Andy Booth

~ Thursday, October 8, 2026

Cybersecurity Awareness Month

October is Cyber Security Awareness Month, and while businesses continue to invest in firewalls, antivirus software and advanced security tools, there remains one line of defence that technology can never replace: people.

It is easy to assume that cyber security is an IT problem. In truth, every member of staff plays a part in protecting their organisation. That is why security professionals often talk about the human firewall: the collective awareness and actions of employees that prevent attacks from succeeding.

Why attackers target people

Modern security systems are incredibly effective at blocking known threats, but cyber criminals know that convincing a person to click a link, share information or approve a request can sometimes be easier than bypassing technical controls.

The goal of an attacker is often simple: create just enough urgency, curiosity or trust to bypass someone's natural caution. A phishing email may appear to come from IT support. A text message may claim to be from a courier delivering a parcel. A phone call might sound like a colleague, supplier or even HMRC. The method changes, but the objective remains the same: convince someone to act before they stop and think.

The Rise of Spear Fishing

Most people are familiar with phishing emails, but today's attackers have become much more targeted.

Spear phishing uses publicly available information such as your name, role, organisation and social media profiles to create highly convincing messages. Rather than sending the same email to thousands of people, attackers craft messages specifically for individual targets.

A typical spear phishing attack follows four stages:

1.The attacker researches the target.
2. A convincing message is created using information they have gathered.
3. A malicious link, attachment or request is delivered.
4. If the victim responds, access to accounts, data or funds can be gained.

The most dangerous part is that the message may look completely legitimate.

How to spot a phishing email

Many phishing emails follow predictable patterns once you know what to look for.

• A sender address that does not match the organisation it claims to be from.
• Language designed to create panic or urgency.
• Requests to verify credentials or provide sensitive information.
• Links that point somewhere different from where they appear to go.

One of the easiest and most effective checks takes just a second:
hover over the sender's address and any links before clicking. This reveals where the email actually came from and where links will really take you. If something does not look right, do not click.

The Threat of MFA Fatigue

Multi-Factor Authentication (MFA) is one of the best defences against account compromise. Even if your password is stolen, attackers still need a second approval from your device.

Unfortunately, criminals have developed a technique known as MFA fatigue. This works by repeatedly attempting to log into an account, generating a stream of approval notifications on the victim's phone. After receiving repeated prompts, some users eventually approve one simply to make them stop.

In some cases, attackers even contact victims pretending to be IT support and claim the notifications are part of a system issue that needs approval to resolve.

If you did not initiate the login, never approve the MFA request.

Passwords still matter.

Many successful cyber attacks start with a password obtained from an old data breach. Attackers regularly use leaked credentials from one service and try them elsewhere, hoping people have reused the same password across multiple accounts.

Using a unique password for every account dramatically reduces this risk. Better still, use a password manager to generate and store strong passwords for you.

Building a Strong Human Firewall

Cyber security is not about turning everyone into an IT expert. It is about building a few simple habits that become second nature.

• Pause before clicking links or opening attachments.
• Verify unusual requests through another communication channel.
• Never approve unexpected MFA notifications.
• Use a unique password for every account.
• Report suspicious emails, texts or phone calls immediately.

Perhaps most importantly, organisations need a culture where staff feel comfortable reporting concerns. Security incidents are often prevented because someone spoke up early. A false alarm is always preferable to an unnoticed breach.

The human firewall is your strongest defence.

Technology will continue to evolve, but attackers will always look for ways to exploit human behaviour. Firewalls, antivirus software and security platforms are essential, but they can only do so much.
The strongest defence comes from employees who pause, question and report when something does not seem right. Cyber security is no longer just an IT responsibility. Every member of staff is part of the human firewall, and that human firewall is often the difference between stopping an attack and becoming its next victim.

Need help strengthening your organisation's human firewall?

Naglotech can support your team with phishing simulations and security awareness training, helping employees recognise and respond confidently to common cyber threats.

By combining practical exercises with ongoing education, we help build a security-conscious culture where your people become an active line of defence against phishing attacks, social engineering and other cyber risks. Whether you're looking to meet compliance requirements, reduce risk or improve cyber resilience, our team can help.

Get in touch today to discuss how we can help protect your business.