What if people weren't the problem in cyber security - but the ones we've failed to protect?
Groups like Scattered Spider and Lapsus$ have shone a light on the current MO for cyber threat actors. They don't want to breach systems by exploiting software anymore, they now get in – more than ever - by exploiting people.
For decades, the industry has treated human risk as something to reduce through blame, training, and rigid controls. But attackers aren't primarily exploiting technical controls, they're exploiting people. And the systems we've built leave humans as the blind spot. It's time to flip the narrative.