The human factor in cybersecurity: strengths and weaknesses
The IBM Cyber Security Intelligence Index attributes 95 percent of successful attacks to human error. What that means concretely for phishing, ransomware and the role of the people in an organisation.
95% aller erfolgreichen Cyberangriffe haben menschlische Fehler als Ursache, sagt der IBM Cyber Security Intelligence Index in einer kürzlich veröffentlichten Studie. Die Herausforderungen, mit denen Unternehmen konfrontiert werden, nehmen unaufhörlich zu. Phishing-Angriffe, in denen Cyberkriminelle durch gefälschte E-Mails persönliche Informationen entwenden und Ransomware-Angriffe, bei denen Schadsoftware Dateien verschlüsselt und Lösegeld erpresst, sind nur eine der zahlreichen Angriffe, denen Unternehmen ausgesetzt sind.
95 percent of successful cyber attacks have human error as their cause, according to the IBM Cyber Security Intelligence Index. Phishing, where attackers use forged emails to take personal information, and ransomware, where malware encrypts files and a ransom is demanded, are only two of the attacks companies face.
That is reason enough to look closely at the human factor in security. In practice it is our clicks, decisions and interactions that shape how well the defences hold.
People are at the centre of this, and the analysis has to cover their strengths as well as the weaknesses that get named whenever an attack succeeds. What follows looks at both.

The chart shows that in 2023 people were considerably more resilient against techniques that appeal to helpfulness or flatter the target.
Where people are strong
The human factor is decisive in security, and several of its qualities are what make the difference:
- Intuition and creativity: thinking past the prepared answer is how new approaches to complex problems appear.
- Situational awareness: noticing an anomaly and understanding what it could lead to is a large part of early detection.
- Social intelligence: reading suspicious behaviour in digital communication, and recognising a phishing attempt because something about it is off, is what defeats a social engineering attack.
- Judgement and ethics: people can take complex decisions and weigh them against company goals and legal requirements.
- Flexibility: people adapt to new technology, new threats and new practice, and respond to a situation nobody planned for.
- Willingness to learn: a mistake is also information. Organisations can learn from one, improve their training and change their processes so the same risk does not return.
- Collaboration: security specialists working together recognise threats sooner and respond to them better, because different fields and perspectives meet.
These qualities, together with the technology, are what meet the problem.
Where people are weak
The same factor brings problems with it. According to the IBM Cyber Security Intelligence study, an average of 95 percent of attacks are caused by human error. Knowing where those weaknesses sit is what makes it possible to act on them.
The weaknesses that show up during an attack include:
-
Unpredictability and fatigue: with the volume of information involved, specialists and users alike are exposed to fatigue and overload. That leads to carelessness and less attention to security, which raises the risk of mistakes and incidents. Misjudgements, whether through inattention, carelessness or missing knowledge, open up real gaps.
-
Missing awareness and training: if staff and users are not properly informed about current threats, security practice and company policy, incidents become considerably more likely. Not understanding a security policy is itself a weakness.
-
Too much faith in technology: assuming the technology will stop everything leads to risky behaviour.
-
Less careful practice in private: people tend to be less careful with their own devices. That becomes a problem when the same devices are used for work.
-
Policies followed inconsistently: using insecure networks or downloading insecure applications outside work carries real risk. Even where clear policies exist, getting everyone to follow them consistently is hard. Convenience or ignorance leads to policies being worked around, and the measures lose their effect.
- Convenience: people take the path of least resistance. Where the secure option is not the default, many will not take on the extra effort.
What strengthens the human factor
Addressing the weaknesses and making the most of the strengths takes specific measures, covering both awareness and training and the technology around them:
- Awareness and training: regular training and information campaigns raise awareness of the risks and help staff act accordingly. This matters because they are usually the first line of defence.
- Technical support: security systems and tools complement what people do, by reducing mistakes and responding to threats automatically. That ranges from intrusion detection systems through to a security operations centre and SIEM that recognise suspicious activity and act on it immediately.
- A security culture: where security is understood as a shared responsibility, each person’s contribution to protecting digital resources becomes part of the job rather than an interruption to it.
Together these build knowledge, attention and an effective response.
In short
The human factor has to be part of any security strategy. People bring a range of strengths and a set of specific weaknesses with them, and a strategy that works combines their qualities with the technology.
Being aware of the weaknesses is where it starts, and specific measures are what address them. Training, technical support and a security culture together build something that holds. In the end each person contributes to security in the digital world, and every step in that direction strengthens the collective defence.