What Is the Human Firewall? - Bistech

How empowering your employees can make them your greatest cyber security asset.

There’s an acronym sometimes used in the tech world: PEBKAC, or ‘Problem Exists Between Keyboard and Chair’. It’s a tongue-in-cheek way of saying that the issue isn’t with the technology itself, but with the person using it. And nowhere is that truer than in cyber security.

According to Mimecast’s State of Human Risk 2025 report, 95% of data breaches are caused by human error. That means most incidents come down to things like weak passwords, falling for phishing scams, or using personal email in inappropriate ways. It’s easy to see why employee mistakes are often viewed as one of the biggest threats to a company’s security.

But there’s another side to this. If human error is behind 95% of breaches, it also means 95% could be prevented by addressing the root causes of those mistakes. Instead of seeing your people as the weakest link, what if you saw them as your first line of defence — your business’s own ‘human firewall’?

Let’s break down what this term means, how to do it effectively, and the steps you can take to get started.

What is the human firewall?

Organisations have long deployed firewalls as part of their cyber security strategy, typically to protect the network perimeter by monitoring and controlling traffic based on set rules. But as cyber threats grow more sophisticated, often using tactics like social engineering, technical defences alone aren’t enough. What’s needed now is another layer of protection: the human firewall.

The human firewall refers to people making smart, cautious choices that help stop breaches before they happen. It’s a culture of awareness built through ongoing education and shared responsibility across the entire organisation, not just one person or team.

True cyber resilience depends on this human element. When every employee is trained, informed, and alert, they can spot the kinds of suspicious activity that automated systems might miss, like emotionally charged messages or unusual language designed to trick someone into clicking a malicious link.

How to create a human firewall

The concept behind a human firewall is to turn employees from potential security vulnerabilities into a strong first line of defence against digital threats. This involves several key steps:

  • Providing employees with regular training to help them recognise and respond to a variety of threats, from AI-generated phishing emails and malicious attachments to suspicious links and social engineering tactics. This effort is most impactful when led from the top — senior leaders who take the time to engage in training and awareness send a strong message that everyone, at every level, plays a vital role in keeping the organisation secure.
  • Identifying high-risk team members for targeted training; as identified in Mimecast’s report, just 8% of employees account for 80% of incidents.
  • Promoting secure habits in day-to-day work. This includes using strong, unique passwords (ideally handled by a password manager), enabling multi-factor authentication, locking screens when stepping away, and avoiding password reuse across different platforms.
  • Creating a culture where employees feel comfortable reporting anything suspicious right away. Delays caused by fear of blame or embarrassment can be costly.
  • Running controlled simulations to see how employees respond in real-world scenarios. These exercises highlight areas for improvement and help reinforce learning in a more memorable way.
  • Writing cyber security policies in plain, straightforward language, making them easy to access, and regularly reinforcing them. When people understand what’s expected of them — and why it matters — they’re far more likely to follow through.

What’s the missing piece in most human firewalls?

Many businesses understand the importance of the steps above, but delivering the depth and personalisation required for effective training can be a challenge. According to Mimecast’s report, 94% of organisations say they struggle to get employees to consistently follow compliance standards and security protocols.

So, why is this the case?

Often, it comes down to using outdated, one-size-fits-all training approaches that fail to resonate with different roles and risk profiles. To make an impact, training needs to be personalised, realistic, and role-specific – moving beyond just raising awareness to creating real, lasting behavioural change.

This is where a Human Risk Management (HRM) platform can make all the difference.

How can Human Risk Management platforms help?

A HRM platform is software that helps identify, assess, and mitigate vulnerabilities caused by employee actions, whether intentional or unintentional.

HRM platforms offer a range of features to strengthen the human side of cyber security. One leading example is Mimecast’s HRM platform, which:

  • Continuously monitors employee activities to provide real-time insights into their behaviour and risk levels. The Mimecast Engage section of the platform scores users based on risk, so that businesses can make sure the right support reaches the right employees at the right time.
  • Uses video-based training and continuous feedback loops to keep employees informed about evolving threats, reinforce best practices, and highlight areas for improvement – all essential for building a proactive security culture.
  • Quantifies the effectiveness of training by tracking behavioural improvements, identifying remaining gaps, and ensuring that investments in security training deliver real-world results.
  • Supports the creation and enforcement of clear security and risk management policies, helping employees understand and adhere to acceptable behaviour standards.

Implementing an HRM platform can reduce the likelihood of data breaches, improve incident response times, support policy compliance, and foster a stronger overall security culture.

Planning the way ahead

Keeping systems secure means more than just 24/7 monitoring of firewalls and logs. With human error being such a major vulnerability, it’s worth rethinking the once-a-year approach to employee training and instead making it a continuous part of your security strategy.

At Bistech, we take a long-term, holistic approach to cyber security. We work closely with our customers to build custom, multi-layered defences that align with their broader business goals, both on the technical and human front.

If you’re looking to improve your security strategy, book a call with us today.

 

Book a call today


Shaun Farrow, Practice Lead

Shaun Farrow works with customers to strengthen their cyber security posture, combining hands-on engineering expertise with a consulting approach. He leads the growth and direction of Bistech Managed Security, supporting solution design and translating complex challenges into clear, practical guidance. Shaun focuses on security, governance, risk and compliance, and how frameworks such as NIST CSF v2 support informed, senior-level cyber security decisions.