Human risk: don’t blame the victim, fix the system

The wave of cyberattacks which targeted some of the UK’s most prominent luxury and high-street retailers has served as a stark reminder of the persistent and evolving threat landscape.

As these organizations grapple with the operational, financial, and reputational fallout, the broader business community in the UK and Ireland is asking a critical question: how did this happen, and how can we prevent it from happening to us?

While it’s easy to point fingers at sophisticated malware or shadowy nation-state actors, the uncomfortable truth is that the initial point of failure is often much closer to home. The human element remains the most unpredictable and, therefore, the most exploited variable in the cybersecurity equation.

Arctic Wolf’s recent report found that a staggering 80% of successful breaches involve a human factor. Attackers aren’t just breaking down digital walls; they’re often being handed the keys to the kingdom.

They understand that it is far easier to trick a person than to defeat a complex security system. In the fast-paced retail environment, where staff are focused on customer service, logistics, and sales, the pressure to be efficient can inadvertently open the door to security lapses.

A rushed click on a malicious link in a fake shipping notification, or using the same simple password for multiple systems, is all it takes for an adversary to gain a foothold.

Culture of blame

Cybercriminals are skilled at leveraging human psychology. They exploit our curiosity with convincing phishing emails, our trust with impersonation tactics, and our tendency to take shortcuts with password hygiene.

Employees are also three times more likely to click on a phishing link than to report it to their IT or security department. This is not because they are malicious, but because they are often unaware, untrained, or simply too busy to stop and scrutinize every email.

Furthermore, the pervasive issue of credential compromise continues to plague organizations. Over 60% of compromised credentials discovered on the dark web stem from the use of weak or reused passwords.

For a retail sector that relies on a complex web of suppliers, partners, and third-party vendors, a single stolen password can trigger a devastating supply chain attack, impacting countless other businesses.

For too long, the industry has fostered a culture of blame, where employees are seen as the weakest link. This is a fundamentally flawed and counterproductive approach.

When employees fear punishment for reporting a mistake, they stay silent. A minor incident, like a clicked link or a suspicious login, can quickly escalate into a catastrophic breach if it goes unreported.

Building resilience

To truly build resilience, leaders across the UK and Ireland must shift their perspective. Instead of blaming people, we must empower them.

This begins with fostering a robust security culture built on shared ownership. It requires moving beyond the annual tick-box training exercise and investing in continuous, engaging security awareness programs that are relevant to the specific threats employees face daily.

However, we must also operate with the assumption that, despite our best efforts, mistakes will happen. That is where technology must provide a crucial and non-negotiable safety net. A 24×7 Managed Detection and Response (MDR) strategy is essential.

It acts as a constant guardian, monitoring the entire IT environment for signs of compromise that may bypass preventative tools. Whether a threat originates from a malicious insider or an accidental click, MDR allows security teams to detect, respond, and neutralize it in minutes, before it can escalate into a headline-grabbing breach.

The security of our most beloved brands and bustling businesses doesn’t just rest on the shoulders of the IT department. It is a collective responsibility.

By shifting from a mindset of blame to one of empowerment, and by combining a positive security culture with a relentless technological safety net, UK and Irish businesses can turn a serious risk, their people, into their strongest line of defense.

We’ve featured the best encryption software.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

Read more @ TechRadar

Latest posts

How well do you really know Superman? This 30-question quiz could be your Kryptonite

He's an icon who's rocketing towards his centenary, but how well do you really know Superman? That's what I want to figure out, so...

Sunderland vs Newcastle live streams: How to watch Premier League 2025-26 Tyne-Wear derby from anywhere in the world

Sunderland vs Newcastle: Sunday, Dec. 14 — 2pm GMT / 9am ETStream on Sky Sports (UK) or USA Network via YouTube TV (10-days free)Access...

Confused about AMD’s FSR Redstone update? You’re not alone – here’s what it all means for PC gamers

AMD's FSR Redstone update was finally launched earlier this week – roll out the rendered red carpet – and it arrived boasting four separate...

The future of minivans? Citroen’s six-seater concept EV has inflatable beds and some very clever ideas

Concept plays with the idea of a future minivanSix seats fit inside a vehicle not much larger than a MiniSwivel seats, inflatable beds and...

How to watch Big Bash League 2025/26: free streams, fixture list for BBL15 T20 cricket season

Watch 34 of 44 Big Bash League games for *FREE* on 7Plus (Australia)Use NordVPN to watch from anywhereBBL15: Sun, Dec 14 – Sun, Jan...

Affinity CEO reveals why Canva and Affinity made pro design software free – and what that means for creativity

When I announced at Canva World Tour in October that the all-new, professional-grade Affinity would become completely free, the design world reacted with a...

Runners rejoice — the Shokz OpenRun Pro 2 hit a record-low price at Amazon

At TechRadar, our health and fitness wearables team love a pair of bone conduction headphones. And if you're looking for our top recommendation right...

A new AAA Alien game is reportedly in the works

If Alien: Romulus reawakened your appetite for the iconic sci-fi franchise, the good news is that a promising video game could be on the...

How to watch John Cena’s final match: free streams, schedule for Saturday Night’s Main Event XLII

Stream John Cena’s final match free on YouTube (everywhere except US)Unlock your stream with NordVPN's Holiday Deal (save 74%)Saturday Night's Main Event XLII: Sat,...

Hitman at 25: Celebrity crossovers, co-op chaos, and the future of Agent 47

Who could have predicted that such a methodical game about a deadly barcoded assassin with seemingly unlimited fashion choices would spark one of the...