The Human Firewall Is a Myth: Designing Security for Actual Human Behavior

For more than two decades, businesses have invested substantially in security awareness programs aimed at transforming employees into a "human firewall." Nonetheless, phishing attacks, credential theft, and social engineering continue to occur at an alarming rate. If awareness training works, why do users continue to make the same security mistakes?

This session questions the human firewall notion and investigates whether the issue is not with users, but with how security programs are structured. Drawing on human factors research, behavioral psychology, and real-world cybersecurity examples, the session investigates how cognitive overload, time constraints, decision fatigue, and conflicting workplace objectives influence security-related choices.

Rather than expecting faultless behavior from fallible individuals, attendees will discover how organizations can create security systems, procedures, and cultures that can withstand human error. The presentation provides a realistic, human-centered approach to cybersecurity that goes beyond blame and awareness metrics to design security around how people think, work, and behave.

Whether you are a security practitioner, management, developer, or researcher, this presentation will challenge long-held assumptions and deliver actionable insights into developing more effective and realistic security tactics.


For years, organizations have relied on the concept of the "human firewall" as a foundation of their cybersecurity strategy. Employees are required to spot phishing emails, avoid social engineering attacks, adhere to security standards, and serve as the final line of defense against cyber threats. Despite enormous investments in awareness campaigns and phishing simulations, human-focused attacks remain one of the most effective attack vectors.

This session investigates the disparity between cybersecurity expectations and actual human behavior. Drawing on human factors, behavioral psychology, and cybersecurity awareness studies, the session investigates why educated and well-trained people continue to make security blunders. Cognitive overload, decision fatigue, time constraints, trust exploitation, and workplace diversions will be discussed to demonstrate how attackers successfully target human behavior rather than technical vulnerabilities.

The presentation contends that many security initiatives are based on an unrealistic assumption of faultless user behavior. Instead of striving to eradicate human mistake, organizations should concentrate on developing systems, processes, and security measures that anticipate and accommodate typical human behavior.

Participants will get a better understanding of the limitations of traditional awareness approaches, why security failures are frequently systemic rather than individual, and practical ways for developing more resilient, human-centered security programs.

The key subjects include:

-The origins and assumptions of the "human firewall" idea.

  • Why awareness training alone is often ineffective.
  • Human aspects and behavioral influences on security decision-making.
  • Common misconceptions regarding user mistake.
  • Designing security mechanisms that are resistant to human error.
  • Creating a security culture that empowers rather than condemns users.

This seminar is intended for cybersecurity experts, security awareness practitioners, researchers, managers, and anybody interested in understanding the human side of security.

The speaker's profile picture
Endurance Imasuen

Endurance Imasuen is a cybersecurity professional with a background in Computer Science and an MSc in Cyber Security with Human Factors from Bournemouth University. He has experience spanning software engineering, IT support, and cybersecurity education, with a focus on translating technical security concepts into practical, user-centred understanding.

His work and research interests centre on human factors in cybersecurity, particularly phishing behaviour, security awareness effectiveness, and the design of systems that better reflect real human decision-making. He is currently developing a phishing-awareness platform aimed at improving how individuals and organisations recognise and respond to social engineering threats.

Endurance is passionate about bridging academic research and real-world cybersecurity practice, with a focus on security culture, behavioral change, and more realistic approaches to organizational security.