Key Takeaways
- Cyberattacks and data breaches are accelerating, threatening New Jersey residents, public institutions, and private businesses.
- Human error drives the vast majority of incidents— ≈ 95 % of 2024 breaches stemmed from employee actions, not technology flaws.
- Phishing and related social‑engineering tactics (email, smishing, vishing) remain the most prevalent and costly attack vectors, with business‑email compromise accounting for a large share of losses.
- Regular, targeted cybersecurity awareness training can cut employee susceptibility by up to 80 % and create a proactive “human firewall.”
- Effective defense requires collaboration across state agencies, private organizations, and leadership—not just IT teams.
- Governor Mikie Sherrill’s administration should institutionalize mandatory, ongoing cybersecurity education, strengthen public‑private partnerships, and launch statewide awareness campaigns to build a resilient cyber culture.
Escalating Threat Landscape in New Jersey
Cyberattacks and data breaches are rising at an alarming pace, expanding the threat landscape and jeopardizing the safety, privacy, and economic stability of New Jersey residents and the organizations that serve them. High‑profile incidents illustrate the scope: a November phishing scam breached a Princeton University database, potentially exposing personal data of over 100,000 individuals, while an October 2024 breach at Conduent Business Services disrupted state agencies and insurance providers. The New Jersey Cybersecurity and Communications Integration Cell warns that attacks on public institutions, private companies, and residents will continue to grow in both volume and impact, underscoring the need for urgent, coordinated action.
Global Trends Highlight Local Urgency
Worldwide, more than 12,000 breaches were disclosed across 139 countries in 2024, according to the 2025 Verizon Data Breach Investigation Report. These figures reinforce the urgency for Governor Mikie Sherrill to prioritize cyber resilience and awareness on her agenda. The scale of incidents demonstrates that cyber threats are not isolated events but a persistent, systemic challenge requiring sustained attention and resources from state leadership.
The Human Factor: Employees as Both Vulnerability and Defense
Employees remain the weakest link in cybersecurity. The Mimecast State of Human Risk Report attributed 95 % of data breaches in 2024 to human error, far outweighing vulnerabilities in technology itself. This statistic does not imply that workers are indifferent or incompetent; rather, it highlights the necessity of comprehensive training, strong policies, and robust security tools to mitigate preventable risks. When properly educated, employees become the backbone of a strong cybersecurity ecosystem, capable of recognizing and thwarting threats before they cause harm.
Phishing and Social‑Engineering: The Dominant Attack Vectors
Phishing attacks and related scams continue to be one of the most persistent and damaging cyber threats. Delivered primarily via email, these schemes trick individuals into clicking malicious links, downloading harmful attachments, or divulging confidential information by exploiting social engineering—manipulating trust, urgency, fear, or curiosity. The financial toll is staggering: businesses reported $2.9 billion in losses from phishing in 2023, with an average loss of $137,132 per incident, according to the FBI Internet Crime Complaint Center. Business‑email compromise, a subset of phishing that impersonates trusted parties to induce unauthorized payments or data disclosure, accounted for 73 % of cyber incidents in 2024, per Hoxhunt. Approximately 70 % of organizations have faced social‑engineering attempts, with manufacturing (27 %), energy (23 %), retail (10 %), utilities (7 %), and real estate (6 %) among the most frequently targeted sectors. The pervasive nature of these attacks proves that no industry is immune, making awareness training essential across the board.
Building a Collaborative Human Firewall
As Steve Jobs observed, “Great things in business are never done by one person. They are done by a team of people.” This principle applies directly to cybersecurity: protecting New Jersey’s digital assets demands collaboration among state agencies, private organizations, and senior executives, not just IT professionals. Cybersecurity awareness training serves as the foundation of this collective defense. Programs that simulate phishing and teach employees to recognize suspicious links, maintain strong passwords, and report anomalies have reduced employee susceptibility by as much as 80 %, according to CyberPilot. Well‑trained staff act as a proactive “human firewall,” forming the first line of defense against threats, a concept highlighted in research from the University of Albany titled Behind the Screen: Understanding the Human Firewall in Cybersecurity.
A Call to Action for Governor Sherrill’s Administration
Drawing on firsthand experience as a technologist, I assert that New Jersey’s stability hinges on prioritizing cybersecurity resilience and awareness. Governor Mikie Sherrill has both an opportunity and an obligation to confront the escalating threat landscape with urgency and intention. This begins by making cybersecurity awareness training mandatory—not optional—across all state agencies and strongly encouraging its adoption throughout the private sector. Employees cannot prevent or report threats they do not recognize; purposeful, ongoing, and accessible education is critical to preparing the workforce. The state should consider establishing baseline training standards, expanding public‑private partnerships, and launching statewide awareness campaigns that foster a culture of cyber vigilance.
Conclusion: Toward a Resilient, People‑Centered Cyber Future
New Jersey deserves a comprehensive, people‑centered approach to cybersecurity. With decisive leadership, sustained investment in education, and collaborative effort across sectors, Governor Sherrill can ensure that the state is not only forewarned but also forearmed against cyber threats. By elevating cybersecurity awareness to a core component of the state’s resilience strategy, New Jersey can protect its residents, safeguard its businesses, and maintain the trust and stability essential for continued prosperity. The time to act is now—through informed, empowered individuals, we can build a digital environment that is secure, resilient, and ready for the challenges ahead.

