RSS Amplifier

Audience 1st · Mar 18, 2026

Why Human Risk Will Define the Next Decade of Security

0
Sign in to vote or save

Dani Woolf · Audience 1st

This episode is presented together with:

Secure Human Risk—all in one platform.

Identify high-risk users and guide them to smarter security choices with a unified platform.

Learn More

When I sat down with Masha Sedova to record this episode of Audience 1st, I was not expecting to walk away with the kind of clarity that made me want to immediately pick up my pen and go deep.

I was expecting a good conversation about security awareness, a category I understand, with a guest I respect.

What I got instead was a genuinely uncomfortable realization that I, someone who has spent years inside the cybersecurity marketing machine, had been operating with the same broken mental model as everyone else.

What follows is not a product review of Mimecast. It is not a puff piece on Masha, though she is unquestionably one of the sharpest people working in this space right now.

This is a structured attempt to surface what this conversation actually revealed about the state of human risk management as a category, the structural failures that allowed the problem to compound for three decades, and the commercial, philosophical, and organizational implications for everyone from CISOs to founders to the VCs writing checks into this space.

68% to 72% of breaches trace back to the human element, year after year, and the primary intervention has been mandatory training and simulated phishing.

We give people mandatory training and then cross our fingers and hope for a different outcome, Masha says.

But I think the industry gets off too easy when we treat this as simply a technology gap. The real scandal is that the metrics were deliberately insufficient, and the people running these programs understood that at some level and kept reporting them anyway.

Training completion rates are not a proxy for security risk reduction. Neither are phishing simulation click rates.

Security leaders have known this intuitively for a long time and yet these metrics persisted in board decks and QBRs and vendor dashboards for decades.

They persisted because they are measurable. Numbers travel well up the chain of command, they satisfy compliance requirements, and they require no uncomfortable conversation about the gap between what an employee knows in a training environment and what they actually do at 4:47pm on a Tuesday when an urgent vendor invoice lands in their inbox.

The industry optimized for reportability instead of truth, and that is a choice that accumulated into thirty years of largely preventable breach exposure.

This matters enormously for anyone in go-to-market. When a security leader has spent years presenting training completion rates to their board, a vendor asking them to adopt a platform that measures something fundamentally different is also asking them to walk back everything they previously said was working.

That conversation has real political cost inside their organization. Most security vendors have dramatically underestimated that cost, and as a result they are pitching a product problem when the actual obstacle is an organizational one.

Masha used the phrase ‘learned helplessness’ to describe the posture of CISOs who have tried to invest in the human element and come up empty.

Security teams have run awareness programs, iterated on phishing simulations, hired communications professionals, gamified training modules, and watched the breach statistics barely move.

After enough cycles of that, the rational response is to lower your expectations and redirect budget toward something that shows cleaner ROI.

That is what happened across the industry and that scar tissue is still very much present in the buying population today.

The problem for anyone selling into this space is that learned helplessness is invisible until it surfaces in an objection.

A CISO does not walk into a demo and say they are skeptical of this category because they have been burned before.

They say things like we are not ready for this yet or we need to get our fundamentals right first.

They ask for case studies from organizations that look exactly like theirs.

They slow-walk approvals.

They send you to procurement.

Understanding that these behaviors are expressions of accumulated disappointment changes everything about how a sales team should structure discovery, how marketing should build content, and how a CEO should think about the length of their sales cycle.

The human risk management category has a trust deficit that predates its own existence and that is genuinely unusual.

Most new categories are selling against ignorance.

This one is selling against experience.

The implication for founders and GTM leaders is that demand generation is table stakes.

Credibility generation is the actual job and it takes longer than most growth models account for.

The status quo is bullshit and we need to do something differently.

Eight percent of the workforce causes eighty percent of incidents.

When Masha said this, I felt the weight of it immediately and I want to make sure we are not just treating it as a memorable data point, because its implications run much deeper than most people initially clock.

If 8% of your people are responsible for 80% of your risk, then 92% of your people are absorbing security friction - complex password requirements, MFA prompts, endpoint monitoring, content scanning, restricted browsing - for incidents they are not causing.

The security tax on the majority of your workforce is protecting you from a minority, at the cost of speed and productivity for everyone else.

Standard security investment models treat the whole population as roughly equivalent in risk.

Controls are applied uniformly.

Policies are written for the most vulnerable users.

The 8/80 rule suggests this approach is actively counterproductive, because the friction imposed on low-risk users creates organizational drag without a corresponding security benefit.

Meanwhile, the 8% who are actually driving incidents may be receiving the same experience as everyone else, just with a slightly different click rate on their phishing simulations.

For vendors, the 8/80 rule opens a pricing and packaging conversation that nobody has fully solved yet.

If a CISO can identify their highest-risk population, they should be willing to pay a meaningful premium to apply intensive intervention specifically to that group.

The challenge is that identifying that population requires a data infrastructure that most organizations have not yet built, which means the first sale is often the instrumentation layer itself.

That requires a fundamentally different value conversation than replacing an awareness training platform, and most vendors have not restructured their pitches around it.

Masha reached for the credit score and driver’s insurance analogies to explain how we already quantify individual risk in other domains and as a positioning move it is genuinely excellent.

It normalizes scoring people on their security behavior by connecting it to systems audiences already trust and understand.

It makes human risk feel less like surveillance and more like infrastructure. I understand why she made that choice and in a podcast context it lands well.

But I want to push back here, because the analogy has limits that the industry needs to confront before it scales this category.

Credit scores have a deeply troubled history.

They have been shown to encode racial and socioeconomic bias.

They have been weaponized by lenders in ways that harm vulnerable populations.

They are contested, disputed, and subject to regulatory scrutiny across multiple jurisdictions.

The reason they feel neutral and inevitable is a function of decades of normalization, not inherent fairness.

Importing that analogy into the workplace, where the power dynamics between an employer and an employee are fundamentally asymmetrical, should give everyone in this space serious pause.

An employee who scores as high risk because they click more links, use personal devices, or handle data differently than their peers may be exhibiting those behaviors because of workload, stress, cognitive overload, or a job design that forces them to move fast in environments where security is inconvenient.

Scoring them without understanding context identifies the symptom while completely missing the cause.

The vendors who build enduring, trusted platforms in this category will be the ones who bake interpretive guardrails into their frameworks, not just dashboards that surface who is risky, but honest thinking about why, and what the responsible uses of that data actually are inside an organization.

This is a regulatory, reputational, and ethical risk the category needs to get ahead of now, while it is still early.

Thanks for reading Audience 1st! This post is public so feel free to share it.

Share

When Masha walked through the four personas - negligent, malicious, targeted, and compromised - she framed it as a way to organize security strategy.

And it is useful for that purpose.

But I want to name what is also happening underneath the surface, because it is instructive for anyone thinking about category creation and platform strategy.

Each of the four personas maps precisely onto a distinct security product category.

Negligent users need awareness and training tools.

Malicious insiders require DLP and insider threat solutions.

Targeted users need email security and identity protection.

Compromised users require incident response infrastructure.

Mimecast, through three acquisitions - Elevate Security, Code42, and Aware - now owns meaningful tooling that addresses each of those four personas.

The four-persona framework gives a CISO the conceptual structure to understand why they need all four product categories, and it positions Mimecast as the only vendor that currently connects those categories under a unified human risk signal.

For founders building in adjacent spaces, the lesson is significant.

When a vendor gets their theoretical framework adopted as the standard way the industry thinks about a problem, they have structured the competitive landscape so that their platform becomes the logical conclusion.

The framework becomes the moat.

This is what Salesforce did with the CRM category, what Palo Alto has repeatedly done with platform consolidation narratives, and what Mimecast is now attempting in the human risk space.

Whether they execute on it is a separate question, but the strategy itself is worth studying carefully.

One of the moments I found most interesting in this conversation was when Masha said that we need to stop treating employees like toddlers and start giving them genuine agency over their own cybersecurity journey.

She is right that this framing shift matters and the contrast with the gamified, infantilizing aesthetic of most security awareness training is valid and overdue.

In the same conversation, Masha also described a nudge mechanism that sends real-time training to an individual employee, calibrated to arrive no more than once per hour, attempting to catch them in the moment following a risky behavior.

She acknowledged the delicate balance between effective and annoying as hell.

My question is whether a system that monitors employee behavior in real time, calculates a risk score, and delivers behavioral correction prompts at algorithmically determined intervals is actually treating that employee like an adult.

I am not arguing that nudges are wrong.

The behavioral science behind them is legitimate, and the intent - helping people make better decisions in moments of real vulnerability - is sound.

But the inconsistency between the philosophy and the product experience is something human risk vendors need to resolve explicitly rather than hand-wave past.

The employees who engage most productively with these platforms will be the ones who understand what is being measured, why it matters, and how they can genuinely improve their standing over time.

Masha made an interesting observation about why human risk resonates in the boardroom:

Board members have been attacked personally and they have family members who have made security mistakes.

There is a depth of lived experience in that room that does not exist for most other security categories.

Board-level anxiety about cybersecurity has been elevated since approximately 2019 and spiked significantly during 2020 through 2022 as remote work dramatically expanded the attack surface.

The personal dimension of that anxiety - executives being targeted individually through spearphishing, whaling attacks, and deepfakes - created a kind of attention that is distinct from the general ‘are we getting breached?’ concern that drove earlier generations of security investment.

Boards have transitioned from seeing cybersecurity as an IT risk to experiencing it as a personal vulnerability.

That transition is what makes the human risk conversation resonate so deeply right now and it is a transition that happened recently enough that most security vendors have not figured out how to fully leverage it.

One of the more candid moments in this conversation came when Masha addressed the decision to operate as an open ecosystem, pulling data in from CrowdStrike, Okta, Netskope, and others, and sharing enriched human risk scores back out to those platforms.

She was explicit that many competitors have chosen closed ecosystems and that from a pure revenue-maximization standpoint, that makes rational sense.

Closed ecosystems sell more products. Open ecosystems are more useful to the customer but give away data that could otherwise be a retention lever.

I think Masha is right that customers should see a closed ecosystem for exactly what it is.

But the commercial risk is real and worth naming honestly.

When Mimecast shares enriched human risk scores with a platform like CrowdStrike, they are making it easier for that customer to evaluate whether they need Mimecast at all, or whether the risk signal coming through the integration is sufficient for their use case. Some customers will decide it is. That is the tax on openness, and it compounds over time.

The counterargument, and this is the bet Mimecast is making, is that in cybersecurity trust is the ultimate currency, and an open ecosystem builds trust faster than any marketing campaign can.

Security practitioners talk to each other constantly.

A CISO who discovers that a vendor withheld data interoperability to protect its moat will tell colleagues before the week is out.

A CISO who discovers a vendor gave away competitive data because it was the right thing to do for the customer will become an advocate.

In a category still at 10% adoption where the primary barrier is credibility earned over time, that bet might be exactly right.

But it requires conviction and patient capital, and not every CEO or board is built for that kind of long game.

I believe this is the most underappreciated dimension of this entire challenge and it is one Masha touched on but that I want to push much further.

The phrase ‘humans are the weakest link’ has been the foundational assumption of security culture for three decades.

It has shaped hiring decisions, product roadmaps, vendor pitches, board presentations, and the unspoken psychology of every security awareness training session ever conducted.

It is also one of the most damaging things the security industry ever said out loud and the field has not fully reckoned with the consequences.

When you institutionalize the idea that humans are inherently the problem, you create downstream cultural consequences that are very hard to undo.

Security teams stop investing serious analytical energy into understanding human behavior because the conclusion feels predetermined - people will fail, the training will not stick, and the best you can do is contain the damage.

Employees absorb the message and disengage, because who wants to bring full engagement to a role where they have been publicly designated the weakest link in the system?

CISOs stop fighting for budget in this area because the track record looks like thirty years of diminishing returns.

The cultural debt accumulates, and by the time a smarter framework arrives, the organization’s immune system is already primed to reject it.

Masha’s reframe - from ‘humans are the weakest link’ to ‘humans are a quantifiable, manageable risk category with distinct personas, data-driven interventions, and the capacity to participate in their own security journey’ - is not just intellectually more sophisticated.

It is psychologically more generous.

And in a field where the implementation of security practices depends almost entirely on human cooperation, psychological generosity toward the people you are trying to protect turns out to be a surprisingly practical strategy.

The founders, vendors, and CISOs who internalize this shift first will build programs and products that earn genuine trust from employees, and that earned trust is what eventually moves the needle on actual security posture, which is what this whole conversation has been about.

I do not use the word seismic lightly.

Human risk management represents a genuine paradigm shift in how the security industry thinks about its most persistent and underserved problem.

The structural conditions for mainstream adoption are either already in place or rapidly accelerating:

The breach statistics demand a different approach, the analyst community is formalizing the category, the acquisition activity is consolidating the necessary tooling, the board-level attention is at a historic high, and the early practitioners are starting to generate proof points that will pull the next wave of buyers in.

Paradigm shifts are not self-executing, though.

They require people who are willing to publicly retire the old model, even when doing so is politically uncomfortable inside their own organizations.

They require vendors who can build trust before scale rather than the other way around.

They require CISOs willing to adopt a strategy that is still being defined, knowing they will need to help define it.

And they require investors who understand that category creation at this level of complexity has a longer feedback loop than most enterprise software bets.

What Masha described in this episode is a reorientation of how an entire industry thinks about people.

That is harder to build, harder to sell, and harder to sustain than any technology platform, and it is precisely why, when it works, it becomes nearly impossible to displace.

The early movers in this category are positioning themselves at the center of the next major shift in enterprise security strategy.

That is worth paying very close attention to, right now, before the window closes.

Leave a comment

Read the original on audience1st.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.