Human Risk, Not Human Blame: Moving Past the ‘Stupid User’ Myth
Let’s be honest, calling users “the weakest link” has always been cybersecurity’s favorite pastime, right up there with blaming DNS and arguing about password lengths. But here’s the inconvenient truth, users aren’t stupid. They’re busy, overloaded, and constantly being targeted by professional criminals who only need one mistake to win.
In this talk, Erich Kron digs into the long-standing “stupid user” myth and shows why shame-based security not only fails but actively creates security risk. We’ll look at how guilt-driven training backfires, how fear-based messaging shuts down engagement, and why blaming users is the fastest way to ensure they never report an incident again, even their computer is literally bursting into flames.
Modern cybersecurity requires a culture shift, one rooted in empathy, behavioral science, and a realistic understanding of human limitations. Through real-world examples, research insights, and a few humorous war stories, we’ll break down what truly drives human behavior and how security teams can work with people instead of against them.
Attendees will learn:
• Why shame-based training fails and how it quietly increases risk
• The psychology behind human error and why mistakes are predictable
• How to build a security culture that encourages positive behavior, not fear
• Practical playbooks for Human Risk Management (HRM) that focus on reduction, not ridicule
• Communication strategies that engage people instead of alienating them
By the end, you’ll walk away ready to work on building a high-performing security culture where humans aren’t scapegoats, instead they’re empowered allies. And maybe, just maybe, you’ll never utter the phrase “stupid user” again… at least not out loud.
