Incident response · Essay
Humans Aren't the Weakest Link
The line that excuses broken process, and what it costs dwell time.
"Humans are the weakest link."
You've seen it on a vendor slide. Probably more than one. It's the most repeated line in security awareness, and it's repeated for a reason: it's comforting. If the human is the weak link, then the breach wasn't a design failure, or a missing control, or an alert nobody tuned. It was someone in finance clicking a link. Problem named. Problem outsourced.
I want to push back on it—not because it's entirely wrong, but because it's lazy in a way that actively makes incident response worse.
The kernel of truth, and where it breaks
Let's be fair to the cliché first. Phishing, social engineering, weak passwords, someone plugging in a found USB—a large share of incidents do start with a person. That's real. I'm not going to pretend the human-shaped gap in the perimeter doesn't exist.
But "incidents often start with a person" and "the person is the weakest link" are two very different claims. The first is an observation. The second is a verdict. And the verdict smuggles in an assumption: that the fix is to make the human stronger—more training, more phishing simulations, more sternly worded emails—rather than to ask why one person's one mistake was allowed to matter that much.
This isn't only my take. Researchers who study the human side of security make the same argument. Dr. Iain Reid (University of Portsmouth) has talked through exactly why "the human is the weakest link" oversimplifies risk—and how something as mundane as time pressure quietly reshapes the decisions people make when an attack lands [1].
If a single click can compromise your environment, the click isn't your weakest link. Your architecture is.
Humans are also the only link that reports
Here's what the slide never says: the same humans are your detection layer.
I spend a lot of my time building detections—KQL analytics rules in Microsoft Sentinel mapped to MITRE ATT&CK [2]. And here's the thing those rules taught me: a detection doesn't respond to anything. It fires. That's it. Something has to read it, judge it, decide it's real, and act. That something is a person.
The employee who forwards a weird email to the security team instead of clicking. The SOC analyst at 2am who looks at an alert everyone else snoozed and says, "Wait—that's lateral movement." Those aren't weak links. They're sensors, often the only sensors that catch what slipped past the tooling.
You don't get those reports from people you've spent years telling they're the problem.
And this isn't wishful thinking — it's measurable. A MITRE study trained employees with hands-on practice and feedback instead of slides, then quietly tested them with simulated social-engineering attempts over a full year. Reporting of the malicious ones improved, and the effect held up for 12 months.[3] The paper's own word for trained employees is the one I keep coming back to: sensors.
Why this matters for IR specifically
This is where the "weakest link" framing stops being merely annoying and starts being expensive.
Incident response lives and dies on one number: how fast you find out. Dwell time: the gap between compromise and detection is the difference between "we contained it" and "we're calling a lawyer." And the fastest path to early detection is almost always a human who noticed something and said something quickly.
So ask: What does a "humans are the weakest link" culture do to the speed of that report?
It slows it down. If an organisation treats mistakes as moral failures, then the person who clicked or who realises they shouldn't have or who isn't even sure hesitates. They wait. They hope it's nothing. They check with a colleague before they admit it to security. Every one of those minutes is dwell time you're handing to the attacker, for free, because you built a culture where reporting feels like a confession.
Aviation worked this out decades ago. So did site reliability engineering. It's called a just culture, or blameless postmortems: you separate "What happened and how do we stop it recurring?" from "Whose fault is it?" Not because nobody is ever responsible, but because the moment people fear blame, they stop giving you information and in IR, information is the whole game.
Contain first. Blame never or at least not until the incident is dead and you're learning from it instead of prosecuting it.
The responder is human too
There's a second human in this story we talk about even less: the responder.
The person who clicked the phish was making a fast, low-attention decision under pressure: a plausible email, a busy Tuesday, fifty other tabs open. We love to judge that decision with the calm hindsight of someone who wasn't there. But that's exactly the dynamic Reid points to: under time pressure, people lean on mental shortcuts, and attackers design for precisely that moment. And the analyst three hours into an active incident is also a human under load—tired, stressed, with cognitive bandwidth shrinking, making high-stakes calls fast. There's a growing body of research on the psychological toll of serious cyber incidents on the people who respond to them too [4].
If we accept that responders make worse decisions under stress — and they do — then we owe the same grace to the user who clicked. Both are humans operating inside systems that asked too much of their attention at the wrong moment. The fix isn't to demand better humans. It's to design for the ones we have.
So what actually changes
Drop the "weakest link" frame, and an IR program starts to look different:
-
Make reporting frictionless and safe. One button, no judgement, no twelve-field form. The goal is speed, and speed comes from people not being afraid.
-
Run blameless postmortems. Ask what in the system let the mistake matter, not who made it.
-
Design alerts and playbooks for humans under stress, not for a well-rested analyst with infinite time. Clear, prioritized, low-noise.
-
Treat people as sensors. Their reports are detection telemetry. Tune them, value them, and close the loop with them, the same way you would a noisy rule.
The actual weakest link
Humans aren't the weakest link. They're the most adaptable component in the whole stack: the one that improvises, notices the thing that doesn't fit, and reports it when the tooling stayed silent.
The weakest link is a culture that punishes people for being human and then wonders why nobody spoke up until it was too late.
References
[1] Cybercrimeology podcast, The Human in Security: Deception, Weapons, Crime, Culture — featuring Dr. Iain Reid, Senior Lecturer in Cybercrime, University of Portsmouth. https://cybercrimeology.com/episodes/the-human-in-security-deception-weapons-crime-culture-7NBb6hrH
[2] My Sentinel detection lab: https://github.com/Kajal-Dhanjal/sentinel-detection-lab
[3] Caputo, D. D., Danley, L., & Ratcliff, N. J. (2024). Employee risk recognition and reporting of malicious elicitations: longitudinal improvement with new skills-based training. Frontiers in Psychology, 15, 1410426. https://doi.org/10.3389/fpsyg.2024.1410426
[4] Virtanen, T. (2024). The Psychological Effects of Continuity Threatening Cyber Incidents. Proceedings of the 23rd European Conference on Cyber Warfare and Security, 23(1). https://doi.org/10.34190/eccws.23.1.2268
Spotted an error or have a suggestion?
Email me