Human factor
The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.
Full definition
The human factor is the dimension of cybersecurity risk that depends on people's decisions, habits and context: which emails they open, which passwords they reuse, whom they believe under pressure. It is the attackers' preferred vector because manipulating a person usually costs less than breaching a patched system.
Speaking of the human factor rather than individual failure is deliberate: people are the target of the attack, not its cause. An employee who falls for a well-crafted spear phishing message is not negligent; they faced a professional deceiver armed with information about their role and tools.
Managing it demands the same rigor as any other risk: continuous measurement of real behavior, training targeted at each person's vulnerability, and validation that behavior changed. That is the terrain of human risk management.
Related terms
Human risk management (HRM)
The discipline that measures and reduces the security risk originating in people's behavior, using continuous data instead of annual courses.
Social engineering
Psychological manipulation that leads a person to hand over information, access or money. It is the starting point of most successful cyberattacks.
Security culture
What employees do about security when nobody is watching: reporting, verifying, asking. It is built through practice, not posters.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.