From Human Firewall to Human AdvantageFor years, organisations have been encouraged to think of their employees as the human firewall.
The idea was simple. Technology cannot stop every cyber-attack. Eventually, every suspicious email, unusual request or unexpected phone call reaches a person. Employees become the final barrier between attackers and organisational systems. While this concept has helped organisations recognise the importance of people in cybersecurity, it also has an unintended consequence. It frames employees as the last line of defence. A barrier. A control. Something that stands between the organisation and a cyber incident. Today's organisations need to think differently. People are not simply a firewall. They are an organisation's greatest competitive advantage. A Firewall Doesn't Learn Traditional firewalls follow rules. They inspect traffic. They block known threats. They do exactly what they have been programmed to do. People are different. People learn. They adapt. They collaborate. They ask questions. They recognise unusual behaviour. They solve problems. They make decisions in situations that technology has never encountered before. Artificial Intelligence may process information faster than people. But it still depends on human judgement, context and values. The organisations that succeed in the future will not simply have better technology. They will have better people, supported by better leadership. The Human Advantage The Human Advantage is created when employees are empowered to become active contributors to organisational resilience. Rather than seeing cybersecurity as someone else's responsibility, people understand that they have an important role in protecting customers, colleagues and the organisation. This doesn't happen because employees fear making mistakes. It happens because they feel trusted, informed and supported. The Human Advantage combines knowledge with confidence. Technology with judgement. Governance with culture. Why Technology Alone Is Not Enough Cybersecurity technology has advanced dramatically. Artificial Intelligence can identify anomalies. Security platforms can detect threats in seconds. Automated tools can isolate compromised devices. Yet many successful cyber-attacks still begin with a human interaction. An employee approves a fraudulent payment. A manager shares information with an impersonated executive. A supplier receives a convincing AI-generated email. A customer service representative resets an account after being deceived. Technology provides important protection. People provide context. Together they create resilience. Leadership Creates the Advantage Employees rarely become engaged because of policies. They become engaged because of leadership. Leaders influence how people think about cyber risk. They determine whether cybersecurity is viewed as: An IT problem. Or everyone's responsibility. When leaders regularly discuss cyber resilience, recognise positive behaviours and demonstrate responsible use of AI, employees are more likely to follow. Culture is shaped by what leaders consistently reinforce. Trust Unlocks Potential People perform at their best when they feel trusted. When organisations create a Just Culture, employees are more likely to:
Every Conversation Matters Cyber resilience is rarely built during annual awareness training. It is built through everyday conversations. A manager asking whether an unusual email looks legitimate. A colleague reminding someone not to upload confidential information into a public AI platform. A Cyber Champion discussing a recent phishing attempt during a team meeting. A Board reviewing lessons from a recent near miss. These conversations create awareness. Awareness shapes behaviour. Behaviour creates culture. AI Makes Human Judgement More Important Artificial Intelligence is changing the workplace faster than many organisations expected. Employees increasingly rely on AI to improve productivity. AI can generate reports. Summarise meetings. Write software code. Analyse data. Create content. But AI also creates new risks. It can confidently produce incorrect information. It can reflect hidden bias. It can generate convincing phishing emails. It can be used to create deepfake voices and videos. This is why organisations need more than AI capability. They need human judgement. The Human Advantage recognises that people remain responsible for questioning, validating and making ethical decisions. Technology can recommend. People remain accountable. Cyber Champions Build the Human Advantage One of the most effective ways to strengthen organisational resilience is to empower people throughout the business. Cyber Champions encourage conversations. Share practical guidance. Promote responsible AI use. Support colleagues. Identify emerging risks. They demonstrate that cybersecurity is not owned solely by IT. It belongs to everyone. Every department contributes to resilience. Measuring What Matters Many organisations continue measuring awareness through:
But they tell only part of the story. A true Human Advantage can be seen through different indicators. How quickly are suspicious activities reported? Do employees challenge unusual requests? Are near misses shared openly? Do teams discuss cyber and AI risks regularly? Do leaders actively promote cyber resilience? These behaviours provide a far richer picture of organisational maturity. The Board's Role Boards have a critical role in creating the Human Advantage. Directors should ask:
A Competitive Advantage Customers increasingly trust organisations that demonstrate responsible governance. Investors look for organisations that manage risk effectively. Employees want to work where leadership values openness, learning and innovation. The Human Advantage strengthens all three. It improves resilience. Builds trust. Supports innovation. Creates stronger organisational culture. Enhances reputation. These are outcomes that extend well beyond cybersecurity. The Future Belongs to People Artificial Intelligence will continue to evolve. Technology will become faster. Automation will become more sophisticated. Cybercriminals will continue finding new ways to exploit organisations. The organisations that succeed will not simply deploy the latest security technologies. They will develop workplaces where people think critically. Speak openly. Challenge assumptions. Learn continuously. And work together to protect what matters most. The future of cybersecurity is not about building a stronger human firewall. It is about creating a Human Advantage. Because technology may detect threats. But it is people—guided by leadership, empowered by trust and supported by good governance—who create truly resilient organisations.
0 Comments
Creating a Just Culture: Why Employees Must Feel Safe Reporting Cyber Mistakes Imagine this scenario.
An employee receives an email that appears to come from a trusted supplier. Everything looks legitimate. The branding is correct. The language is professional. The request seems routine. Without realising it, they click a link and enter their credentials. Within seconds, they suspect something isn't right. Now they face a decision. Do they report it immediately? Or do they hope nobody notices? That decision may determine whether the organisation experiences a minor security event—or a major cyber incident. The greatest cyber risk is often not the mistake itself. It is the delay in reporting it. We Are All Human Every employee makes mistakes. Directors make mistakes. CEOs make mistakes. IT professionals make mistakes. Cybersecurity specialists make mistakes. Even experienced security professionals occasionally click suspicious links or overlook warning signs. Cybercriminals understand this. Modern cyber attacks are no longer crude or obvious. They use Artificial Intelligence. They research social media. They impersonate trusted colleagues. They exploit urgency, curiosity and human emotion. Their objective is not to defeat technology. It is to exploit perfectly normal human behaviour. Organisations should not expect perfection. They should expect humanity. The Cost of Silence In many organisations, employees hesitate to report cyber mistakes because they fear:
Unfortunately, they can significantly increase organisational risk. An email reported within five minutes may affect one employee. The same email reported six hours later may affect hundreds. Time matters. The sooner an organisation knows about an incident, the more options it has to contain it. What Is a Just Culture? A Just Culture recognises an important truth. People should not be punished for making honest mistakes. Instead, organisations should seek to understand: What happened? Why did it happen? How can we reduce the likelihood of it happening again? A Just Culture does not remove accountability. Deliberate misconduct, reckless behaviour and intentional policy violations still require appropriate action. However, honest mistakes become opportunities for learning rather than occasions for blame. High-performing industries such as aviation and healthcare have embraced this approach for decades because they understand that learning depends on openness. Cybersecurity should be no different. Fear Is the Enemy of Resilience Many organisations invest heavily in security technology while unintentionally creating cultures where employees fear speaking up. This creates a dangerous contradiction. Leaders ask employees to report incidents immediately. Employees worry they will be criticised if they do. The result is predictable. Problems remain hidden. Opportunities to contain incidents are lost. Resilience suffers. Trust is built when people believe they can admit mistakes without fear of unfair consequences. Boards Set the Tone Culture starts in the boardroom. Boards influence organisational behaviour through the questions they ask, the behaviours they recognise and the values they reinforce. Directors should ask:
It is to ensure mistakes become learning opportunities. Managers Shape Everyday Behaviour While Boards establish expectations, managers influence daily culture. Employees watch how leaders respond when something goes wrong. If the first response is: "Who made this mistake?" Employees quickly learn to remain silent. If the response becomes: "What can we learn from this?" The conversation changes completely. Managers should thank employees for reporting concerns. Recognise honesty. Focus on solutions. Celebrate transparency. People repeat behaviours that are acknowledged and valued. Shadow AI Makes Trust Even More Important Artificial Intelligence has introduced new reporting challenges. Imagine an employee accidentally uploads confidential information into a public AI platform. Will they immediately report it? Or will they hope nobody notices? As AI becomes more common, organisations will inevitably experience accidental misuse. The organisations that respond most effectively will be those where employees feel safe admitting what happened. AI governance depends as much on culture as it does on policy. Near Misses Are Valuable Intelligence One of the most overlooked sources of organisational learning is the cyber near miss. Examples include:
Rather than asking, "Who was responsible?" Leaders should ask, "What can this teach us?" Near misses often reveal weaknesses before they become major incidents. Building a Reporting Culture Creating a Just Culture requires deliberate effort. Organisations should:
Cyber Champions Can Help Cyber Champions play an important role in building trust. Because they work within individual teams, colleagues often feel more comfortable discussing concerns with them than approaching IT directly. Cyber Champions encourage conversations. Answer questions. Support colleagues. Promote responsible AI use. Most importantly, they help create an environment where seeking advice becomes normal rather than something to avoid. Trust Is a Competitive Advantage Customers trust organisations that respond openly to incidents. Employees trust leaders who support learning. Investors trust Boards that demonstrate strong governance. Trust is built long before an incident occurs. It is built every time an employee feels confident enough to say: "I think I've made a mistake." Without fear. Without blame. With confidence that the organisation will help solve the problem. The Future Belongs to Learning Organisations Technology will continue to improve. Artificial Intelligence will continue to evolve. Cyber threats will become even more sophisticated. The organisations that remain resilient will not be those with the most advanced technology alone. They will be those where people feel trusted. Where leaders encourage openness. Where reporting is recognised as a strength rather than a weakness. Because in cybersecurity, silence is often far more dangerous than mistakes. The most resilient organisations understand that culture is not simply another security control. It is the foundation upon which every other control depends. Creating a Just Culture is not about accepting failure. It is about creating an organisation that learns faster, responds sooner, and becomes stronger because its people are confident enough to speak up. In today's digital world, that may be one of the greatest competitive advantages any organisation can build. The Rise of Shadow AI: What Every Board Should KnowArtificial Intelligence is transforming the way organisations operate.
Employees are using AI to write reports, analyse spreadsheets, prepare presentations, summarise meetings, write software code, create marketing campaigns, and automate repetitive tasks. For many organisations, this is increasing productivity, improving customer service, and creating new opportunities for innovation. But there is another side to this transformation. It is happening quietly, largely unnoticed, and often without Board oversight. It is known as Shadow AI. Just as organisations once discovered employees were using unauthorised software and cloud services—known as Shadow IT—many are now discovering that staff are using AI tools every day without clear governance, policies, or understanding of the risks involved. The question for Boards is no longer: "Should our organisation use AI?" The question is: "Do we know how AI is already being used across our organisation?" For many Boards, the honest answer is: probably not. What is Shadow AI? Shadow AI refers to the use of Artificial Intelligence tools or services that have not been approved, governed, or adequately monitored by an organisation. It often begins with good intentions. An employee wants to save time writing a report. A manager uses AI to analyse customer feedback. A marketing team generates campaign ideas. A developer uses AI to accelerate coding. A finance team asks AI to summarise complex spreadsheets. None of these actions are necessarily inappropriate. In fact, many deliver genuine business value. The problem is that they often occur without anyone considering:
Why Boards Should Care Artificial Intelligence is no longer confined to technology teams. It is being adopted across every department. That means AI-related decisions are influencing:
Shadow AI Is Often Invisible One of the greatest challenges with Shadow AI is that organisations frequently don't know it exists. Employees are not trying to bypass governance. They are simply trying to work more efficiently. AI tools are often:
The risk isn't that people are using AI. The risk is that leadership has no visibility over how it is being used. Banning AI Isn't the Answer Some organisations have responded by attempting to ban AI altogether. This is rarely effective. Employees who see clear productivity benefits are unlikely to abandon AI simply because policies prohibit it. Instead, AI usage often becomes even less visible. History has shown this before. When organisations banned cloud storage, employees found alternatives. When organisations restricted mobile devices, staff brought their own. The same applies to AI. Effective governance is built on enablement, not prohibition. The objective should be to create an environment where employees can use AI safely, responsibly, and confidently. Questions Every Board Should Be Asking Rather than focusing solely on technology, Boards should ask strategic questions. For example:
AI Governance Is About Trust Good AI governance is not about slowing innovation. It is about building trust. Employees need confidence that they understand organisational expectations. Customers need confidence that their information is protected. Boards need confidence that AI supports business objectives without introducing unnecessary risk. Trust becomes a competitive advantage. Organisations that demonstrate responsible AI governance are increasingly viewed as more reliable by customers, regulators, investors, and business partners. Building an AI-Aware Culture Policies alone are not enough. AI governance must become part of organisational culture. This means:
Strong organisations recognise this and invest in both. The Role of Cyber Champions Cyber Champions can play an important role in helping organisations manage Shadow AI. Because they work within different departments, they often identify emerging AI use before leadership becomes aware of it. They help colleagues understand:
AI Governance Is a Leadership Opportunity The organisations that gain the greatest value from AI will not necessarily be those using the most sophisticated tools. They will be the organisations with the strongest governance. Boards that embrace AI thoughtfully can encourage innovation while maintaining trust, protecting information, and meeting their governance responsibilities. This requires curiosity. Leadership. Clear accountability. And a willingness to ask better questions. The Future Belongs to Governed Innovation Artificial Intelligence will continue to evolve. Employees will continue discovering new ways to use it. Customers will increasingly expect organisations to use AI responsibly. The question is no longer whether AI belongs in your organisation. It almost certainly already does. The real question is whether your Board has the visibility, governance, and leadership to ensure AI is being used safely, ethically, and in ways that strengthen—not weaken—your organisation. Shadow AI should not be viewed as a hidden threat waiting to be eliminated. It should be viewed as a signal. A signal that innovation is happening. The role of the Board is to ensure that innovation is guided by governance, supported by culture, and aligned with the organisation's values. Because in the age of Artificial Intelligence, organisations will not be defined simply by how quickly they adopt AI. They will be defined by how well they govern it. Building Cyber Champions: Why Every Department Needs a Security Advocate For many organisations, cybersecurity still sits within the IT department.
When employees have a security question, they contact IT. When a phishing email arrives, they forward it to IT. When a cyber incident occurs, everyone expects IT to fix it. This mindset creates a significant problem. Cybersecurity is no longer simply an IT function. It is an organisational capability. The most resilient organisations recognise that cyber vigilance cannot be delivered by one department alone. It must be embedded throughout the business, with people at every level understanding their role in protecting the organisation. One of the most effective ways to achieve this is by building a network of Cyber Champions. What is a Cyber Champion? A Cyber Champion is not another IT support person. They are not expected to investigate cyber incidents, configure security systems or become cybersecurity experts. Instead, they act as a trusted advocate for cyber resilience within their own team. Cyber Champions help connect organisational security objectives with everyday business activities. They encourage conversations. Promote good security practices. Support colleagues. Provide feedback. Identify emerging risks. Most importantly, they help make cybersecurity part of everyday work rather than something that only appears during annual awareness training. Why Every Department Needs One Cyber risks exist across every part of an organisation. Finance teams face invoice fraud and business email compromise. Human Resources manages highly sensitive employee information and is increasingly exposed to AI-generated recruitment fraud. Marketing teams use AI tools to create content while managing brand reputation and social media risks. Operations teams rely on business systems that support day-to-day service delivery. Customer service teams regularly verify identities and manage personal information. Legal teams oversee contracts, privacy obligations and intellectual property. Every department faces different risks. A Cyber Champion understands how cyber and AI risks affect their own team and helps translate organisational policies into practical behaviours. Creating a Human Firewall The phrase "human firewall" is often used in cybersecurity. While it conveys an important message, people are much more than a barrier between attackers and systems. People are decision-makers. Problem-solvers. Communicators. Leaders. Cyber Champions help create an environment where secure decision-making becomes a normal part of everyday business. They encourage colleagues to ask questions before sharing sensitive information. They promote responsible AI use. They reinforce good cyber habits. Over time, these small conversations help create lasting behavioural change. Bridging the Gap Between IT and the Business One of the biggest challenges facing many organisations is communication. Security teams often understand technical risks. Business teams understand operational priorities. Cyber Champions help bridge the gap. Because they work within the business, they understand both the pressures their colleagues face and the importance of protecting organisational information. They help explain security requirements in language that makes sense to their team. Equally important, they provide valuable feedback to security and leadership teams about practical challenges, emerging concerns and opportunities for improvement. This two-way communication strengthens governance and supports continuous improvement. Cyber Champions and AI Governance Artificial Intelligence has introduced a new dimension to organisational risk. Employees increasingly use AI tools to:
They also create new governance challenges. Cyber Champions can play an important role in helping colleagues understand:
What Makes a Great Cyber Champion? The best Cyber Champions are not necessarily the most technical people. They are people who are:
They build confidence rather than fear. They create engagement rather than compliance. Supporting Your Cyber Champions Simply appointing Cyber Champions is not enough. Organisations should provide them with:
The Board's Role Boards and executive leaders have an important role in ensuring Cyber Champion programmes succeed. They should ask:
They are a leadership investment. They strengthen organisational culture, improve communication and increase resilience. Measuring Success Success should not be measured by the number of Cyber Champions appointed. Instead, organisations should ask:
Every Organisation Can Benefit You do not need thousands of employees to build a Cyber Champion programme. For a small business, the owner or a senior team member may naturally become the Cyber Champion. Medium-sized organisations may appoint one Champion for each department. Larger organisations may build networks of Champions across offices, regions and business units. The model is flexible because every organisation is different. The principle remains the same. Cyber resilience is strongest when responsibility is shared. Turning Awareness into Action Technology will continue to evolve. Artificial Intelligence will continue to reshape the workplace. Cyber threats will continue to become more sophisticated. The organisations that succeed will not simply invest in better technology. They will invest in better conversations. Cyber Champions create those conversations. They turn policies into behaviours. Awareness into action. Compliance into culture. And colleagues into confident advocates for organisational resilience. Building a network of Cyber Champions is not simply another cybersecurity initiative. It is one of the most effective ways an organisation can embed cyber vigilance, strengthen AI governance and build a resilient culture that protects the business long into the future. Why Security Awareness Training Often Fails (And What Boards and Leaders Should Do Instead in the Age of AI)Every year, organisations invest millions of dollars in cybersecurity awareness training.
Employees complete online modules. They answer multiple-choice questions. A certificate is issued. The compliance box is ticked. Yet organisations continue to fall victim to phishing attacks, business email compromise, ransomware, insider threats, and increasingly sophisticated AI-enabled cybercrime. If awareness training is so widespread, why do so many organisations continue to experience preventable cyber incidents? The answer is surprisingly simple. Most organisations measure participation. Very few measure behavioural change. Cybersecurity awareness is not a training programme. It is an organisational culture. Compliance Does Not Equal Resilience For many organisations, cybersecurity awareness has become a compliance exercise. Staff are required to complete annual training because regulations, insurers, or auditors expect it. Completion rates become the primary measure of success. "We achieved 98% completion." That sounds impressive. But it tells us very little. It does not tell us whether employees:
Resilience measures capability. The two are not the same. The Threat Landscape Has Changed Faster Than Training Traditional awareness programmes were designed for a different era. Today, employees face threats that barely existed a few years ago, including:
Cybercriminals innovate daily. Training often changes annually. That imbalance creates risk. People Are Not the Weakest Link One of the most damaging phrases in cybersecurity is: "People are the weakest link." People are not the weakest link. They are the most targeted. When employees receive thousands of emails, constant Teams or Slack messages, phone calls, and AI-generated content every week, expecting perfect decision-making every time is unrealistic. Instead of blaming employees, organisations should ask:
Boards Set the Tone Cybersecurity culture starts long before an employee receives awareness training. It starts in the boardroom. If boards treat cybersecurity as an annual compliance exercise, management often does the same. If boards instead ask:
Culture follows leadership. Awareness Should Be Continuous Learning is most effective when it is ongoing. The same applies to cybersecurity. Rather than relying on a single annual training session, organisations should create continuous engagement throughout the year. Examples include:
AI Literacy Is the New Security Awareness Artificial Intelligence has fundamentally changed the way people work. Employees increasingly use AI to:
Without governance, employees may:
Employees need to understand not only how to use AI effectively, but also how to use it responsibly. Make Cybersecurity Relevant Generic awareness programmes often fail because employees struggle to relate them to their daily work. The risks faced by a finance manager differ from those faced by a software developer, HR advisor, receptionist, or board member. Training should reflect those differences. Examples include: Finance Teams Business email compromise, invoice fraud, executive impersonation. Human Resources Sensitive personal information, recruitment scams, AI-generated CV fraud. Marketing Brand impersonation, AI-generated content, social media attacks. Executives Whaling attacks, deepfake communications, strategic decision-making. Board Members Cyber governance, AI governance, organisational resilience, regulatory oversight. People engage when learning feels relevant. Build a Culture Where Reporting Is Encouraged One of the strongest indicators of cyber maturity is how quickly employees report concerns. Unfortunately, many organisations unintentionally discourage reporting. Employees worry about:
Instead, organisations should celebrate reporting. An employee who reports a suspicious email—even if it turns out to be harmless—has demonstrated the exact behaviour leaders should encourage. Reporting should be recognised as a positive contribution to organisational resilience. Measure Behaviour, Not Attendance If awareness programmes are to improve, organisations must rethink what they measure. Useful indicators include:
Leadership Must Participate Nothing undermines an awareness programme faster than leaders who fail to participate. When executives ignore security policies or directors bypass governance processes, employees notice. Leadership should:
Security Awareness Is Really Organisational Awareness The most resilient organisations understand that cybersecurity is not simply about technology. It is about decision-making. Communication. Trust. Leadership. Behaviour. And increasingly, it is about how people use artificial intelligence responsibly. Technology can block many threats. But it cannot replace informed judgement, ethical leadership, or a workforce that understands its role in protecting the organisation. The question boards and executives should ask is no longer: "Have our people completed cybersecurity training?" It should be: "Have we created a culture where our people think securely, act responsibly, and feel empowered to protect the organisation every day?" That is the difference between compliance and resilience. And in today's rapidly evolving digital landscape, resilience is what truly matters. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
September 2026
Categories |
RSS Feed