Movies present hackers as smart individuals using advanced technology to infiltrate a company. But the sobering reality is that they consistently exploit a vulnerability that technology alone cannot patch — the human element.
According to Verizon, the US telecom giant, approximately 90% of breach incidents begin with a social engineering attack targeting a human victim. This statistic may lead you to believe humans are the weakest link in your cybersecurity strategy, but the truth is quite the opposite.
Why people are your most important security control
With over 989,000 unique phishing attacks detected in the final quarter of 2024, the obvious answer is to reduce dependence on humans and use artificial intelligence (AI) to prevent these attacks. But automated systems have limitations that make employees a more efficient first line of defence:
-
AI lacks human intuition: Fully automated security systems are designed to recognise patterns, making them great at detecting system-level threats. But they lack human intuition and context to identify personalised social engineering attacks.
-
AI can't look for novel threats: Even when they're trained to perceive attacks, automated systems can only detect what they’ve been programmed to look for. Any new social engineering tactic may go unidentified until damage is done.
-
AI can only detect, not protect: Automated security tools usually only alert you to a potential threat. Security professionals are still needed to analyse the data, determine a genuine risk, and decide on next steps.
These limitations clearly show that a human-centric cybersecurity approach is still the best firewall available to a business.
Building ongoing training and awareness programmes
Organisations often treat security training as a yearly checkbox exercise. But that won’t work for a people-centric security strategy, which makes cybersecurity every employee’s responsibility.
Create continuous training programmes
A 2024 survey found that yearly training programmes are not enough to reduce the probability of employees clicking on phishing links. What does help is continuous learning programmes held every quarter. This cadence reinforces cybersecurity training protocol while also updating employees on the latest threats. Monthly phishing simulations can also keep cybersecurity top of mind throughout the year.
Adapt training programmes for new threats
In their 2025 Global Threat Report, CrowdStrike revealed that 26 new cyber threats were introduced the previous year. To ensure training remains effective, regularly update your programme to reflect the current threat landscape. Track the latest threats through cybersecurity groups, threat reports, or external vendors. You can also send out security tip newsletters regularly to your employees with the latest cybersecurity news.
Customise training to professional responsibilities
A one-size-fits-all cybersecurity training programme won’t work in most cases, as it overloads employees with unnecessary information that doesn’t pertain to their jobs. By narrowing the scope to cover role-specific scenarios, you can ensure training is relevant, practical, and relatable. The SANS Institute agrees - targeted simulations and coaching resulted in a 35% reduction in repeat clickers, with fewer costly incidents, faster detection, and reduced IT workload.
How to navigate jurisdictional variations in cybersecurity risks
Cybersecurity regulations vary across different countries and regions, affecting security policies and employee training. Mid-market companies should be mindful of these variations to ensure security awareness efforts are compliant and effective.
Regional considerations around cybersecurity regulations
In many industries, security awareness training is a mandatory requirement. But the exact expectations and emphasis can vary depending on the region. For example, European standards like the General Data Protection Regulation are mandatory, while the National Institute of Standards and Technology’s Cybersecurity Framework in the US is voluntary. This makes it important to augment your global training curriculum to cover local laws and industry regulations. You can conduct regular compliance audits to ensure your training covers current and upcoming laws.
Cultural considerations around cybersecurity regulations
Culture plays a major role in how people communicate, behave online, and even fall victim to cybercrime. For example, phishing attacks in the US usually increase during the holiday season. Stores are running discounted sales, and the fear of missing out on great deals drives buyers to click on even suspicious links.
These cultural nuances also appear in the workplace. Some may question authority, while others may be less inclined to challenge instructions, even if something seems suspicious. Tailoring your course to address these differences can improve its relevance and effectiveness. Multinational companies that implemented culturally adapted security protocols saw a 35% improvement in threat detection and a 45% reduction in response times.
Addressing the cybersecurity skills gap
As of 2024, the global cybersecurity workforce required about 4 million professionals to meet demand. For mid-market firms, bridging this gap is critical to building a strong human defence. Here are some strategies to address cybersecurity skills shortages within your organisation: