The Human Factor in Cybersecurity

The Human Factor in Cybersecurity


Karen F. Madrigal
Old Dominion University
CYSE 200T
09/27/2026


Introduction
“While technological advancements continue to fortify digital defenses, human behavior remains a pivotal element in determining the success or failure of cybersecurity measures” (SecurityScorecard, 2024). In simpler terms, the human factor is people’s direct impact on cybersecurity at its core. The human factor brings an array of different variables that cannot always be factored in, and it can contribute to up to 60% of data breaches (Babcock, 2026). Insider threats, social engineering, and human psychology all come together in ways that allow human error to directly impact cybersecurity. In this paper, we are going to evaluate these variables and how to mitigate many of these vulnerabilities.

Social engineering
Social engineering is one of the most prevalent tactics that threat actors continuously use to gain access to sensitive information, data, and networks. With the rise of the widespread use of the Internet during the early 1990s, social engineering has always been a prime tool used by threat actors. It is unique in the aspect that it does not rely on complicated software or technology to truly have an impact. Its real threat comes from the fact that humans, if uninformed, can fall for these scams unintentionally. Clicking on an unsuspected email can create a vulnerability that a threat actor can use to gain access to an organization’s network.
A good example of this would be the 2016 Snapchat data breach, where a payroll employee fell for a phishing scam. A threat actor had sent an email impersonating the CEO at the time. In this case, proper awareness training could have potentially prevented this breach. On the technical side, the company could have implemented a better email filtration system that could flag potential scams or emails coming from outside of the organization.


Psychology
Human psychology is one of the biggest factors in why human error is so prevalent in data breaches. People are often creatures of habit. We clock in at work, do our jobs, and often drive back home in the same manner and at the same time, following the same routine and starting all over again. Familiarity can often be one of the greatest weaknesses that people experience when it comes to cybersecurity.
For example, nearly 59% of all car accidents happen within five miles of your home, while 69% happen within the first 10 miles. A contributing factor to this can be familiarity, as you are often going on autopilot in order to complete your task (Eaton & Torrenzano, 2021). This can make people more careless. If you see the same formatted email 1,000 times over, you may have less reason to doubt its authenticity because it looks familiar and similar to what you have seen before. Threat actors know this familiarity and often use it as a starting point when launching a data breach. Another factor can be security fatigue. If people see that security requirements feel laborious, too intensive, or happen too often, it can cause even laxer cybersecurity on the user’s end. But there are ways to combat this, such as multifactor authentication, requirements for updating old passwords, or even foregoing passwords and using biometrics as a way to combat poor password hygiene.


Insider Threats
“Insider threat is the potential for an insider to use their authorized access or understanding of an organization to harm that organization” (Cybersecurity and Infrastructure Security Agency [CISA], n.d.). In my earlier section, I used an example talking about the 2016 Snapchat data breach caused by an employee. This is a good representation of an insider threat. It was completely unintentional on their part, but nonetheless, they became an unwilling participant in a massive data breach. Oftentimes, many employees become unwilling participants in these types of incidents, but with proper awareness training, these incidents can be prevented.
Just as easy as someone can be an unwilling participant in a data breach, there are some insider threats that deliberately cause harm. These can have an array of reasons, from disgruntledness with the employer, sabotage, or feeling unrecognized.

Conclusion
There are several ways organizations can help reduce the risks caused by human error and behavior. Simple awareness training can help employees be alert to social engineering attacks and insider threats. This can serve as both a reminder of how attacks can be presented and a way to bring awareness to current and new attacks that are on the rise. Biometrics and password managers are a fantastic way to implement heightened security without compromising current security measures and avoiding security fatigue. Overall, the human factor has multiple approaches, reasonings, and goals that make it difficult to predict, but that is not the end-all-be-all. We are people, and we have the capability to learn and change.


References
SecurityScorecard. (2024, February 16). The human factor in cybersecurity. SecurityScorecard
Babcock, K. (2026, February 18). Human error causes 60% of data breaches: How to protect your organization. Bitwarden. Bitwarden article
TechClass. (2025, April 15). 10 security breaches caused by employees. TechClass article
Eaton & Torrenzano. (2021, February 22). Studies show that most car accident happen close to home. Eaton & Torrenzano
National Institute of Standards and Technology. (2016, October 4). “Security fatigue” can cause computer users to feel hopeless and act recklessly, new study suggests. https://www.nist.gov/news-events/news/2016/10/security-fatigue-can-cause-computer-users-feel-hopeless-and-act-recklessly
Cybersecurity and Infrastructure Security Agency. (n.d.). Defining insider threats. https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats

Leave a Reply

Your email address will not be published. Required fields are marked *