Writing · Human Layer
Why the human layer is the hardest security problem to solve
By Mahmoud Lotfy · Mar 2026 · 10 min read
Most security budgets tell a story.
A significant portion goes to technical controls: firewalls, endpoint protection, SIEM platforms, vulnerability scanning. A meaningful slice goes to governance: policies, frameworks, compliance audits. If the budget stretches, there's room for penetration testing and incident response.
And then, somewhere near the bottom of the list, there's security awareness training. A few hours a year. A phishing simulation. A module that most people click through as fast as possible to get the completion certificate.
"The firewall is not your last line of defence. The person reading their emails at midnight is."
This is the wrong order of priorities. And the consequences are measurable.
Where attacks actually start
The data on this is consistent across every major report. Verizon's 2025 Data Breach Investigations Report found that the human element was a factor in the majority of breaches. IBM's Cost of a Data Breach Report consistently shows phishing and social engineering among the top initial attack vectors. The technical controls that organisations invest in heavily are being bypassed entirely, not because they don't work, but because attackers have learned it's easier to manipulate a person than break through a firewall.
Social engineering works because it exploits something that can't be patched: human psychology. The instinct to be helpful, to act quickly, to trust authority, to not want to seem paranoid or obstructive. These aren't weaknesses, they're normal human traits. But in a professional context, they're also attack surfaces.
The executive problem
Here's what most organisations don't want to say out loud: the most dangerous targets in your organisation are often the most senior people in it.
Executives have access to everything that matters. Financial systems, strategic documents, legal communications, board-level information. They're also the people most likely to be targeted specifically. Spear phishing campaigns are built around them, business email compromise attacks impersonate them, and whaling attacks target them directly. And they're the people least likely to engage seriously with security training.
Not because they're careless. Because they're busy, they believe, often correctly, that they understand risk better than most, and because the training they're given is designed for everyone, which means it's really designed for no one.
I've seen this firsthand. A CFO at a large, well-resourced organisation with a mature security function fell for a phishing attack. Not a crude, obvious one. A targeted, well-crafted message that arrived at the right moment and asked for something plausible. The 24-hour incident response team caught it in time. The damage was contained. Most organisations don't have a 24-hour IR team, and find out weeks or months later, if at all.
Why training doesn't work the way we think
This isn't just an observation from consulting. It was the subject of my undergraduate dissertation at Northumbria University. I designed and ran an experiment measuring students' vulnerability to spear phishing before and after a live attack demonstration. The hypothesis was that showing participants exactly how a spear phishing attack is constructed, the tools, the psychological techniques, the OSINT, would meaningfully reduce their vulnerability.
The majority of participants would have fallen victim before the demonstration. That's people who considered themselves reasonably tech-aware, failing against a single targeted attack. After the demonstration, ideal responses increased, but a significant portion of participants remained vulnerable. The demonstration helped. It didn't solve it.
What the data suggested was that a single intervention, however realistic, is not enough. Combining demonstration with mindfulness techniques, roleplay, and regular repetition produced better outcomes than any one method alone. If a realistic, live attack demonstration doesn't fully close the gap for students who just watched it happen, what chance does an annual compliance module have with a CFO who already believes they understand risk?
What good looks like
The organisations that handle this well treat security training as something worth designing properly. Not a compliance checkbox, not a generic module that assumes everyone needs to be told what a password is. What works is training built around the specific world of the person receiving it. A CFO needs examples from finance: wire transfer fraud, invoice manipulation, the specific pretexts attackers use against people who control money. A legal director needs examples from legal. The attack surface looks different from every seat, and the training should reflect that.
They also give executives different training to everyone else, and invest in detection and response capability alongside prevention. Because no matter how good the training is, someone will eventually click something they shouldn't. The question is whether you find out in hours or months.
The honest conclusion
There is no technical solution to the human problem. You can reduce the attack surface, make phishing harder to execute, and add layers of verification that catch mistakes before they become incidents. But you cannot engineer human judgment out of the equation entirely.
What you can do is take it seriously. Give it budget that reflects its actual risk contribution. Design training that works for the people who need it most. And build the detection capability to catch what inevitably gets through. The firewall is not your last line of defence. The person reading their emails at midnight is.