From the weakest link to the human firewall: building human cyber resilience in 2026

Perspectives 22 September 2026

For years, I’ve referred to people as the weakest link in cyber security, and the statistics often appear to support that view. However, the more I’ve worked with organisations, leaders, and employees, the more I’ve questioned whether that phrase is still helpful.

The reality is that cyber criminals don’t target people because they’re weak. They target them because they’re human. Every day, employees are expected to make hundreds of decisions, manage competing priorities, and respond quickly to requests. Attackers understand this and exploit it.

Rather than viewing people as a weak point in secure systems, organisations should start viewing them as a security asset to be developed. The goal is to create a workforce that can recognise threats, question unusual requests, and report concerns with confidence. That’s the difference between treating people as the weakest link and investing in them as your human firewall.

The attacker’s favourite target hasn’t changed. Cyber security technology has evolved substantially over the last decade. Organisations have invested heavily in firewalls, endpoint protection, threat detection platforms, identity management, and security monitoring. And yet, attackers continue to achieve success through one remarkably consistent approach: manipulating people.

Verizon’s 2026 Data Breach Investigations Report found that the human element was present in 62% of confirmed breaches. That figure has remained stubbornly high for years and serves as a reminder that while technology continues to evolve, people remain the attacker’s preferred route into an organisation. Attackers exploit:

  • Trust
  • Curiosity
  • Authority
  • Fear
  • Urgency
  • Familiarity

These aren’t weaknesses. They’re normal human traits that help us function in business every day.

In fact, most successful attacks work because employees are trying to do their jobs. They are responding to what appears to be a customer request, helping a colleague, processing a payment, or dealing with a supplier. The problem is that cyber criminals have become remarkably good at making malicious requests appear legitimate.

The threat landscape looked very different in 2026

There was a time when phishing emails were relatively easy to identify. Poor grammar, spelling mistakes, and suspicious email addresses gave attackers away. Those days are largely behind us since generative AI changed the game.

Cyber criminals can now create highly convincing emails, messages, and documents in seconds. They can personalise communications, mimic writing styles, and scale attacks far more efficiently than ever before. Verizon’s latest research highlights the increasing use of AI throughout the cyberattack lifecycle, particularly to support social engineering and phishing campaigns.

While attack methods continue to evolve, the threat facing UK organisations remains significant. The Government’s Cyber Security Breaches Survey 2025 found that 43% of UK businesses identified a cyber breach or attack during the previous 12 months. Medium and large organisations reported considerably higher levels of attack activity.

For business leaders, the question is no longer whether cyber criminals are targeting organisations like yours. The question is whether your people are prepared when they do. At the same time, attackers are no longer relying solely on email. Many organisations have invested heavily in email security, forcing criminals to look elsewhere. Today we are seeing attacks delivered through:

  • Microsoft Teams
  • WhatsApp
  • SMS messages
  • LinkedIn
  • Collaboration platforms
  • Voice calls
  • QR codes
  • Video conferencing tools

Unfortunately, many employees still view these channels as safer than email, which creates new opportunities for attackers. Microsoft has publicly reported increasing abuse of Teams through voice phishing, social engineering, and impersonation attacks. In one documented incident, a threat actor repeatedly impersonated IT support via Microsoft Teams calls until an employee granted remote access, leading to a compromise.

The lesson is simple: If your cyber awareness programme is only focused on email, you’re preparing employees for yesterday’s threats. Trust has become the new attack surface, and cyber criminals understand something many organisations overlook: people don’t trust emails, people trust relationships.

This shift is visible across almost every major cyberattack trend. Attackers increasingly seek to impersonate:

  • Colleagues
  • Suppliers
  • Professional advisers
  • Senior leaders
  • IT support teams
  • Customers

The objective is to remove suspicion before a request is ever challenged. This is particularly dangerous within supply chains. Many organisations spend considerable time assessing their own cyber security controls but pay far less attention to what happens when a trusted supplier becomes compromised.

If an attacker gains access to a supplier’s mailbox, communications instantly inherit trust.

The email comes from the correct address, the conversation history exists, the language appears familiar, and traditional warning signs often disappear. This is why some of the most damaging phishing attacks today originate from genuine accounts that have already been compromised.

The rise of deepfakes and AI impersonation

Just a few years ago, deepfake fraud sounded like science fiction. Today it is reality. One of the most widely reported examples involved engineering firm Arup in 2024, where an employee was deceived into transferring approximately $25 million after participating in a video call featuring AI-generated representations of senior colleagues. The fraud started with a phishing approach but was ultimately reinforced through what appeared to be a legitimate video meeting.

What makes this incident so significant isn’t the amount of money involved; it’s the fact that the employee did exactly what many organisations tell staff to do. They verified, attended a meeting, and sought reassurance.

The problem was that the verification process itself had been compromised. For decades, organisations have relied on visual recognition and trusted voices as methods of validation. AI is eroding both.

As these technologies become more accessible, organisations will need to place less reliance on recognising a face or voice and more reliance on robust processes and independent verification procedures. Because, in the near future, seeing may no longer be believing.

Security fatigue is real

Over the last few years, organisations have introduced:

And while these are all positive initiatives, there is a risk that we create security fatigue. When employees are constantly bombarded with warnings, prompts, and alerts, there is a danger that security simply becomes background noise. Cyber criminals understand this. Many attacks are deliberately designed to catch people when they are busy, distracted, or trying to clear an overflowing inbox. That’s why blaming individuals after an incident rarely addresses the underlying problem.

Instead, organisations need to ask:

  • Were employees adequately prepared?
  • Was the process clear?
  • Was reporting easy?
  • Was the request genuinely unusual?
  • Would others have acted differently?

Cyber resilience is rarely about one poor decision, but rather a combination of circumstances. This is why annual awareness training isn’t enough. One of the biggest mistakes organisations continue to make is treating awareness training as a compliance exercise. Employees complete a course, tick a box, receive a certificate, then return to work. Unfortunately, cyber criminals do not operate on an annual training cycle.

The Government’s Cyber Security Breaches Survey 2025 found that phishing remained the most common cyber threat, affecting 85% of organisations that experienced a breach or attack. If phishing continues to dominate the threat landscape, we need to ask ourselves whether traditional awareness approaches are keeping pace with modern attack methods.

Threats evolve constantly, and so should awareness. People learn best when information is relevant, timely, practical, repeated, and connected to real-world experience.

Employees don’t need another presentation explaining what phishing is. They need examples of the attacks they are likely to encounter this week, this month, today. That’s why phishing simulations, short awareness campaigns, team discussions, and incident reviews are generally more effective than relying exclusively on annual training sessions.

Human Risk Management: a better approach

Increasingly, organisations are moving from security awareness to Human Risk Management. The difference may sound subtle, but it is important. Traditional approaches often focus on training completion. Human Risk Management focuses on behaviour.

Instead of asking, ‘Did everyone complete the training?’, ask:

  • Are suspicious emails being reported?
  • Are employees challenging unusual requests?
  • Are fewer people clicking phishing links?
  • Are escalation procedures being followed?
  • Are lessons being learned from incidents?

Completion rates tell you who attended, but behaviours tell you whether risk is reducing. This builds a stronger human firewall. When I talk about a human firewall, I’m not talking about another software platform; I’m talking about people who:

  • Feel comfortable speaking up
  • Know it’s acceptable to question instructions
  • Understand they won’t be blamed for raising a concern
  • Recognise that cyber security is part of their role, regardless of their job title

Every organisation is different, but the strongest human firewalls usually share five characteristics:

  1. They operate a no-blame culture: People report issues sooner when they don’t fear punishment. And in cyber security, earlier reporting often means less damage.
  2. They make security part of everyday business: Cyber resilience should not be treated as an annual event. It should become part of normal decision-making.
  3. They train continuously: Small amounts of learning delivered regularly are often more effective than lengthy annual courses.
  4. They simplify security: If reporting a suspicious email is difficult, people won’t do it. If verification processes are confusing, shortcuts emerge.
  5. Leaders lead by example: Employees notice leadership behaviour. If leaders take cyber security seriously, the culture follows.

The National Cyber Security Centre continues to emphasise that cyber resilience is not simply an IT issue but a leadership and governance issue that requires board-level engagement.

From human risk to human resilience

The UK Government’s Cyber Security Breaches Survey continues to show that phishing remains the most common and disruptive type of cyberattack experienced by organisations. That fact alone tells us something important.

Cyber criminals are still targeting people because it works, but that doesn’t mean people are the weakest link, far from it. Technology remains essential and will continue to play a critical role in defending organisations. However, every attack ultimately reaches a human decision somewhere along the way:

  • A payment is approved
  • A file is opened
  • A password is entered
  • A concern is reported

That final decision is where resilience lives. The most successful organisations in 2026 won’t necessarily be those with the biggest security budgets or the most advanced technologies. They will be the organisations that invest in their people, support good decision-making, and create a culture where cyber security is everyone’s responsibility.

For years, we’ve talked about people as the weakest link. Yet the latest research tells a different story. The human element continues to feature in the majority of successful breaches. Phishing remains the most common cyber threat facing UK organisations. Attackers are increasingly investing in social engineering rather than purely technical attacks.

That doesn’t prove people are the weakest link; it proves they’re the primary target. Perhaps it’s time we stopped focusing on people as a weak point in secure systems and started investing more heavily in human resilience. When employees are informed, empowered and supported, they become something far more valuable. They become your human firewall.

Get in touch to find out how we can help you empower your employees to better protect themselves and your business.

Further reading:

Defence, protection, security. We've got you covered.

Whether you need to enhance your approach to cyber threats, overhaul your IT infrastructure or improve your communications, we’re here to help and advise. Talk to a specialist today and take the next step towards being a stronger, more resilient business.

Speak to us today

Need support? Take Control.

The button below is to be used when instructed by our technical support team. This will allow a file to be downloaded to your device for them to take control and help solve the issues you are having.

ND Take Control

exe · 7.70MB

Please note: only to be used when instructed by a member of our support team. Windows devices only.