Stop Calling Humans the weakest link
Introduction: A category error at the heart of security
Every serious conversation about organisational security eventually arrives at the same conclusion: the human is the weakest link. The phrase has become so familiar it has stopped prompting scrutiny. It is cited in board papers, embedded in awareness training rationales, and used to justify the billions spent annually on behaviour-change programmes that the evidence suggests are largely ineffective.
The problem is not that humans are reliable and the “weakest link” diagnosis is uncharitable. Humans are not always reliable, not under pressure, not in the presence of sophisticated manipulation, not when exhausted or distracted or operating inside institutional cultures that prioritise speed over caution. The problem is that "weakest link" is a static descriptor applied to a dynamic variable. Human behaviour is not a fixed property of individuals; it is a product of the environments, incentives, cognitive states, and social contexts in which those individuals operate. Treating it as a fixed state leads to the wrong interventions, and crucially, allows the structural conditions that produce unsafe behaviour to go unexamined.
This article examines what a rigorous human risk management perspective reveals about the security industry's dominant assumptions: about training, about technology, about measurement, and about where the locus of responsibility should actually sit. Its argument is not that humans do not matter to security outcomes. It is that we have been trying to solve the wrong problem and that solving the right one requires a fundamental reorientation, from individual deficit to system design.
I. The limits of the awareness model: Why training has not worked, and why AI will not fix it
The dominant model of human security risk management is built on an intuitive but empirically fragile assumption: that if people know what threats look like and understand the consequences of falling for them, they will behave more securely. Decades of investment in awareness training: phishing simulations, annual compliance modules, security culture surveys has produced organisations where staff can describe social engineering accurately and yet still click on well-crafted malicious links in real conditions. The knowing-doing gap is not a training design failure. It is a fundamental feature of human cognition under pressure.
Awareness training was conceived for a threat environment in which the signals of deception were detectable with reasonable effort: mismatched sender domains, grammatical irregularities, improbable requests. That environment no longer exists. AI-generated content eliminates most of the surface cues that training was designed to teach people to spot. Deepfake audio and video go further still, attacking not only knowledge but also perception, a cognitive layer that training cannot meaningfully reach. You cannot train the human perceptual system to defeat a well-constructed deepfake in a real-time, emotionally charged interaction. The cognitive load is too high, the time horizon too short, and the social pressure too potent.
AI does not make the human problem worse in the sense that humans have become less capable. It makes the manipulation problem worse - the attacks have become better targeted, more plausible, and more precisely calibrated to the cognitive shortcuts that humans reliably use.
The appropriate response to this problem is not better training. It is a structural shift from detection-based to process-based security. When the question "is this real?" cannot be reliably answered in real time, the security system must not depend on the answer. Secondary verification channels, mandatory approval thresholds, normalised challenge cultures, these are not supplements to awareness; they are substitutes for it at exactly the points where awareness fails.
This conclusion extends to the current enthusiasm for AI-driven adaptive learning platforms. The technology is genuine and some of the capability claims are credible: personalisation at scale, just-in-time interventions, behavioural risk scoring, continuous rather than periodic engagement. But the value of these tools is almost entirely conditional on variables the technology itself cannot address. A micro-intervention delivered immediately after a simulated phishing failure is cognitively sound in principle. But in a culture where mistakes carry blame, it will reliably produce shame and concealment rather than learning. An AI system deployed in a psychologically unsafe environment will teach people to game its metrics, not to behave differently. The technology amplifies the culture it is placed in; it does not replace it.
II. The structural problem: When the environment makes unsafe behaviour rational
If training is an inadequate primary intervention, what explains the industry's sustained investment in it? Part of the answer is that training is measurable, auditable, and satisfying to procure. Completion rates can be reported to boards. Phishing click rates can be graphed over quarters. The paper trail is legible, which makes it defensible, even when it is not effective.
The structural conditions that actually produce unsafe human behaviour are harder to quantify and considerably less comfortable to address, because they implicate the organisation rather than its individuals. These include (but are not limited to): Role ambiguity about who is responsible for security decisions. Performance management systems that reward speed and penalise caution. Access architectures that give employees vastly more privilege than their roles require. Workflow designs in which the secure path is slower, more effortful, and more socially costly than the insecure one. These are the conditions under which unsafe behaviour becomes locally rational, the individually sensible response to a badly designed environment.
Mandatory multi-factor authentication outperforms any volume of password hygiene training because it removes the behavioural decision from the human layer entirely. The most powerful security interventions are environmental, not educational.
This is the central insight of human risk management as a discipline: behaviour is a product of systems, not just of individuals. If the friction-free path is the insecure path, training will not change that, it will be overridden the moment a deadline approaches or a senior figure signals that process can be bypassed. Conversely, organisations that redesign their environments to make secure behaviour the path of least resistance produce better outcomes – not because their people are better trained but because their people are being asked to do something achievable within the conditions they actually face.
The underestimation of structural failure is not merely an analytical error. It has a cost. Organisations that attribute security incidents to individual lapses - to the employee who clicked, the contractor who used a weak password, systematically fail to examine the systemic conditions that made those lapses likely and consequential. The individual carries the blame; the environment that produced the incident goes unreformed.
III. Measurement and culture: What genuine behavioural change looks like, and who has to model it
Security programmes are typically evaluated on metrics that are easy to collect and poorly predictive of actual risk: training completion rates, simulated phishing click rates, compliance attestations. These measure exposure to training stimuli and performance in controlled conditions. They do not measure the behaviour that matters, what employees actually do when facing real uncertainty, real time pressure, and real social context.
Genuine behavioural indicators look different. Unsolicited reporting rates - how often people flag suspicious activity they were not prompted to report, tell you something about psychological safety and felt responsibility. Near-miss disclosure rates tell you whether the culture treats close calls as learning opportunities or liability events. The speed and frequency of verification requests in live interactions tells you whether challenge culture has been genuinely normalised or merely endorsed in policy. These metrics are harder to collect and impossible to manufacture through compliance exercises, which is precisely why they are more informative.
The most significant single predictor of security culture, however, is not any metric that training programmes generate. It is leadership behaviour. Research on organisational culture is unambiguous on this point: people at all levels of an organisation take their behavioural cues not from policy statements but from what they observe leaders actually doing under pressure. An executive who bypasses two-factor authentication because it is inconvenient, who authorises a payment outside the approval process because a client is waiting, who treats security protocols as obstacles for other people, that executive has done more damage to the organisation's security posture than any number of sophisticated attacks could achieve alone.
Boards and senior leaders should be driving security culture change, not having it done to them. The gap between endorsing a training programme and modelling the behaviours it teaches is where most security culture initiatives quietly fail.
This has direct implications for where security investment should be directed. The marginal return on the fifteenth hour of annual awareness training for front-line staff is low. The return on a serious programme of leadership behaviour change, where senior figures understand that they are the most visible signal in the system, and act accordingly, is considerably higher and almost entirely neglected.
IV. Reframing the problem: From human deficit to system design
The question of whether to focus on educating users or designing systems that are secure despite user behaviour is often framed as a choice between idealism and pragmatism. It should be framed as a risk allocation question. What decisions genuinely need to remain with humans? For those decisions, invest in the conditions; psychological safety, clear authority, adequate time, that allow humans to make them well. What decisions can be removed from human discretion, or can have their consequences bounded by technical controls? For those, design them out of the human layer.
This is human-appropriate security: not the abandonment of human-centric thinking, but its honest application. Humans are reliably good at contextual judgement, pattern recognition across ambiguous signals, and social verification. They are reliably poor at sustained vigilance, real-time adversarial content detection under time pressure, and resisting sophisticated authority-based manipulation. A security architecture that asks humans to be good at the things they are reliably bad at is not a human-centric architecture. It is a liability architecture dressed in training brochures.
The final reframing concerns the question of whether humans are the primary attack vector. They are, but not because there is something deficient about the humans. Attackers target humans because the return on investment is high: social engineering is cheaper than technical exploitation, more reliably scalable, and more precisely tuneable to individual vulnerabilities. The appropriate response is not to make humans more resistant to attacks tht they cannot reliably detect. It is to reduce what a successfully attacked human can access, increase the cost to attackers of achieving exploitation at the scale their economics require, and build organisational systems that contain and surface incidents quickly rather than depending on humans to prevent them entirely.
V. Conclusion:Five Findings and a Single Imperative
Human behaviour is a variable shaped by environment, not a fixed property of individuals. Security programmes that treat it as fixed will optimise for the wrong things.
Awareness training cannot bridge the gap between knowing and doing under pressure, and AI-generated threats have eliminated many of the surface signals that training was designed to teach. Process-based controls are more reliable than detection-based ones at exactly the moments that matter.
The structural conditions that make unsafe behaviour locally rational, poor access architecture, competing incentives, friction-free insecure paths are systematically underweighted relative to training investments. Environmental design outperforms education at scale.
Genuine security culture is produced by leadership behaviour, not policy endorsement. The most important security investment most organisations are not making is senior leader behaviour change.
The right question is not how to make humans more resistant to attacks they cannot reliably detect. It is how to make human exploitation less economically attractive to attackers through access limitation, rapid detection, and resilient containment.
The imperative that follows from these findings is not to abandon investment in people. It is to invest in the conditions under which people can actually succeed, and to stop using training as a substitute for the harder, more expensive, more organisationally disruptive work of building systems that do not depend on human perfection to remain secure.
This article was first published On the RISCS website. Penny is a an Advisory Board Member for RISC. The Research Institute for Sociotechnical Cyber Security (RISCS) University of Bristol