The 2026 Verizon DBIR Just Dropped. The Human Element Number Has Not Moved. Maybe We Are Asking the Wrong Question.

The 2026 Verizon DBIR Just Dropped. The Human Element Number Has Not Moved. Maybe We Are Asking the Wrong Question.

The 2026 Verizon Data Breach Investigations Report landed this week. The human element is still the most frequent cause of breaches. Social engineering, phishing and stolen credentials continue to dominate the initial access vectors. The numbers have not moved in any meaningful direction.

This is the part of the security industry’s annual ritual that nobody wants to say out loud: we have known this for years. We keep publishing the same statistics. We keep responding with the same training programmes. The breaches keep happening at roughly the same rate.

The 2025 DBIR, which analysed over 22,000 incidents and 12,000 confirmed breaches, found the human element in 60% of all breaches. The year before it was 61%. The year before that, slightly higher. The trend line is essentially flat despite the fact that security awareness training has become a multi-billion dollar industry and virtually every organisation of any size now runs some version of it.

Before the training vendors compose their responses in the comments, this is not an argument that security awareness training is worthless. It clearly produces some benefit. User reporting increased fourfold in organisations with training programmes, according to the 2025 DBIR. That matters. It is also not the same as preventing breaches.

Here is what we think is actually happening.

We built security awareness training to address an information deficit. The assumption was that employees fall for phishing because they do not know what phishing looks like. Teach them what it looks like and they will stop clicking. That assumption was not unreasonable in 2010 when targeted social engineering was relatively rare and phishing emails were full of obvious spelling mistakes. In 2026 it is simply not the environment we are operating in.

The 2025 DBIR found that the median time for a user to fall for a phishing email is less than 60 seconds. The same report notes that the failure rate, meaning the click rate on phishing simulations, was unaffected by training in many measured cohorts. Attackers are not sending badly spelled emails about Nigerian princes anymore. They are sending AI-generated, context-aware messages that reference real projects, real colleagues and real deadlines. They arrive in moments of distraction, authority and urgency. The cognitive conditions that make humans susceptible to these attacks are not knowledge gaps. They are features of how human decision-making works under pressure.

Verizon also found that 8% of employees account for 80% of security incidents. That figure has been consistent across multiple reporting cycles. It tells you that the problem is not evenly distributed across a workforce. There is a subset of people, in specific roles, under specific conditions, who represent the majority of the risk. Generic training delivered to everyone equally does not solve a problem that is concentrated in a specific 8%.

What would it look like to actually respond to these findings rather than continue to respond to the findings we wish we had?

It would probably look like identifying the 8% before they cause the 80% rather than training everyone to the average. It would look like designing interventions around the conditions under which people make poor decisions rather than the information they lack. It would look like measuring behaviour change over time rather than training completion rates. It would look like accepting that some risk cannot be trained away and building technical controls that account for human fallibility as a constant rather than a correctable defect.

The Stryker attack this year involved no phishing at all. The Kali365 platform the FBI warned about this month is designed specifically to succeed after a user has already completed MFA successfully. These are not knowledge problems. They are architectural problems that training does not address.

None of this means stop training employees. It means stop expecting training alone to hold the line against threats it was not designed to counter. The human element staying at 60% year after year is not evidence that humans are ineducable. It is evidence that we have not yet built a response proportionate to the actual nature of the problem.

Leave a Reply

Your email address will not be published.