Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal

17 August 2025

3 minutes read time

Why people are the weakest link in cybersecurity?

I’ve been Chief Operating Officer at CloudTech24 for over eight years and have played a key role in its growth from a team of three people in 2018 to a business of 45 and growing today. During that time, we’ve achieved more than 25 times revenue growth while building a reputation for delivering high-quality managed IT and cyber security services.

My career began in sales and IT support before progressing into website hosting, technical pre-sales and leadership. That experience has given me a broad understanding of both the commercial and technical aspects of running a successful technology business.

As Chief Operating Officer for CloudTech24, I lead our operations, technical services and customer experience. I’ve helped shape our technology strategy, securing Microsoft Tier 1 Direct Partner status, Microsoft Modern Work Solutions Partner and Security designations, while maintaining our Google Workspace partnership and introducing new technologies that continue to strengthen our services.

I’m passionate about building high-performing teams, improving the way we work and using automation and AI to help businesses become more efficient, secure and resilient.

In my spare time, I enjoy playing 7-a-side football, keeping up with the latest tech and gadgets, and spending time with my two Maine Coon cats. I’m also a long-time Call of Duty fan, especially from the OG Verdansk and Rebirth Island days.

Read blogs in other categories

Why are people the weakest link in cybersecurity?

New technology brings new cyber threats, and what follows is a tightening of cybersecurity measures to keep your data safe. But despite stronger security systems and advances in technology, there is still a lack of guidance around human behaviours in cybersecurity.

This post looks at why people are the most exploited vulnerability in cybersecurity. We’ll cover what makes people the weakest link, the most common human errors, and why the errors are damaging.

What makes people the weakest link in cybersecurity?

Cybersecurity systems are robust – programmed and coded to do something without overcomplication. But the people who rely on these systems are unpredictable, with an innate trustworthiness which can be exploited. 

A lack of cybersecurity knowledge, coupled with sophisticated tactics from hackers, such as creating urgency or mimicking trusted individuals, can lead to significant data security issues that no amount of technology can compensate for.

What are the most common human errors in cybersecurity?

Weak passwords

Weak, predictable, and often reused passwords can compromise your data massively.

Passwords like “123456” or “111111” are among the most common passwords that can be cracked in under a second by a cybercriminal.

Following that, passwords that include your pet’s name, or your favourite football player, followed by “123” aren’t a great alternative either, as they’re only slightly stronger, taking a couple of seconds to crack. 

Use a password manager with a strong password generator that creates and safely stores a strong, unique password. That way, you won’t have to remember a jumble of numbers, letters, and special characters, and your accounts stay secure.

No two-factor authentication (2FA)

Many people skip setting up two-factor authentication, leaving their accounts protected by just their password. Even with a strong, unique password, if a cybercriminal gains access, then they have free rein over your account.

2FA and MFA (multi-factor authentication) are an extra layer of security that protects you even if your password has been compromised.

Using your mobile phone number or an authenticator app, you can easily put the protection in place to prevent cybercriminals from accessing your account

Read more: What is two-factor authentication, and why is it important?

Phishing attacks

Phishing attacks often catch humans off guard. Playing into impulsive human behaviours like creating urgency to do something, a cybercriminal can prompt you to click a link filled with malware or send over personal information.

How do you counter these if they slip through the cracks? Simple. Double-check these emails for spelling errors, strange-looking attachments, and an email address that is slightly off.

Read more: 7 ways to spot a phishing email

Why are these errors so damaging?

Your business can suffer significant damage due to human errors in cybersecurity, which begins with a data breach. This can result in financial loss, possible reputational harm to your business, and regulatory penalties.

Human errors caused some of the most costly data breaches.

The recent Marks and Spencer ransomware incident (2025) was caused by compromised employee details that resulted in disruption to payment systems and online orders. This led to financial loss, service disruption, and the exposure of customers’ personal information. So, how do you prevent human errors from damaging your business?

  • Provide regular cybersecurity training to your employees to keep them aware. By keeping them informed, you’re likely to suffer fewer issues with phishing and social engineering attacks.
  • Educate them on strong passwords and introduce a password manager along with MFA and 2FA for extra security.
  • Have a strong cybersecurity and IT support team by your side

A final thought

You can have the strongest security systems in place, but it only takes one unaware member of the team to fall victim to a cyber attack, and you could end up with a bill for lost revenue and long-term reputational damage. 

Keep yourself and your team informed to stay ahead of cyber attacks.

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more