By Myles Bray, CEO of CyberSentriq.
When it comes to cybersecurity, discussions often centre on technical capabilities, tooling and attacker tactics, but often overlooks the employees and security teams the strategy is intended to protect.
The reality is that most critical business functions from staff payroll to procurement and more have now moved online across digital applications, cloud environments and CRMs. With this comes the intense responsibility of ensuring they work as intended and that they are secure from outside threats.
That raises fundamental questions for business leaders and security teams: what is your attitude to a successful attack, and how do your teams learn from internal mistakes?
If the answer is to simply fire or punish the employee, then that risks overlooking the issue entirely.
When employees fear embarrassment or punishment for making a mistake, they’re less likely to raise their hand when something goes wrong. As cyberattacks increase in number and sophistication, an employee’s ability to identify and report incidents quickly is now a defining characteristic of resilient businesses.
A complete cybersecurity strategy supports employees
With employees generating and managing more data than ever before, it’s essential that they are being provided with adequate support to escalate threats. This doesn’t mean that they need to be cybersecurity experts overnight, but they should be able to identify a threat and know how to escalate it internally.
IBM reported that human error accounts for 95% of all data breaches, other industry research found that 74% CISOs cited human error as their top cybersecurity risk, which is a 60% increase from the previous year. As cybersecurity is an ongoing discipline that demands consistency and constant vigilance, even one unpatched vulnerability or lapse in judgement can allow attackers to slip through defences.
There is also a practical case for developing a people-focused strategy. If an employee delays reporting an incident, it tips the scales in favour of the attacker. The longer an incident goes unreported, the more time attackers gain to access sensitive data and move laterally across networks.
That makes containment harder or worse; it could force security teams to shut systems down while they investigate.
Designing processes that work
When employees delay or don’t report on threats, that doesn’t make them malicious or lazy. Often, it’s a sign to businesses that current security protocols are not working for them. To ensure threats are escalated properly, businesses need to replace complex and fragmented reporting procedures with streamlined processes.
Simplifying the reporting process: If reporting a threat requires employees to fill out a form or submit a lengthy ticket, they’re less likely to follow through. Instead, businesses can replace these barriers with centralised communication channels and automated triage pools to bypass email exchanges. This allows security teams to quickly filter out the noise and prioritise more serious threats.
Train employees to focus on behaviour: Employees do not need to be technical experts to spot risk, but they can become experts in context and operational procedures. This means training employees to identify MFA spamming, urgent requests for credentials or data transfers and sudden changes in communication patterns. Aligning training with how employees work instead of technical exploits means security becomes part of daily work rather than an occasional afterthought.
Automate where you can: Security stacks can be configured to automatically log contextual information like an employee’s email address, device ID, network status and session logs the moment they report an incident. Here, automation can reduce administrative burden while allowing security teams to focus on the root cause and containment.
These examples illustrate that when security is embedded into business and daily habits, escalating threats becomes more efficient and crucially, it’s more likely to be embraced by employees.
Hybrid and remote working have expanded the attack surface
It’s estimated that less than half (43%) of employees work exclusively from an office; this makes safeguarding security perimeters a much more complex task.
Given that a vast majority of UK workforces are now working across different devices, networks and locations, threat escalation strategies need to reflect these new workforce trends because many employees often do not have the means to physically verify suspicious activity with another colleague.
That means a truly effective security strategy must give businesses confidence that their employees can identify and flag potential security threats no matter where they are working or what device they are using.
Don’t fall into the blame culture trap
Suppose an attacker is able to slip through defences and manipulate financial transactions. Rather than blaming the employee, businesses should focus on the how and instead ask themselves: How did our email filters let this through, and why do our financial processes allow an invoice to be paid based on a single email link?
When threats are reported and contained quickly, employees feel involved and valued in a business’ security efforts. This reduces the likelihood of containable threats escalating into more serious ones while removing the fear of punishment. It also creates an ongoing feedback loop, exposing security gaps and whilst giving teams actionable insights to improve processes.
While tooling is an essential part of a cybersecurity strategy, business leaders should not overlook the human layer. Security is also about culture, processes and employee behaviour, which even the most advanced tools alone cannot compensate for. By removing the fear of judgement, businesses can reduce dwell time and foster a proactive security culture.
Modern cybersecurity is not about creating perfect employees; it is about building environments where individuals feel safe to speak up when something goes wrong.





