The Human Side of Cybersecurity: Why Security Awareness Is Your Most Underinvested Control

Approx. Reading Time: 7 minutes

According to the 2026 Verizon Data Breach Investigations Report, 62% of all data breaches involve the human element. Not a misconfigured firewall. Not an unpatched server. A person, clicking a link, sharing a credential, or responding to a convincing request that turned out to be fraudulent. 

At the same time, the threat is getting harder to spot. A skilled attacker used to spend around 16 hours crafting a convincing phishing email. Today, AI can produce the same result in under 5 minutes, and the output is often indistinguishable from a legitimate message from a colleague or trusted supplier. 

Organisations continue to invest heavily in technical controls: firewalls, endpoint protection, email filtering, multi-factor authentication. These are all important, and none of them are going away. But when the average cost of a phishing-related data breach reached $4.88 million in 2025, it’s worth asking a harder question: are we investing proportionally in the part of our security posture that attackers are most actively targeting? 

The answer, for most organisations, is no. 

This article is about Human Risk Management: what it is, why it matters, and what it actually takes to build a workforce that’s genuinely resilient, not just one that’s sat through an annual compliance training module.

The Human Risk Problem

For most organisations, cybersecurity is treated as an IT problem. The IT team manages the firewalls, monitors the alerts, and responds when something goes wrong. Everyone else gets on with their job. It’s a model that made sense when the network had a clear boundary, but that boundary no longer exists. 

The shift to hybrid and remote work has fundamentally changed the threat landscape. Employees are making security-relevant decisions dozens of times a day: from home networks, on personal devices, under time pressure, without a colleague nearby to sense-check a suspicious email. The conditions that make people vulnerable to social engineering, including distraction, urgency, and trust, are baked into the modern working environment. 

This is what makes human risk a cultural problem, not a technical one. Security awareness can’t live in a once-a-year training module or an IT policy document that nobody reads. It has to be part of how an organisation operates day to day: the instincts people develop, the habits they build, and the confidence they have to pause and question something that doesn’t feel right. 

The organisations that understand this are shifting their thinking from “do our people know the rules?” to “do our people behave securely when nobody is watching?” That’s a harder question to answer, but it’s the right one. 

Technical controls remain essential. Email filtering, endpoint protection, and multi-factor authentication all reduce risk meaningfully. But no filter catches everything. Research shows that 11% of zero-day phishing URLs still slip past email security systems, and attackers actively design campaigns to exploit the gap between what technology blocks and what people see. When a well-crafted email lands in someone’s inbox, the last line of defence is the person reading it.

What is Human Risk Management?

Human Risk Management (HRM) is the practice of systematically identifying, measuring, and reducing the security risks that come from human behaviour within an organisation. It goes well beyond sending staff a phishing email once a quarter or rolling out an annual compliance training module. 

At its core, HRM is a continuous program: a cycle of simulation, training, measurement, and improvement that runs alongside the business rather than interrupting it periodically. The goal isn’t to catch people out. Much like workplace health and safety, the aim is to build a security culture where safe behaviours are the default, not something people have to be reminded of. 

The distinction that matters most is the difference between awareness and behaviour change. Awareness is knowing that phishing exists and that you should be careful with suspicious emails. Behaviour change is actually pausing before you click, reporting something that looks off, and doing that consistently, not just in the week after a training session. Most traditional security awareness programs measure the former. Effective HRM programs measure the latter. 

This means tracking metrics that tell a real story: not just how many people clicked a simulated phishing link, but whether that number is trending down over time, how quickly people are reporting suspicious emails, and which teams or individuals might need additional support. These are the signals that connect a security awareness program to a measurable reduction in organisational risk. 

That connection to risk is what makes HRM a business conversation, not just an IT one. When you can demonstrate that your phish-prone rate has dropped from 35% to 5% over twelve months, or that your average time-to-report a suspicious email has halved, you’re showing the business that its exposure is genuinely reducing. That’s a very different outcome from ticking a compliance box.

Why Phish Testing Alone Isn’t Enough

Phishing simulations are a valuable tool, but they’re only one part of the picture. Organisations that run simulations without a structured training and follow-up program often find themselves asking the same frustrated question six months later: why are people still making the same mistakes? 

The answer usually isn’t that the staff are careless. It’s that simulation alone doesn’t build capability. When someone clicks a simulated phishing link and receives nothing more than a notification that they failed, the experience is closer to punishment than education. They know they did something wrong, but they don’t necessarily understand what to look for next time or how to respond differently. Without that context, the behaviour doesn’t change, and the next simulation produces the same results. 

This is why training has to be built into the response. When a staff member interacts with a simulated phishing email, that moment is the most teachable moment in the entire program. Immediate, targeted micro-learning, explaining exactly what the indicators were and what the correct response looks like, is far more effective than a 20-minute generic module assigned weeks later. 

Frequency matters too. A quarterly simulation gives you four data points a year, barely enough to identify a trend, let alone manage one. Ongoing, regularly varied simulations give you a clearer picture of where your organisation actually sits, which individuals or teams carry the most risk, and whether your training investment is producing measurable improvement over time. That’s the difference between running a program and managing one. 

The data backs this up. Research analysing 67.7 million phishing simulations across more than 62,000 organisations found that a structured program combining ongoing simulation with integrated training reduced phishing click rates by 86% over twelve months. The misconception that phishing simulation doesn’t provide value is almost always a reflection of how the program was run, not evidence that the approach doesn’t work.

What Good Security Awareness Looks Like

Effective security awareness programs share a few common characteristics, and none of them involve sending the same phishing template every three months and hoping for the best.

Ongoing simulation with varied templates

A well-run program uses a continuous stream of simulations that vary in theme, complexity, and delivery. Impersonating a courier, a Microsoft 365 login prompt, a payroll notification, an urgent request from a senior leader: these are the scenarios attackers actually use, and staff need exposure to all of them. Variety prevents people from learning to spot the test rather than the threat, and it gives a much more honest picture of where your organisation’s vulnerabilities actually lie.

Immediate targeted training at the point of failure

When someone clicks a simulated phishing link, the most effective response isn’t a stern email or a long training module assigned as a consequence. It’s a brief, targeted piece of learning delivered immediately, explaining exactly what the indicators were in that specific email and what the correct response looks like. This turns a failure moment into a learning moment, which is where lasting behaviour change actually happens.

Reporting as a positive behaviour

Most security awareness programs focus heavily on who clicked. The better metric is who reported. An organisation where staff actively flag suspicious emails, even when they’re not sure, is one where the security culture is working. Encouraging and recognising reporting behaviour shifts the dynamic from surveillance to participation. Staff become part of the organisation’s defence rather than its weakest point.

Leadership involvement

Security culture doesn’t scale through IT policy alone. When leadership visibly participates in awareness programs, talks openly about the importance of security, and models the right behaviours, it signals to the rest of the organisation that this is a business priority, not just an IT requirement. The tone at the top shapes the culture on the floor.

How Netier Can Help

Many organisations know they should be doing more on security awareness, but between competing priorities, limited internal resources, and uncertainty about where to start, it stays on the to-do list. That’s the problem Netier helps solve. 

Netier delivers ongoing phishing simulation and security awareness training programs powered by Sophos, giving organisations a structured, measurable way to reduce human risk over time. Rather than a one-off exercise that produces a report and then sits in a drawer, Netier’s approach is built around continuity: regularly varied simulations, integrated training at the point of failure, and reporting that shows how your organisation is trending, not just how it performed on a given day. Netier manages the program end to end, so the internal lift on your team is minimal. 

The focus is on outcomes that mean something to the business: a declining phish-prone rate, an increasing reporting rate, and a clearer picture of where targeted support is needed. These are metrics that can be presented to leadership and used to demonstrate that the investment in security awareness is producing a real reduction in risk. 

For organisations looking to go further, Netier’s consulting team can work with you on broader security strategy, helping to identify gaps, prioritise investments, and build a security posture that’s appropriate for your size, industry, and risk profile.

Take the First Step

Human risk won’t manage itself. Attackers are getting faster, more sophisticated, and more targeted, and your people are on the front line whether they know it or not. 

If your organisation doesn’t have a structured, ongoing security awareness program in place, now is the right time to start. And if you have one but aren’t confident it’s producing the outcomes it should, it’s worth a conversation. 

Get in touch with the Netier team to discuss how a phishing simulation and security awareness program could work for your organisation.

About the author