How Human Factors Affect Cybersecurity

About This Write-Up

This professional write-up examines how human behavior can influence cybersecurity and create or reduce security risks. I explore how psychology, cognitive biases, social engineering, workplace behavior, and organizational culture can affect cybersecurity decisions. Using the 2020 Twitter cyberattack as a real-world example, I examine how attackers can manipulate human behavior and take advantage of organizational weaknesses. This assignment helped me understand why cybersecurity requires both technical safeguards and an understanding of the people who use technology.


The human factor is a crucial consideration in cybersecurity. People interact with technology and make security decisions daily. Humans can increase or decrease cybersecurity risks and create vulnerabilities through human error, poor security practices, social engineering, or intentional violations of organizational rules and policies. Psychology, cognitive biases, social influences, and organizational culture can affect how people make cybersecurity decisions. Due to human factors, organizations must combine employee awareness and training with clear policies, communication, technical controls, and a strong cybersecurity culture.

The Human Factor in Cybersecurity

The human factor in cybersecurity refers to the way people’s behavior, decisions, attitudes, and interactions with technology affect the security of information and systems. Cybersecurity is not only a technical issue. People are the ones responsible for using and protecting technology. Humans are seen as the weakest link in the cybersecurity system. Singh (2025) connects psychology to cybersecurity by explaining how human behavior can influence security. Trust, fear, curiosity, convenience, stress, and overconfidence can influence how people respond to situations.

Cognitive bias can affect cybersecurity decision-making and shows why cybersecurity is a socio-technical issue. A person may trust a message because it appears to come from someone they know or may respond to an urgent request without taking the time to verify it. Human behavior and organizational practices influence how well those controls work.

Human-Factor Cybersecurity Risks and Mitigation

Human-factor cybersecurity risks can result from mistakes, manipulation, or intentional actions. Employees may unintentionally create vulnerabilities by using weak passwords, failing to follow security procedures, using unauthorized services, or sharing information with the wrong person. Attackers may use social engineering to manipulate people into providing information or access. Human behavior can also involve intentional violations of organizational rules. An employee who deliberately accesses information without authorization or misuses organizational resources engages in workplace deviance and could pose an insider threat.

The 2020 Twitter attack provides a real-world example of how human and organizational factors can cause a cybersecurity incident. Attackers used phone-based social engineering, pretended to be Twitter’s IT department, and contacted employees about current VPN issues. They sent them to a fraudulent website created to collect their credentials. The attackers took advantage of a situation that employees were already experiencing, making the requests appear more believable. After obtaining employee credentials, the attackers gained access to internal Twitter tools and compromised 130 accounts. Forty-five accounts were used to send tweets, and the attackers used several high-profile accounts to promote a cryptocurrency scam that resulted in the theft of more than $118,000 in bitcoin (New York State Department of Financial Services [DFS], 2020).

The incident shows that human behavior must be considered in organizational cybersecurity. The employees who were targeted were not purposely trying to ignore security. Instead, attackers manipulated normal behaviors such as trusting an IT employee and responding to a problem with a company system. The investigation also identified organizational weaknesses that contributed to the incident. This shows why organizations should not automatically blame employees after a cybersecurity incident. Security controls and organizational practices should help employees recognize threats and limit damage when human errors occur.

There are many ways a company can help protect itself from human factors. Organizations can reduce human-related cybersecurity risks through training, clear policies, communication, and technical controls. Security awareness training teaches employees to recognize phishing and social engineering. Clear policies show employees how company information, emails, cloud services, and remote access should be used. They should have a way to report any suspicious activity. Multi-factor authentication, least-privilege access, and monitoring are technical ways to limit damage when mistakes occur or credentials are compromised. These safeguards follow the CIA Triad by protecting confidentiality, integrity, and availability. Merritt et al. (2024) emphasize that ongoing cybersecurity education can encourage safer behavior and strengthen security culture.

Conclusion

Human factors such as pressure, fatigue, emotions, habits, and training must be considered in cybersecurity. People’s behavior, psychology, and decisions influence how organizations protect information and systems. Human error, social engineering, workplace negligence, and intentional deviant behavior can cause security risks. The Twitter attack shows how attackers can manipulate human behavior and take advantage of organizational weaknesses. Organizations can reduce these risks with training, policies, communication, a positive security culture, and technical safeguards. Cybersecurity is not only technical. It requires understanding human behavior and supporting the people who use technology to keep systems, humans, and data safe.

References

Merritt, M., Hansche, S., Ellis, B., Nethery Snyder, J., Sanchez-Cherry, K., & Walden, D. (2024). Building a cybersecurity and privacy learning program (NIST Special Publication 800-50 Rev. 1). National Institute of Standards and Technology.

New York State Department of Financial Services. (2020). Twitter investigation report.

Singh, T. (2025). Cybersecurity, psychology and people hacking. Palgrave Macmillan.