Why I’m done calling humans the weakest link Cybersecurity has long suffered from a people problem, but not in the way we often hear about. As industry that is based on enabling communication across the globe via the internet and many types of devices, many of us practitioners are very bad at communicating to people. A primary example is the phrase “humans are the weakest link” which is well known phrase in our industry. This phrase implies that if it were not for human our systems would be fully secure, but most worryingly projects the message to non-cybersecurity people that there are inferior to us. So not only does this phrase alienate our fellow workers it is a phrase that I firmly believe is unfair and completely misleading. The real issue around cybersecurity is not human error, it is the failure of the technology and the system designs and architecture to support real human behavior. Despite years of awareness campaigns, data breaches linked to phishing and credential misuse continue to dominate incident reports and news headlines. And after each of these breaches the vendors and experts commenting on the breach will reuse the phrase “humans are the weakest link” laying the blame not on any failures in the technology meant to protect us but, instead placing the blame on the person using the computer. Even if a person did get phished or fell victim to a malicious email this should not prompt another round of finger-pointing. Instead, it should raise urgent questions about why so many of our systems still leave people so vulnerable. Take phishing, for example. If a malicious email lands in an inbox and a staff member clicks it, the typical response is to blame the individual for not spotting the signs. But why did the email