Human Error Isn't the Problem. Bad Security Design Is
- BY MODERN OPULENT GAZETTE

- 1 day ago
- 5 min read

Every time an organisation traces a security breach back to a single click, a rushed approval or a document shared through the wrong application, it is tempting to blame human error. It is a familiar diagnosis, and an appealing one because it reduces a complex security failure to one person's decision on one particularly bad afternoon. The solution then appears equally straightforward: more training, more warnings and more reminders for employees to stay vigilant.
The problem is that the same mistakes continue to appear across different people, teams and organisations. When supposedly individual failures repeatedly occur under similar conditions, they begin to look less like isolated lapses and more like symptoms of the environment in which people are expected to work. Human error may be what an organisation sees at the point of failure, but it is often not the root cause of the incident.
The more uncomfortable possibility is that organisations have created workflows in which the insecure choice is simply easier.
This matters particularly in South Africa, where many organisations are defending themselves against increasingly sophisticated threats with lean IT teams, constrained budgets and technology estates that were not designed for today's threat landscape. The scale of the exposure is significant. CSIR's National Cybersecurity Survey found that 88% of participating organisations had experienced at least one breach, while 90% of those organisations had experienced more than one. A Vodacom Business report, meanwhile, put the proportion of businesses attacked in a single year at 80%.
These figures point to something much bigger than an occasional employee clicking the wrong link. Cybersecurity is a systemic business challenge, yet organisations can still fall into the trap of treating individual behaviour as the central problem.
The financial consequences make that approach increasingly difficult to justify. IBM's 2025 Cost of a Data Breach report puts the average cost of a data breach in South Africa at around R44 million, rising to R70.2 million in the financial sector.
Faced with numbers like these, the instinct is often to invest in more employee training in an attempt to close the so-called human gap. CSIR data showing that only around a third of organisations had trained more than half of their employees in 2024 appears to reinforce the argument. But training is only one part of the problem. If employees are repeatedly being asked to make high-stakes security decisions while under pressure, organisations should also be asking whether their systems are making those decisions unnecessarily difficult.
Employees do not make security decisions in a vacuum. They make them while trying to meet deadlines, respond to clients, complete approval queues and keep operations moving. When the secure route is slow, complicated or unclear, people naturally look for a faster alternative.
That can mean shared credentials, personal file-sharing services or transferring information through an external messaging application. Most of these actions are not malicious. They are the result of operational pressure meeting friction, with friction eventually losing.
The problem is that every workaround can bypass a security control that was deliberately put in place to protect the organisation. What looks like an employee ignoring policy may therefore be evidence that the policy does not work particularly well within the reality of the employee's job.
The data around breaches reinforces the importance of looking beyond individual behaviour. IBM's global 2025 findings identify third-party and supply-chain compromise as the leading initial cause of breaches at 17%, while compromised credentials and phishing each accounted for 13%. These incidents involve processes, access controls and trust boundaries as much as they involve individual decisions.
When security processes become bottlenecks, organisations are effectively creating an environment in which the insecure option becomes the path of least resistance. The employee may be the person who takes that path, but the conditions that made it attractive were created long before the breach occurred.
Multi-factor authentication, or MFA, is one of the strongest security measures available to most organisations. Yet even a well-established control can become less effective when it relies too heavily on constant human vigilance.
Consider an employee receiving repeated MFA push notifications. After enough prompts, the notifications can become background noise rather than meaningful security alerts. Under pressure, the employee may approve a request simply to make the interruptions stop. Attackers understand this behaviour, which is why MFA fatigue attacks have become such a useful technique.
The challenge is becoming even greater as attackers gain access to increasingly sophisticated technologies. IBM's global research indicates that roughly one in six breaches now involves AI-driven attacks, with AI-generated phishing and deepfake impersonation among the techniques being used.
Organisations are therefore asking employees to identify fraudulent messages and requests that can be crafted by machines to look remarkably convincing, while those employees are already dealing with thousands of legitimate communications and security prompts. Expecting people to remain perfectly alert throughout that environment is not a realistic security strategy.
A security control does not have to be technically bypassed to fail. It can be fully deployed and completely compliant on paper while remaining ineffective in practice because it depends on people making the correct decision every time.
The real gap is therefore not necessarily between good security policies and bad employees. It is between how security controls are designed and how work is actually performed.
If human vigilance is the weak point, the answer should not simply be to demand more vigilance. Organisations should instead design systems that require less of it.
“The most resilient organisations I see are moving security out of the user's conscious attention and into the workflow itself,” says Subhalakshmi Ganapathy, Chief IT Security Evangelist at ManageEngine. “Instead of expecting an employee to spot risk in real time, the system surfaces the right context at the right moment, flagging an unusual login, classifying sensitive data before it leaves the building, and stepping authentication up only when the risk genuinely warrants it and staying out of the way when it does not. Adaptive, context-aware controls replace rigid, manual gates. Oversight stays intact; friction largely disappears.”
This approach puts the emphasis where it arguably belongs: on designing security around the way people actually work. Rather than creating endless barriers and expecting employees to navigate them perfectly, organisations can use technology to make the secure action the simplest action.
That does not mean removing accountability or abandoning employee education. People still need to understand cybersecurity risks, recognise suspicious activity and know how to respond when something does go wrong. But training should complement good security design rather than compensate for its shortcomings.
South African organisations are operating in an environment where cyber threats are becoming more frequent, more sophisticated and increasingly automated. At the same time, employees are being asked to work quickly, collaborate across platforms and manage more information than ever before. Expecting them to remain perfectly vigilant at every point of that process is neither realistic nor sustainable.
The future of cybersecurity is therefore unlikely to be won by simply adding more warnings, more policies and more training sessions. It will be won by making secure behaviour easier to follow than insecure behaviour.
When organisations design security to fit the way people actually work, they reduce the opportunities for mistakes before those mistakes become incidents. Human error may always exist, but treating it as the root cause can obscure the more important question: why was the system relying on a human to get it right in the first place?























































