The Human factor in cybersecurity refers to the fact that all these high-tech systems are fine, but a chain is only as good as its weakest link. In the cybersecurity “chain” individual humans are by far the weakest link. You can have passwords reset every month, and add in 2 factor authentication, and make multiple security layers that some malicious actor has to breach before they can even glimpse any data, but unfortunately all it takes is one person to receive an email asking for a wire transfer that looks like it is from their boss, or a fraudulent phishing login site, and all that security is for nothing.
Humans by nature are curious creatures. We are also prone to laziness or simple mistakjes that in hindsight are obvious. Unfortunately, when an email comes into your inbox that says, “URGENT OVERDUE BILL CLICK HERE TO PAY”, it is simply human nature to worry that you might have forgotten a bill and be tempted to click that link. Do not click that link. When you get a text message from Grandma that says she’s been robbed while on vacation in Peru, and she needs you to wire her $600 quickly before her minutes run out. I promise you that the text is not from your grandma. Thinking critically or simply doing a quick check through other sources will save you so much pain.
As said previously Humans are the weak link in any cybersecurity chain. According to this article, Alsharif, Maher $ Mishra, Shailendra $ Alshehri, Mohammed. (2021). Impact of Human vulnerabilities on Cybersecurity. Computer Systems Science and Engineering. https://www.researchgate.net/publication/354879445_Impact_of_Human_Vulnerabilities_on_Cybersecurity . It states that humans are responsible for 39% of security risks and roughly 95% of successful cyber-attacks are caused by human error.
This article Akinsola, Fatai & Ogwueleka, Francisca & Mbanaso, Uche. (2025). A Comprehensive Survey of Insider Threat Landscape and Detection Indicators. Kwaghe International Journal of Engineering and Information Technology. 2. 146-177. 10.58578/kijeit.v2i3.7704. https://www.researchgate.net/publication/396836137_A_Comprehensive_Survey_of_Insider_Threat_Landscape_and_Detection_Indicators/citation/download States that close to 60% of cyber-attacks can be attributed to insider attacks, and that number is growing every year. Disgruntled employees, or maybe even someone who simply wants a little more money on the side and sees a quick payday. These threats are real, and the danger can cost billions of dollars.
Setting aside the type of attack caused by a malicious insider, many attacks are still attributed to simply a lack of knowledge on an employee’s part. Regular cybersecurity training and real-world examples of real circumstances and consequences of breaches. Regular password resets, and constant attention from the cybersecurity team are needed today to guard against the endless barrage of threats to digital security.
Sometimes a company has a toxic workplace environment which prevents workers from speaking out when they see something amiss. Sometimes people do not understand the seriousness of a breach when it happens. An employee is worried he will lose his job, so he does not report his ID card stolen. It simply is embarrassing to admit his company email was hacked. Or finally, the employee simply was not trained to recognize a breach when it happens. All these social, organizational, and psychological factors can contribute to a cybersecurity incident becoming worse than it needs to be.
Many factors contribute to human beings as the source of most cybersecurity breaches. From negligence or embarrassment to outright traitorous malevolence, all of these can be part of the cybersecurity chain that makes humans the weakest link. Machines do not care about being treated with respect. Software does not try to steal secrets for monetary gain.