Every time an organisation traces a breach back to a single click, a rushed approval, or a document shared through the wrong app, it reaches for the same explanation: human error. It is a comforting diagnosis. The industry routinely blames the overwhelming majority of incidents on people. That framing is comforting precisely because it locates the failure in one person on one bad afternoon, and points to a familiar cure: more training, more warnings, more reminders to stay alert.
When the same “mistakes” recur across different people, teams, and companies, they stop being individual lapses and start looking like something the environment is producing on purpose. But human error is rarely the root cause of a security incident. It is the visible symptom of a workflow that made the insecure choice the easy one.
The pressure South African teams actually work under
This matters more here than the usual commentary admits. South African organisations are defending themselves with lean IT teams, tight budgets, and technology estates that were never designed for today’s threat landscape. The scale of the exposure is not theoretical. CSIR’s National Cybersecurity Survey found that 88% of participating organisations had suffered at least one breach, and 90% of those had been hit more than once. A Vodacom Business report put the figure at 80% of businesses attacked in a single year. This is not a country with a problem at the margins. It is a systemic condition.
The cost behind those attacks keeps climbing: IBM’s 2025 Cost of a Data Breach report puts the average South African breach at around R44 million, rising to R70.2 million in the financial sector.
Faced with those figures, the reflex is to spend on more user training to close the human gap. The CSIR data even seems to invite it, showing only about a third of organisations had trained more than half their staff in 2024. At this point, we are measuring the wrong gap.
Security decisions happen inside the flow of work
No one makes a security decision in a vacuum. People make them in the middle of a deadline, a client call, or a queue of approvals inside the flow of getting the job done. When the secure path is slow, clumsy, or unclear, employees do what capable people always do: They find a faster route, whether it’s shared credentials, a personal file-sharing tool, or a quick hand-off over an external messaging app.
Almost none of this is malicious. It is operational pressure meeting friction, and friction losing. But each of those quiet workarounds steps around a control that someone carefully designed, and every step around a control is an opening for an attacker. Look at where breaches actually begin, and the point sharpens: IBM’s global 2025 findings identify third-party and supply-chain compromise as the leading initial cause at 17% of incidents, with compromised credentials and phishing each accounting for 13%. These are failures of process, access design, and trust boundaries, not a story about careless individuals. The uncomfortable conclusion is that when our security processes become bottlenecks, we are not just tolerating risky behaviour. We are engineering an environment in which the insecure option is the path of least resistance.
When good controls quietly stop working
Consider multi-factor authentication (MFA), one of the strongest defences most organisations have. Its weakness is not technical; it is human and predictable. Bombard a person with enough push notifications and vigilance erodes. The prompt becomes noise. Under time pressure, they tap approve to make it go away. Attackers know this, which is exactly why MFA fatigue attacks work.
The problem is getting harder, not easier. Globally, IBM reports that roughly one in six breaches now involves AI-driven attacks, most often AI-generated phishing and deepfake impersonation. We are asking employees to spot a fraudulent request that has been machine-crafted to be indistinguishable from a real one while thousands of attacks a week wash over their organisation. That is not a realistic ask of anyone.
A control does not have to be bypassed to fail. It can be fully deployed, fully compliant on paper, and still quietly ineffective because we asked people to stay perfectly alert across thousands of identical prompts. The gap that opens up is not between good policy and bad employees. It is between how a control was designed and how work is really performed.
Stop asking people to be the last line of defence
If human vigilance is the weak point, the answer is not to demand more of it. It is to design so that less of it is required.
“The most resilient organisations I see are moving security out of the user’s conscious attention and into the workflow itself,” says Subhalakshmi Ganapathy, chief IT security evangelist, ManageEngine. “Instead of expecting an employee to spot risk in real time, the system surfaces the right context at the right moment, flagging an unusual login, classifying sensitive data before it leaves the building, and stepping authentication up only when the risk genuinely warrants it and staying out of the way when it does not. Adaptive, context-aware controls replace rigid, manual gates. Oversight stays intact; friction largely disappears.”
This shift should be at the centre of any serious security strategy. The future of cybersecurity is not about stacking up more barriers and hoping people navigate them correctly every single time. It is about making the secure action the easiest action so that doing the right thing requires no heroics, no special alertness, and no perfect day. Design security to fit how people actually work, and you stop paying for the same human error twice. Fight against it, and you will keep discovering that humans were never really the problem.




