The Human Factor: Why People Are Your Biggest Security Risk

Most organizations now run competent firewalls, patched servers, and managed endpoints. It has not stopped the breaches, because the breaches moved. Verizon’s Data Breach Investigations Report, the world’s largest annual study of real breaches, attributes 62% of them in its 2026 edition to the human element: a click, a reply, a reused password, a helpful voice on the phone. The attack surface that now matters most walks out of the building every evening.

This article makes the case that human risk is a governance problem with measurable returns, not an HR course on a calendar. The same workforce that clicks 33% of simulated phishes at baseline clicks 4% after a year of disciplined programme. The difference between those two numbers is not the people. It is the programme.

At a glance

  • The human element is the majority attack surface: 62% of breaches involved a person’s action or interaction, according to the Verizon 2026 DBIR.
  • Attackers win on speed: the median phishing email is clicked 21 seconds after delivery, while the median report of a suspicious email takes 28 minutes.
  • Programmes beat courses: baseline phish-prone rates of 33.1% fall to 4.1% after twelve months of sustained training, an 86% reduction measured across 67.7 million simulations.
  • The cost of failure is concentrated: business email compromise alone generated about R49 billion ($3.05 billion) in reported losses in a single year.

Where Breaches Actually Begin

The initial access market has consolidated around identity. Credential abuse starts 22% of breaches and phishing another 16%, with pretexting adding a further 6%: together, routes that pass through a human being rather than an unpatched server. The pattern is rational. Perimeter and endpoint defences improved faster than the average person’s Monday morning, so adversaries stopped attacking the technology and started attacking the login. In basic web application attacks, 88% involve stolen credentials, which means the password in somebody’s head is formally part of your attack surface.

This changes what security spend buys. A control that only works when nobody makes a mistake is not a control; it is a wish. The architecture has to assume the click happens and build the layers that catch it: phishing-resistant authentication, out-of-band verification for payment changes, and people who report what they see quickly enough for those layers to matter.

The 21-Second Problem

The numbers that should unsettle every executive come from Verizon’s breach dataset. The median time-to-click on a phishing email is 21 seconds from delivery. The median time for a suspicious email to be reported is 28 minutes. Attackers deliberately engineer urgency, authority, and fear into the message precisely because those emotions convert before reason engages. Somewhere in the gap between 21 seconds and 28 minutes, most modern defences live or die.

Attack chain diagram showing phishing email, click in 21 seconds, stolen credentials, access, and impact, contrasted with the 28 minute reporting path
The human attack chain: attackers need 21 seconds of a person’s attention, while defenders need the report, which takes 28 minutes. Awareness programmes shrink both sides of that asymmetry.

Read the chain honestly and the design brief writes itself. You will never make humans faster than 21 seconds, and you cannot delete curiosity or generosity from a workforce. But you can make the click less consequential and the report much faster. That is a systems problem, and it is solvable.

Why Annual Training Does Not Change Behaviour

The compliance industry’s favourite artifact is the annual awareness course: completed by 100% of staff and remembered by approximately nobody. Verizon’s analysts observe that click rates on real phishing campaigns were largely unaffected by training alone, which sounds like an argument against training until you look at what training alone means in most organizations: a once-a-year module with no simulation, no feedback, and no measurement beyond completion.

Behavioural science is unambiguous on the point. Single-event instruction decays within weeks. People do not form habits from annual events; they form them from short, frequent, relevant practice with immediate feedback. Annual training is a compliance checkbox. A twelve-month programme is a control. The distinction is not semantic: it is the difference between an organization that can evidence behavioural change and one that can only evidence video views.

The Evidence That Programmes Work

The strongest published evidence comes from KnowBe4’s 2025 industry benchmarking, drawn from 67.7 million simulated phishing tests across tens of thousands of organizations worldwide. At baseline, before any programme, 33.1% of employees click the simulated phish. After 90 days of short, regular interventions, the rate nearly halves. After twelve months of sustained programme, it falls to 4.1%. That is an 86% behavioural reduction, measured at a scale that leaves little room for luck.

Line chart comparing the decay curve of annual training with the sustained decline of a twelve month continuous programme from 33.1% to 4.1%
Annual training decays back toward baseline within months. A continuous programme compounds: 33.1% phish-prone at baseline, 4.1% after twelve months.

The economics follow. Globally, the average organizational cost of a single phishing incident now runs at roughly R18 million. The local numbers land harder: IBM’s South Africa research puts the average cost of a data breach at R44.1 million, and breaches that begin with phishing among the most expensive causes of all at R50.4 million per incident. When a phish exposes personal information, POPIA’s notification duties to the Information Regulator apply, and penalties reach R10 million. Against those numbers, a twelve-month awareness programme is one of the cheapest risk reductions available to any executive. Unlike most security spend, its returns compound, because every reported phish trains everyone behind the reporter.

Measure Reporting, Not Completion

The maturing metric in awareness management is the click-to-report ratio. Completion rates measure attendance. Click rates measure failure. The ratio between clicking and reporting measures the thing that actually defends the organization: whether people who see something say something, quickly, and without fear. High-performing programmes celebrate reports, including reports of phishes that fooled the reporter, because a reported email is a dead email and an educated employee.

This is the aviation safety model applied to security: near-miss reporting as a cultural norm, blameless by design. The 28-minute median report time is the benchmark to beat. Every minute shaved off it shrinks the window in which one human mistake can become an enterprise incident.

What Leaders Should Do Now

1. Put human risk on the risk register with a name beside it. What gets owned gets managed. What gets owned by nobody gets clicked.

2. Replace the annual course with a twelve-month cadence. Short monthly touchpoints, simulation, and role-relevant content beat the annual marathon in every published dataset.

3. Report the click-to-report ratio at executive level. It is the single number that tells you whether awareness is a culture or a calendar entry.

4. Engineer for the inevitable click. Phishing-resistant authentication, verified callbacks for every payment and bank-detail change, and out-of-band confirmation for credential resets make the 21-second problem survivable.

5. Make reporting blameless and visible. Thank reporters publicly, track report times, and treat every report as a control event, because that is exactly what it is.


Sources: Verizon Data Breach Investigations Reports 2025 and 2026; KnowBe4 Phishing by Industry Benchmarking Report 2025; FBI Internet Crime Report 2025; IBM Cost of a Data Breach Report 2025, South Africa; Protection of Personal Information Act 14 of 2013 (POPIA).

The human factor is not a weakness to be lamented; it is a control to be built, and it responds to discipline like any other control. Lebone Marang and Summer’s IT Security Awareness Platform runs awareness as a year-round programme: simulation, micro-training, and measurement that changes behaviour instead of certifying attendance. If your current programme is an annual course, that is exactly the gap we close.

Facebook
Twitter
WhatsApp
Email