Every year brings a new wave of tooling — better EDR, smarter SIEMs, AI-assisted triage. And every year, the majority of serious breaches still start the same way they did a decade ago: someone clicked a link, approved an MFA prompt out of fatigue, or handed information to someone who sounded like they belonged. Technology raises the cost of an attack. It rarely removes the human decision at the center of it.
Where human awareness matters most
- Phishing and spear-phishing — still the single most common initial access vector across breach reports year after year.
- Social engineering over phone and chat — help-desk impersonation and pretexting bypass technical controls entirely by targeting a person, not a system.
- Physical security — tailgating into secure areas and unattended, unlocked devices remain embarrassingly effective.
- Insider risk — not always malicious; often just a well-meaning employee under pressure, cutting a corner.

Co-published with NexSecure Cybersecurity · Nathaniel T.O, SOC Analyst
Building a culture, not just a training module
Annual compliance training that people click through to get a certificate doesn't change behaviour. What does: short, frequent reminders instead of one long annual session; simulated phishing used to identify where extra support is needed rather than to publicly shame whoever clicked; and — the part most programmes skip — making it easy and low-stigma to report a suspected mistake. A team that's afraid to report a clicked link is a team where that click goes undetected for weeks.
Key takeaways
- Most serious breaches still begin with a human decision, not a technical failure.
- Frequent, low-stakes awareness beats a single annual training session.
- A blame-free reporting culture catches incidents faster than any technical control alone.