A human approach to making cybersecurity stronger

One of my first cybersecurity roles focused on awareness and it taught me that cybersecurity is as much about behaviour, communication, and culture, as technology. Human judgement matters.

For me, effective human cyber resilience comes down to three things: understand human risk; stop blaming people for mistakes; and create an environment that enables good judgement.

The human risk landscape is changing

The 2026 SANS Security Awareness & Culture Report shows how human cyber risk is evolving. Social engineering remains the leading risk at 77 per cent, followed by inappropriate workplace AI use at 42 per cent, sensitive data mishandling at 39 per cent, and weak passwords or authentication at 22 per cent.

These findings matter because the leading risks increasingly involve human judgement, behaviour, and the way we use technology.

Social engineering targets judgement. Phishing, vishing, smishing, impersonation, and deepfake frauds create conditions where capable people can make the wrong decision. Attackers exploit trust, urgency, and uncertainty to bypass the checks people normally make, while technologies such as Artificial Intelligence (AI) are making their methods increasingly convincing.

Defending against this requires more than teaching people to recognise suspicious links. Verification, questioning and reporting need to become normal security behaviours.

Inappropriate AI use presents the same challenge. People often adopt AI to work more efficiently, not to cause an incident. Risk emerges when useful technology meets unclear policies, limited understanding, or weak governance.

The answer is not simply to tell people to “know better”. Organisations need approved tools, clear boundaries around information, effective controls and practical guidance. After all, “don’t use AI tools” is unlikely to be a sustainable AI governance strategy.

Technology can block and detect; policy can establish boundaries. But when neither has anticipated a particular situation, the organisation may depend on something that’s harder to automate: good human judgement.

Stop blaming people

Research published in the Journal of Risk Research in 2025 links many serious  cybersecurity incidents with human behaviour and calls for greater attention to risk perception, uncertainty, decision making and communication.

People don’t make security decisions in isolation. They make them while doing their jobs, often under pressure, with competing priorities and incomplete information. Attackers understand this and exploit trust, urgency, and authority to influence behaviour.

This is why describing people simply as the “weakest link” misses the point. BH Consulting’s founder Brian Honan has repeatedly challenged this narrative. If a phishing email reaches an employee after technical controls have failed to stop it, that person is not the weakest link; they may be the last line of defence.

That distinction changes the questions we ask after an incident. Instead of only asking why someone made a mistake, we should ask: did controls work? Was the secure choice clear? Did processes support secure behaviour?

If people repeatedly circumvent a security control, we should also ask why. Controls that create unnecessary friction or make legitimate work difficult can encourage workarounds.

The better question is: how do we create an environment in which people are more likely to exercise good judgement and make secure decisions?

Building judgement, not just awareness

I mentioned before that one of my first cybersecurity roles focused on awareness. In that role, rather than simply assuming people were doing the wrong thing on purpose, I relied on my natural curiosity to understand why some team members engaged in insecure behaviours or circumvented security policies. Was the policy unclear? Was the secure process making their job more difficult? Were they unaware of the risk? Or had they just found a quicker way to get their work done?

Sometimes the answers surprised me. Team members would tell me they had seen their line managers demonstrating the same insecure behaviours and therefore assumed it was acceptable for them to do the same.

It was an early lesson that people take cues from others, especially leaders.

How to develop an effective security policy

I also learned that the best way to develop a security policy is to get out of the secure, double-locked room where the security team works.

Policies and controls need to reflect how people actually work. Involving employees in their design can identify friction, uncover risks that may not be obvious to the security team, and help find solutions that enable people to work securely rather than work around security.

I remember taking what I thought was a creative approach to developing an Acceptable Use Policy (AUP) and asking a team of executive assistants (EAs) for their input on the cybersecurity challenges they and their executives faced. A few coffees later, at my expense, that conversation proved more valuable than asking them to review a draft policy.

Listening to the EAs revealed practical problems we could address. We introduced controls like password managers for high-risk staff while developing longer-term solutions.

My team and I produced a concise, visually appealing, and practical AUP that clearly explained what to do, supported by illustrations of the do’s and don’ts, followed by a short quiz. We delivered the policy on a shoestring budget by drawing on diverse input from departments across the business.

There are good examples of organisations applying this thinking at scale. Barclays placed employees and organisational culture at the centre of its strategy. It developed human risk behaviour metrics and overhauled its approach to awareness and training through its “Smarter Together” campaign, partnering with business leaders to develop and deliver security messages. In 2023, its security, privacy and risk behaviour framework won Forrester’s Security & Risk Enterprise Leadership Award.

This approach was effective because it moves security awareness beyond just delivering training. It recognises that behaviour, leadership and organisational culture are interconnected.

To change cyber behaviour, understand it

I have previously argued that cyber behaviour should be a board-level concern and that cyber strategy, programmes and culture must consider the human element. Technology has changed, but that principle has not.

The objective should be to develop cyber judgement, not simply cyber awareness. People need to understand not only what the rules are, but why they exist, what an attacker may be trying to achieve and when they should stop, question and verify.

Put another way, we need to move from telling people what not to do, to helping them know what to do.

How to develop cyber judgement

  1. Make it relevant. Use realistic, role-based scenarios which mirror the decisions people actually face. Someone authorising payments, managing sensitive information, or administering privileged accounts will face different risks and should have opportunities to think through those situations before encountering them for real.
  2. Practice decision making. Simulations and incident tabletop exercises can help people practice responding to uncertainty. Don’t just teach someone how to identify a phishing email; ask what they would do when an apparently genuine request is urgent, appears to come from someone senior, and asks them to bypass a normal process.
  3. Make verification and reporting easy. Give people simple ways to independently verify unusual requests and clear routes for reporting concerns. Under pressure, memorable behaviours such as stop, think, verify and report are more useful than expecting someone to recall a lengthy policy.
  4. Learn from mistakes and near misses. Instead of only asking what someone did wrong, ask why the decision made sense to them at the time. Was the policy unclear? Did the process create unnecessary pressure or friction? Did a technical control fail? Learning from those circumstances can strengthen both human judgement and organisational resilience.
  5. Lead by example. If managers circumvent controls, employees may feel entitled to do the same. Leaders should demonstrate the same secure behaviours they expect from everyone else, including challenging unusual requests, following verification processes and reporting their own mistakes. This principle also applies to individuals at the top of the food chain.
  6. Foster the right culture: Create a culture where people can speak up. If every mistake is treated as a failure, people may hesitate to report that they clicked on something suspicious or shared information they should not have. That delay can turn a manageable event into a serious incident. Brian Honan’s work reinforces this point. Security awareness should empower rather than shame. Fear is not the same as awareness.

Every October, European Cybersecurity Month provides an excellent opportunity to refresh these activities. Revisit social engineering scenarios, reinforce safe information handling , AI use and reporting processes, and ask where security controls are creating unnecessary friction. But October should also be a refresh point to a long-term cyber culture programme. Use the great resources available from SANS to benchmark your cybersecurity awareness and culture maturity.

Gaining insight into security behaviour: start with why

Sometimes the most valuable insight comes not from another risk dashboard or policy document, but from sitting down with the people responsible for making security work in practice. When people circumvent a policy, understanding why is more useful than repeating the rule or threatening escalation.

Effective cyber resilience requires organisations to understand human risk, learn from mistakes without assigning blame, and enable good judgement.

Technology and threats will continue to evolve, but resilience isn’t built through technology alone. When technical controls reach their limits, preventing an attack may depend on one person recognising that something doesn’t make sense and having the confidence and judgement to act.

Sarah Hipkin is a Senior Consultant with BH Consulting

Why get in touch with BH Consulting

BH Consulting is a trusted, independent cybersecurity and data protection consultancy with over 20 years of experience. Whether you need expert guidance on compliance, risk management, or security strategy, our team delivers practical, vendor-neutral advice tailored to your needs.

Let’s start a conversation about securing your business.

Respect in Security Pledge logo

Areas of interest*