Why we should stop trying to upgrade people and start designing systems around how humans actually behave.
Every October, Cybersecurity Awareness Month arrives, and with remarkable consistency we hear the same statement: “Humans are the weakest link in cybersecurity.”
We have repeated it for so long that it has almost become a law of cybersecurity but what if we have it backwards? Perhaps the real weakness is that we keep designing security systems that expect humans to behave like computers. And that approach has one obvious problem: Humans don’t have Patch Tuesday.
There is no HumanOS 26.1. We cannot push a security update overnight, reboot everyone before breakfast and expect eight billion people to wake up with improved phishing detection. At least, not yet.
Cybersecurity has historically tried to solve human risk by changing the human. The instructions are familiar: Don’t click. Don’t trust. Check the sender. Inspect the URL. Check the QR code. Use another password. Make it complex. Add a number, a symbol, perhaps a hieroglyph. And whatever you do, don’t write it down.
Then Monday morning arrives. You have 29 unread chat messages, 78 new emails, three meetings starting simultaneously and somebody urgently needs an invoice approved. And we wonder why somebody clicks. The problem is not that humans are defective computers. The problem is that humans are not computers.
Technology advances extraordinarily quickly. Human biology does not. We are walking around with brains shaped over hundreds of thousands of years, using them to interact with cloud platforms, generative AI, QR codes, synthetic voices and deepfakes.
Our brains are remarkably good at interpreting social signals: we recognise authority, respond to urgency, trust familiar faces and react when somebody appears to need help.
These characteristics were extremely useful long before anyone invented email.
Call it the chimp brain. It was built for a world where the biggest threat was a predator in the tall grass and the safest strategy was to obey the loudest voice in the tribe. An email from “the CEO” marked URGENT is that voice, in HTML.
Unfortunately, those same instincts also make excellent ingredients for social engineering. The attacker is no longer merely trying to exploit Windows.
The attacker is exploiting trust, curiosity, fear, authority and urgency. And unlike Windows, those characteristics cannot simply be patched.
Consider how often you click something during an ordinary working day: links in email, chats and messages, documents, search results, calendar invitations, QR codes, notifications, websites. We click hundreds of times because clicking is how modern work gets done.
Then cybersecurity presents someone with an exceptionally convincing malicious link and says: “You should have known not to click that one.” That is a rather extraordinary security architecture when you think about it.
Organisations invest millions in firewalls, endpoint protection, threat intelligence, email security and monitoring. Yet the entire defence can still depend on whether Dave in Accounting recognises one convincing email at 16:47 on a Friday. So, the question shouldn’t only be: “Why did Dave click?” We should also ask: “Why did we design the system so that Dave’s click could have that consequence?”
Yes, breach reports regularly show that a large share of incidents involve a “human element”. That is not proof that humans are weak. It is proof that we built systems in which a single human moment can decide the outcome.
Security awareness and education matter, and people should understand risk. But helping people make better decisions is different from expecting them to compensate for poor technology and poor process design.
We should not try to turn every employee into a malware analyst. A finance specialist should be excellent at finance, a nurse at caring for patients, an engineer at engineering. None of them should need five years of threat-intelligence experience before opening their inbox. Good security should make the safe action easier than the unsafe one. Easy to the right thing and hard to the wrong thing is a good guiding principle. At the same time, removing any temptations to do the wrong thing while we are at it.
Public health learned this long ago. We didn’t defeat cholera by blaming people for drinking the water; we built clean water systems. The weakest defence is always the one that depends on everyone behaving perfectly, every time, all the time. Security awareness is the hand-washing of cybersecurity: valuable, but it should never be the only thing between Dave and the outbreak.
Some organisations still close an incident report with two words: “human error”. I have read countless media articles stating “it was the human factor”. Aviation moved beyond that after decades of hard lessons. When an aircraft is lost, investigators treat the pilot’s mistake as one link in a chain and keep asking why: why was the situation confusing, why did the alert fail, why did the procedure, the training or the interface allow it? Safety scientists call it the Swiss cheese model: harm happens when the holes in several layers line up. In a just culture, mistakes and near misses are reported openly, because those reports save lives.
Now imagine your captain clicks a link promising a free upgrade to first class on the next personal flight, and the aircraft is lost. Nobody would call that pilot error. We would call it a design failure, because aircrafts are built on the assumption that people make mistakes: two pilots, checklists, cross-checks, redundant systems, alarms.
Yet in cybersecurity, a single click by a single person can still bring down an entire organisation, and we call it the user’s fault. “Human error” is a symptom, not a diagnosis.
Passwords demonstrate the problem beautifully. For years, we asked people to create passwords containing uppercase letters, lowercase letters, numbers, symbols and seemingly the blood type of their first pet.
Then we told them: Use a different one everywhere. Never write them down. Remember all of them. Change them regularly. And when people struggled, we concluded: Humans are bad at passwords. Perhaps. Or perhaps passwords were bad at humans.
The better response has been to change the technology: password managers, multistep verfication and increasingly passkeys.
In other words, instead of upgrading the human, we upgraded the system. That principle should extend far beyond access controls.
Strictly speaking, we are already cyborgs. Not through surgery, but through habit. The phone in your pocket is your memory, your map, your wallet, your identity and your second factor. Lose it and you lose part of yourself. Today we have tech implants but we are still very far from downloading Excel skills directly into the brain or installing Cybersecurity Awareness Training 27.2 while employees sleep. The realistic near-term risks are less theatrical.
People don’t only cause incidents. People detect them. People question unusual transactions, notice behaviour that doesn’t make sense, recognise context machines may miss, improvise during crises, report suspicious messages and make judgement calls when rules and algorithms fail.
That is not weakness. That is resilience. Technology is extraordinarily good at processing information. But cybersecurity operates in a world of ambiguity, context and incentives, and humans remain remarkably capable of navigating it.
The objective should therefore be neither to remove humans from cybersecurity nor to “fix” them.
The objective should be to build security and system design around how humans actually behave, rather than around an imaginary perfectly rational user who never gets tired, distracted, curious, hurried or fooled.
Security architecture should assume humans will occasionally click. Processes should assume people will occasionally make mistakes. Technology should limit the consequences.
And organisations should create cultures in which people report mistakes quickly rather than hide them because they fear being labelled the weakest link.
Perhaps we have spent too much time asking: “How do we make humans behave more like secure computers?”The better question may be: “How do we make computers work more securely for humans?”
Until humans come with expandable storage, downloadable knowledge and automatic security updates, we should probably stop treating them like outdated software.
The human is not something cybersecurity needs to fix. The human is the strongest link we have.