A recent article published by Cyber Security Intelligence carried a headline that immediately caught my attention: “Cyber Security:  Rising Threats Demand a Cyber-First Culture.”  Meaning People – Every Employee Counts. 

If you ask me. It is one of those rare statements that appears almost self-evident—until you stop to consider its implications.

For decades, cybersecurity has largely been discussed as a technology problem. Each new generation of tools promised to restore the advantage to defenders. Better firewalls. Better antivirus software. Better encryption. Better authentication. More recently, artificial intelligence has been presented as the next great leap forward.

Yet the evidence accumulating over the past eighteen months tells a very different story.

Cybercrime is expected to generate losses approaching US$10.5 trillion annually—large enough that, if measured as a national economy, it would rank as the third largest in the world, behind only the United States and China and ahead of Germany. At the same time, fraud losses continue to rise, identity theft has become increasingly sophisticated, and artificial intelligence is allowing criminal organizations to automate deception on a scale previously unimaginable.

Technology has continued to improve. Unfortunately, so have the criminals.

Looking back over the developments we have reported during the past eighteen months, one conclusion has become increasingly difficult to ignore. Nearly every major trend—from AI-enabled fraud and deepfakes to data poisoning, workforce shortages, identity verification and international cyber governance—points toward the same underlying reality.

Cybersecurity is becoming less a technology challenge and increasingly a human one.

Building a Cyber Security Culture

Looking back over the past eighteen months, one theme has surfaced repeatedly throughout our reporting. We examined the global shortage of cybersecurity professionals, the growing levels of burnout among experienced practitioners, the industrialization of cybercrime through artificial intelligence, the emergence of deepfakes and data poisoning, and the widening gap between technological innovation and international governance.

At first glance these appeared to be separate developments. In retrospect they point to the same conclusion.   The cybersecurity challenge is becoming increasingly human rather than technological.

The shortage of qualified professionals cannot be solved overnight. Universities are expanding cybersecurity programmes, governments are investing in digital skills, and professional bodies are working to attract new talent. Yet education cannot produce experienced cybersecurity specialists fast enough to keep pace with the accelerating threat landscape. Even if enrolment were to double tomorrow, organizations would still face years of shortages before enough experienced professionals entered the workforce.

That reality makes one recommendation from the recent Cyber Security Intelligence article particularly significant.

Rather than waiting for the education system to close the gap, organizations themselves must become educators.

This is more than an increase in employee awareness training. It represents a fundamental shift in thinking. Cybersecurity can no longer be viewed as the exclusive responsibility of the IT department or a small team of specialists. Every employee who receives an email, accesses customer information, approves a payment, or works remotely has become part of the organization’s security architecture.

The objective is to create what might best be described as a cybersecurity safety net—an organizational culture in which thousands of informed decisions made every day become the first line of defence. Technology remains indispensable, but it is people who determine whether that technology is used safely and effectively.

This principle is not entirely new. I was reminded of it while reflecting on Dun & Bradstreet’s own transition into the digital age many decades ago.

When competitive pressures finally convinced the company that digitization could no longer be postponed, then Chairman and Chief Executive Officer Duke Drake made a remarkable decision. Rather than limiting technical education to programmers and senior management, he required employees throughout the organization—from executives, junior staff to clerical workers—to attend introductory classes explaining programming concepts and the fundamentals of electronic systems.

The objective was not to turn everyone into programmers. The objective was to remove fear. People support change far more readily when they understand it.

As a participant I still remember one exercise from those classes. We were asked to write down every individual action required from the moment we woke up until we left the house for work. The results were both amusing and revealing. Many participants carefully described dozens of activities but completely forgot one essential step—they never wrote down that they got dressed. The lesson has stayed with me for decades.

When we perform familiar routines, we unconsciously assume that important steps will simply happen. Only when we analyse a process carefully do we discover the small omissions that can cause the entire system to fail.

Modern cybersecurity is remarkably similar.

Most major breaches do not occur because organizations lack sophisticated technology. They occur because one seemingly insignificant action is overlooked by someone who never realized its importance. A single click on a phishing email, an unverified identity, a reused password, or an unauthorized AI application can bypass millions of dollars’ worth of security investment.

Technology can detect many threats. Only an informed workforce can prevent many of them.

The developments of the past eighteen months point to one unmistakable conclusion. Cybersecurity is no longer simply an IT issue, nor is it solely a matter of investing in more sophisticated technology. It has become a strategic leadership responsibility that reaches every level of an organization.

For many years I have argued that data is not information, information is not knowledge, and knowledge is not wisdom. Artificial intelligence can process extraordinary volumes of data and generate remarkable insights, but it cannot replace human judgment. It cannot assume responsibility, build an organizational culture, or create trust. Those remain uniquely human capabilities.

A recent article published by Cyber Security Intelligence observed that “the idea that a cyber attack could be existential is no longer a fringe view.” That statement deserves careful reflection. As organizations become ever more dependent on interconnected digital systems, the consequences of a major cyber attack extend well beyond financial loss or operational disruption. They can threaten an organization’s reputation, its customers’ confidence, its competitive position, and ultimately its very survival.

The organizations that succeed in the years ahead will not necessarily be those with the most advanced technology. They will be those that combine technological innovation with informed leadership, continuous education, and a strong cybersecurity culture that reaches every employee. Technology will remain an indispensable enabler, but people will determine whether it is used wisely. Ultimately, the future of cybersecurity will depend not only on stronger systems, but on stronger organizations built upon knowledge, judgment, resilience, and trust.

That recognition marks an important turning point.
Cybersecurity is no longer simply about protecting digital assets; it is about protecting the continuity and resilience of the enterprise itself.


Source: Cyber Security Intelligence,  Intrepid Explorers, LLC. – Research supported by ChatGPT

Also read:
Artificial Intelligence and the Industrialization of Cybercrime
Cyber Security: Majority Expect Cyber Attacks To Threaten Business Survival