Why Humans Are Still the Weakest Link in Cyber Security

Despite the power of many modern cyber security tools like firewalls, AI threat detection and encryption architectures, most cyber incidents still begin with a human action. Whether it’s a phishing email that seems a little too real, or a password that hasn’t been updated in 2 years, these invisible cracks are chinks in your organisations armour, just waiting to be exploited.


The misconception: Technology alone can solve cyber risk

Organisations often assume third-party tools will entirely protect them from cyber attacks, but that just simply isn’t true. These tools are extremely beneficial, but they stand like a tall gate. Sure, no one can get in if the gate is closed, but if a human error opens that gate, it can and will lead to disaster.

Humans are not the problem, but they are the target. According to CISA, 90% of successful cyber attacks start with a phishing email. Phishers often imitate a trusted webpage or email address, designed for you to input sensitive data to then breach into the belly of your organisation.

In the past, phishing emails were pretty weak attempts at breaching systems, but modern tools like AI have made them far more dangerous, they can imitate trusted sites with ease and even ascertain key information about your business, further validating themselves in your eyes.


How humans are exploited: The main risk areas

Social Engineering

As mentioned earlier, phishing remains the most common tool for cyber breaches. This kind of attack is also known as ‘social engineering’, an example of this might be your CEO sending you an email asking you to run to the shops to get Apple gift cards. Through social aspects like emotional manipulation, urgency, authority or familiarity, you can be convinced to do things you wouldn’t usually do.

Password Behaviour

Many people never update their passwords unless made to. This practice can be very harmful as passwords can be compromised in third-party data breaches. Additionally, the act of reusing passwords across multiple gateways can mean that one breach will lead to more. Ensuring you maintain good password hygiene and change passwords regularly is very important.

Remote and Hybrid Working

With the rise of remote or hybrid working structures, people are using their own devices more than they would in the office. These home devices may not have the same levels of firewalls or threat detection as work laptops do, meaning that malicious sites can fly under the radar.

Fatigue and Cognitive Overload

When work gets busy, it is easy for these practices to become ‘background noise’. That isn’t to say that people get careless, simply that when you are tired, strained or overworked, you are less attentive to potential risks.


Why training alone isn’t enough

Training is naturally an excellent tool for increasing awareness, but often these become annual tick-box exercises, done for compliance more so than anything else. This leads to disengagement. Emphasising culture, leadership behaviour and continuous reinforcement are far more effective than simple training exercises. Instead of making it a once-a-year event, have cyber security become ingrained in the daily practices of your work.


Finding this useful? This is just a slice of the excellent information available at the Public Sector Cyber Security Conference, on the 5th February in Westminster, London. Attendance is free. Click-through to see the incredible line-up of speakers and sponsors at the event. We look forward to seeing you there!


Reframing the solution: Designing for humans

We believe that “human error” needs to be shifted to “human-centred security” through practices like:

Clear Reporting Processes

Changes to your organisation to ensure that there are clear reporting processes will allow people to feel comfortable in the process of reporting potential cyber attacks and phishing attempts. It also allows for open conversation between staff on what threats they discover.

Non-Punitive Cultures

Creating environments where people aren’t afraid of punishments will make staff more likely to not fear punishment when reporting accidents they might have made. It is all about accepting that mistakes happen, as we are all human. It is more important that these reports are made so actions to protect the organisation can be made.


Ultimately, cyber security cannot be solved by technology alone. As long as people are part of organisations, they will remain at risk. The goal should not be to eliminate human involvement, but to design systems, processes and cultures that actively support secure behaviour.

When organisations move away from blame and towards clarity, simplicity and trust, staff become a powerful first line of defence rather than a perceived weakness. By recognising humans as part of the solution, not just the problem, cyber security can become stronger, more realistic and far more effective.

The Public Sector Cyber Security Conference 2026 will explore workplace culture, alongside AI integration, supply chains and women in cyber. Attendance is free, we’d love to see you there.

Related Resources