Picture a Tuesday morning in a well-run office. The inbox is full, the phone is ringing, and somewhere in that pile of email is a message that looks like it’s from a supplier the business actually uses — same logo, familiar name, invoice attached. The person who opens it isn’t careless. She’s busy. She processes forty invoices a week, and this one looks like the other thirty-nine.
That’s the moment attackers are counting on. Not a hole in your firewall — a normal person having a normal day.
The numbers back this up
In this year’s Data Breach Investigations Report, Verizon found the human element was involved in 62% of breaches — phishing, stolen passwords, someone talked into doing something that seemed reasonable at the time. The 2026 DBIR analyzed more than 22,000 confirmed breaches, and the pattern has held for years: attackers go through people because people are easier than firewalls.
So yes — statistically, your staff really is your biggest security risk.
Why that’s okay
Because it’s not a character flaw. It’s a design problem, and design problems have fixes.
You can’t patch people the way you patch software, and you don’t need to. What you need is a setup that expects someone to click eventually — and makes that click survivable. Businesses that treat security as “hire smart people and hope” get breached by smart people having a bad morning. Businesses that treat it as a system do measurably better.
Here’s what that system looks like.
1. Train continuously, not annually
The once-a-year security video doesn’t change behaviour — it changes a checkbox. What works is short, regular training with simulated phishing emails, so spotting the fake becomes a reflex instead of a memory.
The difference is bigger than most people expect. KnowBe4’s benchmarking study of 67 million phishing simulations found that before training, about one in three employees clicks a simulated phish. After a year of ongoing training and simulations, that drops to around one in twenty-five — an 86% improvement. That’s not a marginal gain; that’s most of the problem.
If you already know how to spot the current generation of phishing emails, that instinct came from exposure. Training just gives your whole team the same exposure, safely.
2. Make it safe to report a mistake
The employee who clicks a bad link and tells you within five minutes has handed you a contained incident. The employee who clicks and says nothing — because the last person who admitted a mistake got chewed out — has handed you a three-week head start for the attacker.
This is the cheapest security control you’ll ever deploy: when someone reports a click, thank them. Every time. The report is the win.
3. Put verification habits around money
Most of the expensive incidents we see aren’t technical at all — they’re an email asking to change a supplier’s banking details, or an urgent transfer request that appears to come from the owner. One habit stops nearly all of it: any request to move money or change payment details gets verified by phone, using a number you already had. Not the number in the email. No exceptions, including for the boss — especially for the boss, since that’s who attackers impersonate.
4. Assume the click will happen anyway
Training lowers the odds; nothing makes them zero. The rest of the system is there for the day someone clicks:
- Two-factor authentication everywhere — a stolen password alone shouldn’t be enough to get in
- Endpoint protection on every machine — so what the click downloads gets caught
- Working, tested backups — so the worst case is a bad day, not a bad quarter
- Access limited to what each person needs — so one compromised account can’t reach everything
Where to start
If you’re reading this thinking “we’ve got good people, but none of this is actually in place” — that’s most small businesses, and it’s fixable. If you’d like to know how your setup would hold up on the day someone does click, our free security assessment is a good place to start.