Firewalls Don’t Train People: Why Cybersecurity Resilience Starts With Culture

While your organisation might be running the latest authentication tech and threat detection systems, even the most advanced defences can’t prevent a breach caused by one unaware employee.  A single action—clicking a malicious link, reusing a weak password, or ignoring a software update—can inadvertently bypass even the most robust technical defences.  

The Human Factor Behind Data Breaches

Most data breaches don’t begin with a sophisticated hack. They start with a simple mistake. In 2024, global engineering firm Arup lost £20 million after an employee was duped by a deepfake video call featuring AI-generated likenesses of senior executives (Milmo, 2024). And in the same year, 68% of all breaches involved a form of human error (Verizon, 2024). That includes clicking on phishing links, misconfiguring access settings, or accidentally sending sensitive data to the wrong person. 

Social engineering tactics continue to dominate. Attackers are using emails and messages that look legitimate to lure users into handing over credentials or downloading malware. IBM reports that phishing-related infostealers increased by 84% in 2024. These tools silently collect passwords, keystrokes, and login details. Once inside, attackers move fast. The average global cost of a breach reached USD $4.88 million last year (IBM, 2024). 

Technology might catch the threat once it’s in motion, but it often arrives through a human doorway. That’s not just a technical issue, but a cultural one. 

From Awareness to Action: Building Internal Cyber Strength

While technology is essential for detecting threats, enforcing access controls, and maintaining compliance frameworks, it cannot fully protect an organisation unless supported by a culture of vigilance and shared responsibility. 

As National Cyber Security Coordinator Lieutenant General Michelle McGuinness CSC emphasised, “By undertaking simple cyber-safe behaviours consistently, we can turn cybersecurity into an everyday habit, not an afterthought” (McGuinness, 2025). That habit is created through the right tools, awareness, and leadership support. 

According to the Australian Cyber Security Centre, regular employee education and internal simulations are among the most effective ways to reduce human-related risks and reinforce best practices (ACSC, 2024). Similarly, IBM’s 2024 Threat Intelligence Index highlights that organisations combining technical controls with behavioural interventions are significantly faster at identifying and containing breaches (IBM, 2024). 

Aligning Tools and Behaviour for Stronger Outcomes

Building internal resilience means embedding cybersecurity into the fabric of daily operations. In practice, this includes delivering role-specific training, running simulated phishing campaigns, and conducting regular audits to assess compliance.  

Verizon’s 2024 Data Breach Investigations Report found that businesses with strong engagement programs report fewer incidents involving credential misuse, misdelivery, or misconfiguration (Verizon, 2024). 

Best-practice strategies include: 

  • Conducting quarterly phishing simulations to identify training gaps and raise awareness. 
  • Providing scenario-based training tailored to specific roles and risk profiles. 
  • Regularly auditing staff access permissions to prevent privilege creep. 
  • Sharing breach case studies internally to encourage discussion and learning. 
  • Recognising positive behaviour, such as reporting suspicious activity or identifying potential vulnerabilities. 

Resilience Comes When Technology Is Backed by Informed Action

Cybersecurity is both a technical and behavioural challenge. Software can detect anomalies, block malicious traffic, and enforce protocols, but only people can recognise subtle red flags, follow procedures under pressure, and act decisively when it counts. 

The tools may identify threats, but it’s people who prevent them from taking hold. Both elements are essential—not just for reducing risk, but for meeting the rising expectations of regulators, partners, and customers alike (OAIC, 2024). 

At Kinatico CVCheck, we understand that sustainable security depends on both sides working together. That’s why we support businesses with smart platforms, as well as the training, frameworks, and governance needed to turn awareness into action. Contact us to start building a culture where technology and people work hand-in-hand to protect what matters. 

Discover an easier way to manage your compliance needs

References: 

ACSC. (2024). Cyber Security Guide for Small to Medium Businesses. https://www.cyber.gov.au 

IBM. (2024). IBM X-Force 2025 Threat Intelligence Index. https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2025-threat-intelligence-index 

McGuinness, M. (2025). Act now. Stay secure. To protect yourself online. https://minister.homeaffairs.gov.au/TonyBurke/Pages/act-now-stay-secure-to-protect-yourself-online.aspx 

Milmo, D. (2024). UK engineering firm Arup falls victim to £20m deepfake scam. https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video 

OAIC. (2024). Privacy Awareness Week 2024 Resources. https://www.oaic.gov.au/privacy/privacy-awareness-week 

Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/en-au/resources/reports/dbir/ 

Screening Matched to Your Needs

Find out how CVCheck can help with all of your employment screening needs.

Find Out More