The Human Firewall Is Collapsing: Why Distraction Is Cybersecurity's Biggest Vulnerability
- By Erich Kron, KnowBe4
- September 23, 2025

Today's workplace offers plenty of distractions. Workers juggle Slack threads, Zoom meetings, deadlines, and notifications while trying to stay alert against increasingly sophisticated phishing attacks. The result is a setup for disaster, where even minor attacks can succeed.
In the rapidly changing world of cybersecurity, the focus has often been on rising threats such as ransomware, zero days, and now AI-generated deepfakes. However, a new report changes that perspective. The real danger isn’t lurking in advanced code or nation-state tactics; it is in the distracted minds of employees.
Distraction and security apathy: The twin catalysts of cyber risk
According to the Infosecurity Europe 2025 Findings report, distraction (43%) and a lack of good security awareness training (41%) are the main reasons employees fall victim to cyberattacks. A mere 17% of the participants blamed the complexity of threats.
This astounding discovery recontextualizes the cybersecurity debate: the biggest threat is not technical, it's human.
Employees today are bombarded by notifications, meetings, and requests to multitask. In this state of busyness, even simple phishing emails can hit their mark.
Cybercriminals are not just using technical skills; they are taking advantage of distraction, fatigue, and misplaced confidence. The most advanced threat actor doesn’t need to break your encryption; they just need to catch you off guard.
Phishing: Still the king of threats
While AI and machine learning have come to dominate cybercrime, phishing is still the most prevalent threat vector. An astonishing 74% of interviewed professionals named phishing as their most common challenge.
More telling, however, is the strategy: impersonation of executive leadership or established contacts was named by almost half of the interviewees. Malicious links and attachments were next in line. Though well feared, deepfakes and content generated by AI have yet to gain substantial traction.
This echoes the sentiment shared by Alan Shimel in his article, Distraction is the New Zero-Day where he says, “The firewall isn’t failing; the human firewall is.”
Cybercriminals aren’t necessarily getting smarter; they’re getting better at exploiting our cognitive overload.
The confidence paradox
Perhaps the most contradictory finding in the report is the confidence gap. Almost 90% of respondents expressed confidence in their ability to counter cyberattacks, even as breaches occur regularly and are well known. Overconfidence can be risky. It results in underinvestment in human-centered defenses and creates an unwarranted sense of security.
Budgeting blind spots
Encouragingly, 65% of organizations plan to increase their cybersecurity budget. The number one spending areas are email security (45%), security awareness training (37%), and cloud security (34%).

But there is a disconnect: whereas 32% think AI-based tools will have the most impact, only 26% are giving them priority for funding.
This misalignment between perceived effectiveness and actual investment reflects a broader issue. Organizations are preparing for tomorrow’s threats while still vulnerable to today’s. As the report puts it, “It’s like preparing for a hurricane while still dealing with daily rain.”
The AI tipping point
While only 11% of poll participants currently deal with AI-made threats, 60% worry about them. Deepfakes, fake identities, and AI-created phishing attacks are on the horizon. Companies see the storm approaching, but few have strengthened their human defenses.
The report suggests a two-part strategy: improve technical defenses and train staff to spot and respond to more sophisticated tricks. This requires more than just checking compliance boxes and using behavioral security metrics.
Business impacts beyond the breach
Effective cyberattacks do not only create operational downtime or lost data. They destroy customer trust and reputations, which are less measurable but more long-lasting. The report emphasizes that resilience planning should also consider reputation recovery and customer communication strategies, in addition to technical remediation.
Actions to Take: Constructing a Strong Human Firewall
To manage this complex threat environment, organizations need to take a proactive, human-centered approach.
- Embrace human risk management: Use platforms that combine technical controls with analytics of human behavior. Security is not all about firewalls. It is about knowing how humans work under pressure.
- Secure core security: Enforce phishing-resistant multi-factor authentication (such as FIDO), strong email security, and Zero Trust architectures. These are the building blocks of a secure environment.
- Prepare against AI threats: Develop detection and response functions to fight AI-enabled attacks. Control the use of AI tools in your organization to prevent unauthorized use.
- Establish organizational resilience: Develop and periodically exercise incident response plans that cover both technical failure and reputational damage. Cybersecurity is a business continuity matter.
- Build adaptive defenses: Prioritize flexible security solutions that can change with new threats. Rigid defenses cannot keep up with dynamic and evolving threats.
- Narrow the confidence gap: Substitute assumptions with facts. Employ third-party evaluations and practical phishing simulations to improve employee preparedness.
- Address digital distraction: Implement mindfulness activities and create workflows that facilitate concentrated decision-making. Security awareness should be an integral part of the cultural fabric, not an afterthought.
The greatest cyber threat is not lying in the far reaches of cyberspace. It is actually sitting at the workstation, where staff have to cope with perpetual overload and insufficient training. Organizations must move beyond seeing human error as something unfortunate or the cost of doing business. They need to recognize it as the main barrier to modern cyber defenses. In a world filled with deepfakes and AI deception, the busy worker is not a liability; they represent the new zero day.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Orla
Erich Kron, KnowBe4
Erich Kron is a CISO advisor at KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management with over 70,000 customers and more than 60 million users. A 25-year veteran information security professional with experience in the medical, aerospace, manufacturing, and defense fields, he was a security manager for the U.S. Army's 2nd Regional Cyber Center-Western Hemisphere and holds CISSP, CISSP-ISSAP, SACP, and other certifications. Erich has worked with information security professionals around the world to provide tools, training, and educational opportunities to succeed in information security.