---
title: Did I Do That? On Security Errors, Fear, and Shame
description: Why don’t people report security errors when they happen? We dive into the psychology behind mistakes — and explain what companies can do to change.
image: https://shardsecure.com/hubfs/ShardSecure_Risk.jpg
---

- [Home](https://shardsecure.com/)
- [Blog](https://shardsecure.com/blog)

# Did I Do That? On Security Errors, Fear, and Shame

![Picture of ShardSecure](https://shardsecure.com/hubfs/ShardSecure%20brand%20assets/Logo%20(2022)/Profile/ShardSecure-Logo__Profile--Purple-Inverted.svg "Picture of ShardSecure")

[ShardSecure](https://shardsecure.com) 

 December 12 2022 

![](https://shardsecure.com/hubfs/ShardSecure_Risk.jpg)

# Did I Do That? On Security Errors, Fear, and Shame

Security errors are common. No, *really* common. 

 In 2015, human error ranked as the [single largest factor behind security breaches](https://connect.comptia.org/content/research/trends-in-information-security-study). A [2021 report by Verizon](https://www.verizon.com/business/resources/reports/dbir/?CMP=OOH_SMB_OTH_22222_MC_20200501_NA_NM20200079_00001) found that 82% of data breaches involved human error, while a [2014 study by IBM](https://i.crn.com/sites/default/files/ckfinderimages/userfiles/images/crn/custom/IBMSecurityServices2014.PDF) revealed that over 95% of the security incidents they investigated had “human error” as a contributing factor. 

Security errors are also costly. A 2018 study by the International Monetary Fund shows that [cyber threats cost financial institutions between 10% and 30% of their net income](https://www.bai.org/banking-strategies/article-detail/how-to-combat-common-employee-security-mistakes/) — and most of those threats result from employee actions and mistakes. 

 Yet, despite being both common and costly, mistakes at work are widely underreported. A recent study from ISACA, for instance, showed that [employees are underreporting security incidents](https://securityintelligence.com/articles/why-security-incidents-often-go-underreported/) even when it’s a requirement. 

So, why don’t employees report security problems and mistakes when they happen? And what can companies do to create a better culture — from better transparency to more resilient systems — around those mistakes? We’ll investigate below. 

## The psychology of making mistakes 

We all know the feeling of making a mistake — but we may underestimate just how much that feeling can affect our responses to mistakes at work. Unpleasant emotions like fear and shame can be major motivators, in some cases leading employees to conceal evidence of serious errors. 

 Indeed, the fear of failure can become so strong that it leads to a broad range of emotional and psychological problems, including shame, depression, anxiety, and low self-esteem. In extreme cases, it can actually be diagnosed as a [medical condition known as atychiphobia](https://my.clevelandclinic.org/health/diseases/22555-atychiphobia-fear-of-failure) — a testament to how truly unpleasant it can be to make a mistake. 

As a [2021 study in Frontiers in Psychology](https://www.frontiersin.org/articles/10.3389/fpsyg.2021.725277/full) notes, shame and fear of failure in the workplace can “inhibit employees’ motivation to correct errors,” “reduce their confidence in making subsequent improvements,” and cause them “to be evasive about failure events and avoid public attention, which prevents people from communicating about” and learning from failure. 

 Similarly, fear of mistakes can paralyze people — and can paradoxically make mistakes more likely. As the [Harvard Business Review notes](https://hbr.org/2020/06/how-to-overcome-your-fear-of-making-mistakes): “When we’re scared of making a mistake, our thinking can narrow around that particular scenario. Imagine you’re out walking at night. You’re worried about tripping, so you keep looking down at your feet. Next thing you know, you’ve walked into a lamp post.” 

At least part of it may be generational. According to [one research study](https://edubirdie.com/blog/the-psychology-of-human-error), younger employees were five times more likely to admit to cybersecurity errors, with 50% of 18 to 30 year olds owning up to mistakes versus just 10% of workers over 51. Some of that may be due to experience — less-experienced workers are more likely to make mistakes in the first place — but the researchers suggested that younger workers are actually more aware that they have made a mistake and are more willing to admit their errors and “lose face,” opening up more potential for improvement. 

## Adopting a mistake-tolerant culture 

So what can be done? How can organizations better learn from past mistakes and anticipate future ones? 

Turns out, it’s all about the culture. Analyzing mistakes and failures requires openness, patience, and even tolerance for ambiguity — but companies often value decisiveness, efficiency, and action over thoughtfulness and reflection. Without the [right company culture](https://www.frontiersin.org/articles/10.3389/fpsyg.2021.725277/full), employees won’t be willing to own up to mistakes, and supervisors won’t be able to help the organization improve on those mistakes. 

Similarly, CISA notes in their [2020 Insider Threat Mitigation Guide](https://www.cisa.gov/sites/default/files/publications/Insider%20Threat%20Mitigation%20Guide_Final_508.pdf) that a good response “should not be focused on catching people doing things wrong. Rather, it should be grounded in the notions of helping people avoid mistakes, providing a safe environment, and preventing insider incidents from occurring while mitigating the potential risks.” 

To encourage this kind of open, nonjudgmental work culture, one Harvard Business Review article suggests a [top-down approach to learning from security mistakes](https://hbr.org/2011/04/strategies-for-learning-from-failure). They note that leaders should avoid blaming and instead make people feel comfortable to point out their own mistakes. 

Meanwhile, SHRM suggests [curiosity as a tool to avoid shame and learn from mistakes](https://www.shrm.org/resourcesandtools/hr-topics/employee-relations/pages/employee-mistakes.aspx). Remaining curious and open to explanations during conversations about security errors can lead to significantly better communication, improved learning, and growth — as opposed to criticism, which “triggers a combination of defensiveness, dejection, resistance and antipathy.” 

## Let microsharding cover your mistakes 

Company culture aside, you may be wondering what you can do to protect against human error in your security systems. We’ve got you covered. 

ShardSecure’s technology helps companies minimize the fallout of human error and maintain business continuity. Its [three-step microsharding process](https://shardsecure.com/resources/faqs/microsharding) desensitizes sensitive data for the cloud, rendering it unintelligible and of no value to unauthorized users. This supports data privacy and confidentiality even when buckets are misconfigured or storage locations are accidentally left exposed.  

Meanwhile, if a team member accidentally clicks a link in a phishing email and introduces ransomware to a system, our self-healing data can help. By automatically reconstructing in real-time any microsharded data that fails our data integrity checks, we can keep operations running in the face of mistakes. 

To learn more, take a look at our [solution briefs](https://shardsecure.com/resources/briefs), [FAQs](https://shardsecure.com/resources/faqs), and [white papers](https://shardsecure.com/resources/white-papers). We’ve got a wealth of information on how ShardSecure helps your data remain confidential, available, and protected in the cloud — so your future mistakes can involve less fear and shame and more opportunities for growth. 

### Sources

[Trends in Information Security Study | CompTIA](https://connect.comptia.org/content/research/trends-in-information-security-study) 

[2022 Data Breach Investigations Report | Verizon](https://www.verizon.com/business/resources/reports/dbir/?CMP=OOH_SMB_OTH_22222_MC_20200501_NA_NM20200079_00001) 

[IBM Security Services 2014 Cyber Security Intelligence Index | IBM](https://i.crn.com/sites/default/files/ckfinderimages/userfiles/images/crn/custom/IBMSecurityServices2014.PDF) 

[How To Combat Common Employee Security Mistakes | BAI](https://www.bai.org/banking-strategies/article-detail/how-to-combat-common-employee-security-mistakes/) 

[Why Security Incidents Often Go Underreported | Security Intelligence](https://securityintelligence.com/articles/why-security-incidents-often-go-underreported/) 

[Atychiphobia (Fear of Failure) | Cleveland Clinic](https://my.clevelandclinic.org/health/diseases/22555-atychiphobia-fear-of-failure) 

[Shame on You! When and Why Failure-Induced Shame Impedes Employees’ Learning From Failure in the Chinese Context | Frontiers in Psychology](https://www.frontiersin.org/articles/10.3389/fpsyg.2021.725277/full) 

[How to Overcome Your Fear of Making Mistakes | Harvard Business Review](https://hbr.org/2020/06/how-to-overcome-your-fear-of-making-mistakes) 

[The Psycholog of Human Error | EduBirdie](https://edubirdie.com/blog/the-psychology-of-human-error)

[Insider Threat Mitigation Guide | CISA](https://www.cisa.gov/sites/default/files/publications/Insider%20Threat%20Mitigation%20Guide_Final_508.pdf) 

[Strategies for Learning from Failure | Harvard Business Review](https://hbr.org/2011/04/strategies-for-learning-from-failure) 

[Your Employee Messes Up: How Do You Respond? | SHRM](https://www.shrm.org/resourcesandtools/hr-topics/employee-relations/pages/employee-mistakes.aspx) 

[Human Error](https://shardsecure.com/blog/tag/human-error)

## Read on

![](https://shardsecure.com/hubfs/Picture2.jpg)

June 15 2026

### [ShardSecure MCP Secure Gateway](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

[Read more](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

February 18 2026  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Unstructured Data Left Exposed: A Cloud Breach That Should Worry Every Enterprise](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

[Read more](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

November 12 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Can You Really Trust Hyperscalers with Your Data at Rest?](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

[Read more](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Acronis%20and%20ShardSecure%20unveil%20a%20groundbreaking%20technology%20partnership%20set%20against%20a%20backdrop%20of%20a%20sleek%20modern%20office%20filled%20with%20digital%20screens%20displaying%20dynamic%20data%20flows%20The%20atmosphere%20buzzes%20with%20excitement%20and%20anticipation%20illuminated%20by%20sof-1.png)

October 16 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Acronis + ShardSecure: Stronger data protection for modern threats](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

[Read more](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20portrays%20a%20hightech%20digital%20landscape%20filled%20with%20abstract%20representations%20of%20data%20security%20concepts%20At%20the%20forefront%20a%20glowing%20vault%20symbolizing%20advanced%20filelevel%20encryption%20stands%20tall%20surrounded%20by%20intricate%20patterns%20of%20fragmented%20data.png)

October 1 2025  | [Data Sensitivity](https://shardsecure.com/blog/tag/data-sensitivity)

### [Revolutionizing Data Security: How Agentless File Level Encryption Makes Stolen Data Useless](https://shardsecure.com/blog/sensitive_data)

[Read more](https://shardsecure.com/blog/sensitive_data)

![unstructured data](https://shardsecure.com/hubfs/Digital%20image%20of%20globe%20with%20conceptual%20icons.%20Globalization%20concept.jpeg)

September 15 2025  | [Cybersecurity News](https://shardsecure.com/blog/tag/cybersecurity-news)

### [Elevating unstructured data security: ShardSecure® and Entrust® Join Forces!](https://shardsecure.com/blog/entrust_partnership)

[Read more](https://shardsecure.com/blog/entrust_partnership)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/scales%20%20ransomware%20attack%20to%20pay%20the%20money%20or%20risk%20the%20attack.jpeg)

July 29 2025  | [Ransomware](https://shardsecure.com/blog/tag/ransomware)

### [CISOs on Strategic Considerations in Ransomware Response](https://shardsecure.com/blog/ransomware-fine)

[Read more](https://shardsecure.com/blog/ransomware-fine)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Image%20for%20AI%20data%20types-1.jpeg)

July 29 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [The Growth of AI is driving the Imperative of Securing Unstructured Data](https://shardsecure.com/blog/ai-unstructured-data)

[Read more](https://shardsecure.com/blog/ai-unstructured-data)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20hightech%20digital%20landscape%20showcasing%20a%20sleek%20modern%20office%20environment%20illuminated%20by%20soft%20blue%20and%20white%20lighting%20In%20the%20foreground%20a%20large%20computer%20screen%20displays%20intricate%20graphs%20and%20charts%20related%20to%20data%20security%20while%20a%20gr.jpeg)

July 22 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [How to make your SharePoint data of zero value in a zero day attack!](https://shardsecure.com/blog/sharepoint_breach)

[Read more](https://shardsecure.com/blog/sharepoint_breach)

[![ShardSecure®](https://shardsecure.com/hubfs/ShardSecure%20brand%20assets/Logo%20(2022)/ShardSecure-Logo__Horizontal--White.svg "ShardSecure®")](https://shardsecure.com/)

101 Avenue of the Americas, 9th Floor, New York, NY 10013, United States of America

[![linkedin](https://shardsecure.com/hubfs/_2023/li.svg) ](https://www.linkedin.com/company/shardsecure) [![tweeter](https://shardsecure.com/hubfs/_2023/tweeter.svg) ](https://www.twitter.com/ShardSecure) [![facebook](https://shardsecure.com/hubfs/_2023/facebook.svg) ](https://www.facebook.com/ShardSecure/) [![facebook](https://shardsecure.com/hubfs/_2023/youtube.svg) ](https://www.youtube.com/@shardsecure877)

© 2026 ShardSecure®. All rights reserved.   
[Privacy Policy](https://shardsecure.com/privacy-policy)

![websights](https://ws.zoominfo.com/pixel/62e7bb6d62a6b2008e071c83) ![](https://px.ads.linkedin.com/collect/?pid=5456580&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "ShardSecure",
    "url" : "https://shardsecure.com/blog/author/shardsecure"
  },
  "dateModified" : "2024-04-05T22:04:10.514Z",
  "datePublished" : "2022-12-12T12:00:00.000Z",
  "headline" : "Did I Do That? On Security Errors, Fear, and Shame",
  "image" : [ "https://shardsecure.com/hubfs/ShardSecure_Risk.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://shardsecure.com/blog/on-security-errors",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://shardsecure.com/hubfs/ShardSecure-Logo__Horizontal--Purple-Inverted.svg"
    },
    "name" : "ShardSecure"
  }
}
```