Why Employees Remain the Key Vulnerability in Information Security

Cybersecurity

Despite advances in security systems, machine learning, and automated monitoring, up to 70–80% of successful cyber incidents begin with human actions, according to the Verizon Data Breach Investigations Report (DBIR), which analyzes thousands of real-world breaches. Even the most advanced attack detection systems are useless if your employee clicks a malicious link, grants access to a third party, or ignores basic security rules. That’s why the focus is shifting from technology to human behaviour—and how companies can mitigate the impact of human error.

Why employee error still matters more than technical vulnerabilities

Most attacks are based not on finding vulnerabilities in infrastructure, but on deceiving people. The reasons are clear:

  • Employees make dozens of decisions under time pressure;
  • Mass phishing campaigns have become virtually indistinguishable from genuine emails;
  • Voice and image substitution (deepfaking);
  • Attackers study employees’ social media profiles to tailor messages to their interests.

Employees who regularly use financial services or spend time in high-transaction environments—from online banking to Italian sports betting sites (siti scommesse senza documenti), where users are accustomed to acting quickly and interacting with payment systems—are particularly vulnerable.

This doesn’t make such services dangerous; on the contrary, it demonstrates that users are more familiar with the digital environment. However, scammers try to imitate these active online patterns by presenting fake payment requests or copies of real pages.

Social engineering has become smarter: what exactly are attackers using?

ENISA Threat Landscape specifies the following threats in 2025-2026, which pose the greatest risks: 

  • AI-generated phishing emails that mimic corporate tone, structure, and branding with near-perfect accuracy, making them significantly harder for employees to detect.
  • Voice-cloned phone scams (vishing) where attackers impersonate executives or managers to request urgent money transfers or confidential information.
  • Deepfake-based impersonation, including synthetic audio or video used to deceive staff during verification or onboarding processes.
  • Business Email Compromise (BEC) is enhanced by AI, enabling attackers to craft context-aware messages that closely resemble internal communication patterns.
  • Manipulation of employees through fake authentication portals, generated automatically using AI-built templates or cloned company websites.

The goal of these attacks is to trick the employee into acting on their own, making it appear legitimate in the system.

Example: The Twitter hack of 2020 – a single call that compromised the security of a global system

One of the most telling examples of how human error can lead to a large-scale cyber incident is the Twitter hack of July 2020. It wasn’t a technical infrastructure breach, an exploitation of a system vulnerability, or a sophisticated zero-day attack. It all began with successful social engineering against a single employee.

Hackers called Twitter support, posing as employees of a partner company’s IT department. Using a confident tone, precise wording, and phrases typical of internal slang, they convinced the employee to proceed to a fake login page. The employee entered their corporate credentials.

After this, the attackers gained access to the internal account management panel. Result: the profiles of Elon Musk, Barack Obama, Bill Gates, Apple, Uber, and dozens of other major accounts—a total of about 130—were compromised. It’s especially important to note:

  • Twitter confirmed that the attack would not have been possible without an employee error.
  • The company acknowledged that its internal phone verification procedures were insufficient.
  • Following the incident, Twitter strengthened authentication, implemented multi-layered checks for support requests, and restricted access to sensitive tools.

This incident became a classic example: even in a global infrastructure employing thousands of security engineers, a single misstep by an individual can open the door for attackers to gain access to the system.

Why “blaming the employee” is the wrong approach

It’s not the individual who is at fault, but the system they work in. If an employee is forced to respond to messages in a rush, use dozens of services, and juggle multiple tasks, the risk of error inevitably increases. Therefore, cybersecurity companies automate routine operations, reduce the number of communication channels, simplify confirmations, and eliminate pressure points that force employees to make quick decisions under stress.

What Companies Can Do: Training That Actually Works

Simply sending employees memos is no longer enough. Effective organizations build a multi-layered approach:

  • Regular phishing simulations test staff responses to real-world scenarios.
  • Mini-training sessions of 5–7 minutes are integrated into the workflow, rather than lengthy lectures.
  • A double-opt-in mechanism for all financial and technical transactions.
  • Restricting access rights based on the principle of least privilege ensures that a single employee’s mistake doesn’t lead to widespread damage.
  • Transparent internal cyber incident reporting demonstrates real-world examples, not abstract threats.

Companies that regularly train employees using practical scenarios report a 40-60% reduction in successful phishing attacks after just one year.

The human factor isn’t a weakness; rather, it’s an indicator of how well a company has built its processes and training. As long as people remain key participants in business processes, they will be the primary targets of attacks. But with proper preparation and a systematic approach, the risk can be reduced significantly—and employees can be transformed from the “weakest link” into a reliable line of defence.

Leave a Reply

Your email address will not be published. Required fields are marked *