28/05/2026
Your firewalls are fine. It's your employees who are vulnerable.
This is not an accusation. This finding is supported by the responses of 2,500 IT and security decision-makers from nine different countries, as detailed in Mimecast's State of Human Risk 2026 report. Human risk has surpassed technological vulnerabilities to become the defining cybersecurity challenge of our time.
Attackers are no longer breaking in. They are logging in using credentials handed over by a distracted employee, an exploited colleague who thought they were on a Teams call with their CFO, or a well-intentioned finance manager who could not have known that the voice on the other end was AI-generated.
The numbers are stark. A single insider-driven data exposure costs an average of $13.1 million. Organisations surveyed reported an average of six such incidents per month. Yet only 28% have implemented regular awareness training alongside regular checks on user behaviour.
The awareness is there. The action is not. It is precisely this gap that allows breaches to happen, it is a behavioural issue.
In this article, Basil Polydorou explains exactly why the traditional approach to security awareness training is no longer sufficient, and how to close the awareness-action gap.
Read the full article here: https://cyberdexterity.com/articles/how-ai-and-human-risk-reshapes-cybersecurity/
Have a question about where your organisation stands? Chat to us at [email protected]