Skip to content

Cyber Security Starts with People, Not Technology

Cyber starts with People  blog hdr

When organisations talk about cyber security, the conversation typically focuses on the technology, such as firewalls, endpoint protection, email security and identity controls. While these technologies are essential, they aren’t always the weakest link.

In our experience, one of the biggest cyber security challenges businesses face is ensuring their users can recognise threats and make informed decisions when working online. Whether it’s in the office or at home, attackers increasingly target people rather than systems.

As cyber attacks become more convincing and more personalised, user education is no longer a “nice-to-have” exercise. It’s a critical layer of defence.

The Biggest Security Risk? Human Behaviour

Many organisations invest heavily in security technologies, but even the most advanced security controls can be bypassed if a user unknowingly helps the attacker. This isn’t because users are careless or lacking intelligence. It’s because people are busy.

Attackers understand this and design their tactics around human behaviour. They create urgency, apply pressure, and encourage users to make quick decisions before they have time to think.

A simple rule to remember is, attackers only need to be successful once. Your users need to get it right every single time.

How We See Organisations Deliver Security Awareness Training

When speaking with customers, we see a variety of approaches to cyber security education, including things like information screens, quarterly awareness campaigns, team-wide security updates, live training sessions and workshops, and more commonly, simulated phishing exercises.

One thing we’ve found is that traditional annual training sessions often have limited long-term impact. Instead, shorter and more frequent training sessions help keep security at the forefront of users minds throughout the year.

Security awareness should become part of everyday culture rather than once a year compliance activity.

It’s Obvious Phishing Emails… So Why Are People Still Clicking?

One of the most common questions we hear is, “if phishing emails are so obvious, why do people keep falling for them?” The reality is that modern phishing attacks are far more convincing than people realise. Attackers can:

  • Spoof familiar brands
  • Impersonate colleagues
  • Mimic HR or Finance communications
  • Create convincing login pages
  • Use AI to improve language and personalisation

An email from HR@companyname.com asking you to review a policy update may look completely legitimate at a first glance. Combine that with a busy day, multiple meetings, and a sense of urgency, and it becomes easy to see how mistakes happen.

Is This a Technology Problem or a People Problem?

The answer really is both. Technology plays a critical role in blocking threats before they reach users. Modern email security solutions can filter malicious content, detect impersonation attempts, and display warning messages on suspicious emails. The issue is, technology cannot stop every single attack. Some threats will inevitably reach users, which is why education remains so important.

The goal isn’t to create fearful users, it’s to create users who pause, question, and verify before acting.

Implementing the Pause and Check Mindset

One of the simplest but most effective security habits is encouraging users to slow down. Before clicking a link or responding to a request, they should ask:

  • Was I expecting this email?
  • Does this request feel unusual
  • Is somebody creating urgency?
  • Can I verify this through another channel?
  • Does the sender look legitimate?

Taking just a few seconds to stop and think can be enough to prevent an incident.

Microsoft’s Move Towards Passkeys Shows Why User Education Matters

User education isn't just about spotting phishing emails.

It's also about helping users adapt to changes in modern identity security.

Recently, Microsoft announced a significant change to authentication in Microsoft Entra ID. Beginning September 2026, passkeys will become the default authentication experience, and by February 2027 Microsoft will retire its native SMS and voice-based MFA services. Organisations will be encouraged to move users to phishing-resistant methods such as passkeys, Microsoft Authenticator, Windows Hello for Business, and FIDO2 security keys.

This change reflects a wider industry shift away from traditional authentication methods that can be intercepted, socially engineered, or compromised through techniques such as SIM swapping. Passkeys use public-key cryptography and are designed to provide stronger protection against phishing attacks.

Cyber security isn't only about deploying new technology. It's about helping users understand and confidently adopt it. Even the most secure authentication method will struggle to deliver value if users don't understand why, it exists or how to use it.

The full Microsoft article can be found here: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - Microsoft Entra ID | Microsoft Learn

We Are Here To Help

Want to improve security awareness across your organisation? Get in touch with our team to discuss user education, phishing simulations, identity security, and modern authentication strategies that help reduce risk while improving the user experience.

For more information contact us at hello@nabratech.co.uk