When it comes to cybersecurity, are humans the weakest link? Or the strongest defence?
One careless click can break a system. One sharp instinctive response can save it. So, are we the problem or the solution? In our latest article for Cyber Awareness Month, Johan Helin, Senior IT/Security Engineer at Nexova, reflects on the paradox of humans in cybersecurity.
I’ve always been fascinated by one paradox in cybersecurity: the fact that humans can be both the most fragile and the most resilient part of any system. Early in my career, I was often told that “the human is the weak point”. But with experience, I started to wonder, what if it’s actually the opposite?
Yes, one inattentive click can compromise a network; yet one sharp instinctive response can prevent a full-scale crisis.
Machines may automate detection, but it’s humans who interpret, decide and act.
So, are people the weak link or the most powerful line of defence?
From awareness to instinct
As Emmanuel Nicaise, a Belgian clinical psychologist, points out: too many people or companies remain at the stage of ‘security awareness’. But security awareness itself is often not the problem; rather, it is bad behaviour and the lack of a ‘cyber culture’.
What we want to achieve is a lasting change in user behaviour. Something that people will do without even thinking about it. “Culture is what remains in a person when they have forgotten everything else,” famously said Édouard Herriot, a former French Prime Minister. That’s exactly what we aim for when it comes to cybersecurity: transforming awareness into instinct, so that secure behaviour becomes second nature, not just a rule to follow.
Awareness alone is not enough
Awareness alone doesn’t guarantee behaviour change.
Security awareness among users is only one tool, and probably not the most effective one. We all know that most smokers are aware that cigarettes are harmful to their health, yet they continue to smoke.
Likewise, repeated use of the phrase “Humans are the weak link” can create a dangerous assumption that nothing can be done to improve security behaviour.
That's why we need to stop saying:
- Humans are the weak link!
- How do we deal with repeat offenders?
- Who is the idiot who clicked on the link again?
Instead, we should focus on understanding behaviour, supporting users and building a culture where secure actions become instinctive.
Expectation shapes reality
Many experts in security awareness still rely on the quote “Humans are the weak link”. This belief can lower expectations, creating a self-fulfilling prophecy known as the Rosenthal effect (or Pygmalion effect), where one person’s expectations directly influence another’s performance. Positive expectations can improve performance, while negative ones can hinder it.
If a manager believes in someone’s abilities, their performance often improves. Conversely, negative expectations may cause it to decline. We can easily imagine this effect at work in cybersecurity.
The 2019 ENISA report ‘Cybersecurity Culture Guidelines: Behavioral Aspects of Cybersecurity’ highlights this problem at the scientific level. It shows that many commonly used theories in cybersecurity research and interventions are not scientifically validated and calls for more rigorous, evidence-based approaches to transform cybersecurity culture. Measuring behaviour is not always easy and there are many pitfalls but that is no reason not to try.
From awareness to culture: our approach
As IT security professionals, we must decide whether we simply want to tick the ‘security awareness’ box or do we truly aim to change behaviour and, ultimately, shape organisational culture? Do we really want a long-term impact?
It's obvious that watching videos of Dr House doesn't make you a doctor: you need practice, reflection and learning from mistakes.
Our CITEF platform, which enables users to immerse themselves in realistic cyber situations, enables us to influence behaviour.
With CITEF, users can safely experience the consequences of their mistakes and that's when behaviour changes. With knowledge and the right environment, humans become the strongest link.
Culture is the real firewall
At the end of the day, cybersecurity isn’t just about technology: it’s about people. Firewalls, AI and detection tools are essential, but they will never replace the power of a well-informed, responsible and confident human mindset.
Real resilience comes from culture: from people who instinctively make the right choices because security has become second nature.
It’s time to move beyond awareness campaigns and build true cyber maturity, where awareness turns into behaviour and behaviour turns into culture. Because when you empower people, they don’t remain the weakest link. They become your strongest defence.
A + B + C = E
Awareness + Behaviour + Culture = Education
Ultimately, cybersecurity is not just about IT systems: it’s about people. Technology helps us detect threats and respond quickly, but it’s humans who make the difference between a narrowly avoided incident and a crisis.
That’s why our greatest asset isn’t the code we write or the tools we develop: it’s the mindset we cultivate.
Let’s stop blaming humans and start enabling them.