Back to the glossary
    Human risk & behaviorCybersecurity glossary

    Human factor

    The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.

    Full definition

    The human factor is the dimension of cybersecurity risk that depends on people's decisions, habits and context: which emails they open, which passwords they reuse, whom they believe under pressure. It is the attackers' preferred vector because manipulating a person usually costs less than breaching a patched system.

    Speaking of the human factor rather than individual failure is deliberate: people are the target of the attack, not its cause. An employee who falls for a well-crafted spear phishing message is not negligent; they faced a professional deceiver armed with information about their role and tools.

    Managing it demands the same rigor as any other risk: continuous measurement of real behavior, training targeted at each person's vulnerability, and validation that behavior changed. That is the terrain of human risk management.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.