The human firewall

Issue 2 2022 Training & Education, Security Services & Risk Management

Cybersecurity is now battling a human problem just as much, if not more than a technical one. According to Verizon’s 2021 Data Breach Security Report, 85% of successful cyberattacks now involve a human element. Combine that with the fact that even the very best technology can only thwart about 93% of attacks and that leaves a large hole in an organisation’s basic security hygiene. A gap where employees are relied on to make split decisions and failure to choose correctly puts disaster just a click away.

With cybercrime now estimated to cost more than 6 trillion USD annually, the adoption of cybersecurity training is no longer optional. In fact, a growing number of new regulations now require many businesses to add ongoing education to their security programmes, causing a boom in so-called 'awareness training' programmes.

However, security officers say these generic, one-size-fits-all training systems often fall short, particularly as it relates to delivering a change in online employee behaviour. Without this proof point, what is the true ROI of security training?

“Current training programmes are very one-dimensional because they don’t take the human element into account,” says Marc Leckman, director of IT for Wesdome, a Canadian gold mining company with about 500 users, often in remote locations. “You can’t truly solve the problem unless you account for the fact that people react differently to the same type of threat.”


Challenges in security training

“The weakest link is always people; what I call the ‘human firewall’,” stated Kin Lee-Yow, CIO of the Canadian Automobile Association Club Group (CAA), one of the country’s largest not-for-profit associations. As such, they have thousands of employees across the country, including those in retail stores, call centres, corporate offices and accounting; any of which could be an entry point resulting in a serious breach. “We’ve been focusing on how we increase the level of awareness and education for a while now.”

This 'last mile' frustrates even the most vigilant of organisations. In fact, while this 7% to 15% typical firewall gap may seem small, it leaves a 100% statistical probability that every employee will eventually come across some form of novel threat – be it in an email, chat or weblink. They will not only need to identify it as such but be properly trained on how to best act upon it.

This presents a need for security professionals to further buttress their efforts at embedding a sustainable security-aware culture among employees. This has led to a growing demand for ongoing educational programmes that rely on behavioural science to measure and manage cybersecurity risk as a distinctly different solution from generic, one-size-fits-all training programmes. Instead of just putting a check in the training box, these programs focus on training the right person at the right time about their specific risk profile to generate and sustain a change in behaviour.

It wasn’t until Lee-Yow discovered this new breed of cyber-training that he realised the issue was solvable. By utilising machine learning to develop a customised approach for each employee, CAA Club Group could then correct key motivating factors that drive underlying online employee behaviour. This greatly reduced the chances of an employee becoming the victim of a cyberattack that could devastate a company’s reputation, not to mention its bottom line.

Changing behaviour, increasing mindfulness

“We are now attacking it from a completely different angle,” says Leckman. “Beginning with the personalised risk assessment provided by cyberconIQ and their accompanying dashboard, we can ascertain the risk makeup of our employees and strategically plan our next investments based on those results.”

CyberconIQ pioneered the merging of psychology and technology to measure and manage cybersecurity risk. The company’s assessment, training and education have proven to reduce the risk of a successful attack by 45% to 90%. This creates a measurable ROI on security executives’ training expenditures.

“I liked the fact that every employee is given a 40-question assessment, kind of like a Myers-Briggs personality test,” says Lee-Yow. “This gave us a tool that assessed every individual from their own risk standpoint and from there we could show them how to better protect themselves. And going one step further, how to create good online habits.”

Lee-Yow concedes that good habits are not formed overnight, which is another reason he has found the ongoing education – which includes delivering new materials regularly – and simulation drills to be an effective departure from generic training programmes he has used in the past.

“We can actually measure improvement,” says Lee-Yow. “For example, we conduct regular phishing tests and if someone fails, we can follow that up with a programme that reinforces and rejuvenates that employee on best practices.”

CAA Club Group has been using the education assessment and training programme for over a year now and Lee-Yow has been pleased by the results.

Cybersecurity ROI

Wesdome, on the other hand, is still in the early stages of its personalised cyber-training journey. Leckman was looking for a consulting partner who could first help him determine his existing corporate risk profile. After this assessment was complete, he was able to demonstrate to his executive peers and the company’s board of directors that improving their cybersecurity practices was critical.

“From a director standpoint, breaking down the results of that assessment showed me where we were at a higher risk, where we had lower risk and where our budget was best spent,” explains Leckman.

This ability to measure risk-adjusted ROI on improvements in maturity is compelling for those who control budgets and spending, ensuring cybersecurity improvements are targeted appropriately for additional funding. For Wesdome, the key was finding something that was going to deliver a return on their investment. Not in the form of an immediate payback, but instead from the long-term opportunity costs associated with reducing the threats to which they are exposed.

As part of that, both Leckman and Wesdome have decided to further enhance security measures and thus lower their risk profile, by utilising cyberconIQ’s risk advisory team.

“When the massive amount of costs, compliance and other aspects of an attack are taken into account, it is obvious that personalised intervention is what the industry needs,” concludes Lee-Yow.

Time is of the essence on addressing these matters given the constant escalation of new threats and new techniques being deployed to hack and attack organisations globally.

Given the huge global shift in working and learning remotely, combatting situational distractedness should now be a critical component of any security awareness training. Knowing what to do to avoid risk and successfully applying that tactic when an actual threat appears is the key to keeping an organisation and its employees safer online.

“We are all human. We all make mistakes,” Lee-Yow said. “However, we believe that mistakes can be greatly minimised with the proper employee education and effective follow-up.”

Find out more at https://cyberconiq.com/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.