Not on their own.
Employees are often involved when a cyber incident begins because they use the email, applications and data that keep the business moving. But describing employees as the biggest cybersecurity risk can hide a more useful question:
What allowed one understandable action to become a serious business problem?
Why does the phrase persist?
Many incidents can be traced to a recognisable human moment. Someone follows a convincing link, approves an unexpected request, sends information to the wrong recipient or uses a password that has already been exposed elsewhere.
That makes the person easy to identify as the point of failure. It does not necessarily make them the underlying cause.
People work quickly, rely on familiar patterns and make decisions with limited information. These are not unusual behaviours that can simply be trained away; they are part of ordinary work. A business cannot build its security around the assumption that every person will recognise every unusual request, every time. Security Awareness Training and phishing simulations do help (and should be part of your overall strategy.
The same action can have very different consequences in two businesses.
If an account has broad access, an unfamiliar device can connect without challenge, important data is widely shared and unusual activity is not reviewed, one compromised identity may provide a route into much of the organisation.
In a better-managed environment, the same incident may be contained. Strong authentication creates another check. Role-based permissions limit what the account can reach. Managed devices provide useful context. Application and network controls restrict movement. Monitoring helps someone notice that behaviour has changed, while tested recovery arrangements provide a way back to normal.
The employee has not become more perfect. The environment has become more forgiving.
Where does training fit?
Security training still matters. It helps people recognise unusual situations, question requests and know how to report something that feels wrong. Phishing simulations make spotting and reporting suspicious messages more habitual.
But training should support good system design, not compensate for its absence. Asking employees to carry the whole burden of security is neither realistic nor particularly fair.
The aim is not to turn every employee into a cybersecurity specialist. It is to give people clear processes, sensible controls and an easy route to ask for help.
A better question for the business
Instead of asking, “How do we stop employees making mistakes?”, ask:
Can people complete normal work without bypassing controls? Is access limited to what each role needs? Would unusual behaviour be noticed? Can a concern be reported without blame or delay? If something does go wrong, how far could it spread—and how quickly could the business recover?
People will always be part of cybersecurity because people are part of the business. They may also be the first to recognise that something is not right.
The goal is not to remove human judgement. It is to create an environment in which good decisions are easier, unusual activity is visible and one ordinary mistake does not become an extraordinary disruption.

