Human Error Prevention

Introduction

Encryption and two-factor authentication (2FA) protect sensitive information, but they do not protect against the leading cause of data breaches: human error. Sending a message to the wrong recipient, forgetting to use BCC, or attaching a file with hidden data are simple mistakes that can lead to a data breach even when a message is otherwise sent securely.

The Data Breach Report of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, 2024) recorded 3,332 reports of email sent to the wrong recipient — one of the leading causes behind a record 37,839 data breaches reported in the Netherlands that year, alongside causes such as a typo in the recipient’s domain. Source: Zivver — Record number of data breaches in the Netherlands.

Human Error Prevention is a set of business rules designed specifically to help your employees avoid these mistakes at the moment they send a message. It complements the business rules described in Business rules in Zivver, which secure messages based on their sensitive content, by also checking how a message is sent — its recipients, attachments, and addressing.

We recommend enabling all five Human Error Prevention rules at the Suggestion level. At this level, employees only see a purely informational, awareness-raising notification: they are alerted to a possible mistake but can proceed directly with sending — without the mandatory confirmation used by some other business rules. Read more about security levels in Business rules in Zivver.

The five Human Error Prevention rules

Prevent wrong auto-completed recipients

Warns senders when they are about to send a message to a recipient they do not usually correspond with. This works based on machine learning: it doesn’t just look at the recipient’s name, but also at how often and how recently the sender has emailed them, and at the composition of the full recipient list.

Example notification: “Check whether the recipient is correct — did you mean firstname.lastname@gmail.com instead of example.lastname@gmail.nl?”

Prevent sending to personal email

Warns senders when they try to send a message with an attachment from their work email address to their own personal email address.

Example notification: “Please remove your personal email address — it looks like you’re sending this message to your personal email, which is not allowed under your organization’s policy.”

Typo in email domain

Warns senders when they make a typo in a recipient’s domain, for example sending to hotmail.con instead of hotmail.com.

Example notification: “Check for typos in the email address — the domain spelling of …..@gmail.con appears to be incorrect.”

Detect hidden data in spreadsheets

Warns senders when hidden rows, columns, or sheets are detected in an .xls, .xlsx, .xlsm, or .ods file.

Example notification: “Check the data in the attachment — the spreadsheet [filename] contains hidden data in [sheet name, row/column; (if multiple locations) sheet name, row/column] that you may not be aware of.”

Consider using BCC

Advises senders to move recipients to BCC when 10 or more external recipients are placed in the To or CC field.

Example notification: “Move recipients to BCC — 10 external recipients will see each other’s contact details. Move them to BCC to protect their privacy.”

How to enable Human Error Prevention rules

You enable and configure Human Error Prevention rules the same way as any other business rule:

  1. Log in to the Zivver WebApp.
  2. Click Organization Settings.
  3. Expand Policies.
  4. Click Business rules.
  5. Find one of the five rules described above.
  6. Enable the rule.
  7. Set its security level to Suggestion.
  8. Repeat steps 5–7 for the remaining four rules.

For general guidance on setting up and fine-tuning business rules, see Business rules in Zivver.

Use cases

  • Wrong recipient: An employee’s mail client autocompletes an address, inserting a similarly named but incorrect contact. Human Error Prevention flags the mismatch with the employee’s usual recipients before the message is sent.
  • Personal email: An employee wants to keep working from home and forwards a work document to their personal email address. Human Error Prevention flags the policy violation before the message goes out.
  • Domain typo: An employee types hotmail.con instead of hotmail.com. Human Error Prevention flags the invalid domain, preventing the message from being misdelivered or bounced.
  • Hidden data in spreadsheets: An employee shares a spreadsheet export that still contains hidden columns with salary or other internal data. Human Error Prevention flags the hidden content before the message is sent.
  • Large recipient list: An employee emails a group of 15 external contacts using the To field, exposing everyone’s address to each other. Human Error Prevention suggests moving the recipients to BCC.

Questions

If you have any questions about Human Error Prevention, contact your Customer Success Manager or email customer.success@zivver.com.