around £226 million in related expenses, including forensic investigations, incident response, system recovery, remediation efforts, and, in some cases, regulatory fines, legal penalties, and compensation payouts.

The findings underline the importance of strengthening cybersecurity awareness across organizations. Encouraging employees to use password managers, enable multi-factor authentication, avoid password reuse, and keep corporate data on secure company-managed devices can significantly reduce cyber risks. As cyber threats continue to evolve, developing a strong culture of security awareness is essential for protecting both employees and businesses from costly data breaches and cyberattacks.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display