Cyberdise AG

Why the Employee Has to Become Part of the Security Stack

Published Date:

A warehouse employee checks a suspicious message on his phone while a signal labelled Employee Signal Sent reaches a colleague at a security workstation
When employees report what systems miss, their signals become part of the defense.

AI is pushing cyber defense to machine speed. The answer is not to remove people from the equation, but to turn human judgment into a security capability – to treat the human layer as part of the security stack.

IBM’s Cost of a Data Breach Report 2026 calls this year an “AI tipping point,” and the numbers explain why. Frontier AI models are compressing the time between vulnerability discovery and exploitation, while generative AI lowers the cost and expertise required to launch attacks. AI-driven attacks increased 56% over the previous year and added an average of USD 1.01 million to the cost of a malicious breach. Meanwhile, the global average breach cost climbed 12% to a record USD 4.99 million, reversing last year’s decline –  we looked at what a data breach costs in 2026 and why detection time drives so much of it separately.

That should trigger more than another round of security-tool spending. It should make us reconsider who — and what — belongs in the security stack.

AI does not make the user irrelevant. It makes the employee’s judgment more valuable.

Phishing still lands on a human decision point

For the fourth year in a row, phishing (including Smishing and Vishing / Deepfake Attacks) was the leading initial attack vector in IBM’s study. On top of this: voice and SMS phishing were involved in 17% of attacks and produced the highest average breach cost among the attack vectors: USD 5.29 million. Social engineering, including help-desk impersonation and MFA fatigue, accounted for another 13%. Among AI-driven attacks, deepfake and impersonation attacks represented 45% — the largest category.

A convincing message may pass an email filter. A realistic voice may reach an employee directly by phone. An attacker may combine email, SMS, Teams and a call into one coherent story. At that point, there is a human decision: engage, verify, refuse, delete — or report.

For too long, cybersecurity has often framed this moment primarily as a weakness to be managed. But there is another way to look at it. Employees see signals that technical systems may never see: a suspicious call, the unusual request, the strange conversation or the message that simply does not feel right.

If those observations can be captured, analyzed and connected to security operations, the workforce becomes an active part of cyber defense. The employee, and the signal they send, becomes part of the solution rather than part of the problem.

From security awareness to Behavioral Defense Engineering

Traditional awareness remains an important knowledge baseline. But knowledge alone is not the same as safe behavior under pressure. The real question is whether somebody recognizes an attack, reacts correctly and reports it quickly — which is why awareness training alone isn’t enough.

We call the systematic improvement of the behavior “Behavioral Defense Engineering”, or BDE. The idea is to improve measurable risk behavior through realistic, personalized exercises across multiple attack channels, while turning employee reactions and reports into useful security signals.

A randomized field study conducted with the Lucerne School of Business (HSLU) and funded in part by Innosuisse supports the approach. Among 539 employees assigned at random to a control group, a training group, a conventional phishing group and an AI-spearphishing group, realistic personalized exercises produced the largest behavioral change: click-through to a malicious site fell from 20.4% in the control group to 8.9% — 56% fewer — and credential entry fell by around 60%, from 9.8% to 3.9%.

The study’s second finding matters just as much. Training moved risk attitude but moved behavior least, while realistic exposure moved behavior most and barely touched attitude. These are distinct mechanisms, and the authors expect a program combining them to be additive or stronger. That is the argument for keeping awareness inside the system rather than replacing it.

This creates a different security loop.

The four pillars of Behavioral Defense Engineering: report and feedback, analyze and engage, simulate and exercise, educate and teach
Four pillars, one loop: reports become security intelligence, and real attacks become exercises.

An employee reports a suspicious message. AI analyzes it and can group multiple reports into a single case. The signal is passed into SOC or SOAR processes, where automated actions can block senders, remove malicious messages or trigger other containment measures. At the same time, the employee receives immediate feedback — and how that report happens, and what it contains, matters a great deal. A real attack can then be transformed into a safe exercise, even instantly. And related scenarios can be used later across phishing, smishing, vishing or other channels.

The result is not simply “more training.” It is a system in which employees, AI and security operations continuously learn from attacks.

Machine speed needs human signals

IBM’s findings underline why speed matters. Organizations making extensive use of AI and automation in security reduced breach costs by an average of USD 1.93 million and shortened identification and containment time by 65 days compared with organizations not using these technologies. Yet only 36% of breached organizations reported extensive use across the security lifecycle, and adoption remains uneven.

Machine-speed defense, however, should not mean machine-only defense.

Behavioral Defense Engineering is designed to connect the human layer to the rest of the security architecture. With API-first and AI-first principles, and deployment options that can also support on-premises environments, human reports, behavioral analytics, simulations and feedback can become part of existing SOC workflows rather than another isolated awareness platform.

The next security stack is therefore not just EDR, firewalls, identity systems, SIEM, SOAR and AI agents. It also includes the people who receive the message, answer the phone and notice that something is wrong.

The objective should not be to manage employees as the problem. It should be to engineer the environment in which they can become part of the solution.

 

Awareness creates knowledge. Behavioral Defense Engineering turns judgment and action into defense. And in the age of AI, speed contains.

FAQ: the human layer in the security stack

What is the human layer in the security stack?

The human layer is the set of decisions employees make when an attack reaches them directly — engage, verify, refuse, delete or report. It becomes part of the security stack when those decisions and reports are captured as signals and connected to security operations, rather than treated only as a training outcome.

Is the human the weakest link in cybersecurity?

No. That framing describes a program that never gave employees a way to contribute. We make the human part of the solution, not part of the problem. Employees see things technical controls do not — a strange call, an off request — and once reporting is easy and rewarded, they become the fastest detection layer an organization has.

What is Behavioral Defense Engineering (BDE)?

Behavioral Defense Engineering (BDE) is the systematic improvement of measurable risk behavior. It combines realistic, personalized exercises across multiple attack channels with a loop that turns employee reactions and reports into security signals feeding SOC and SOAR processes. Awareness training is a component within BDE, not something BDE replaces.

How is Behavioral Defense Engineering different from security awareness training?

Awareness training changes what people know. BDE changes what they do under pressure, and measures it. The two work through different mechanisms: in a randomized study of 539 employees, training moved risk attitude but moved behavior least, while realistic exercise moved behavior most and barely touched attitude. A program needs both.

How do employee reports reach the SOC?

An employee reports a suspicious message. AI analyzes it and groups related reports into a single case. The signal passes into existing SOC or SOAR processes, where automated actions can block senders, remove malicious messages or trigger containment. The employee receives immediate feedback, and the real attack can be turned into a safe exercise.

Sources

IBM, Cost of a Data Breach Report 2026 – The AI tipping point.

Pugnetti, C. and Stacho, P. (2025). Improving Cyber Risk Behavior through AI-Enabled Spearphishing – A Comparative Analysis. Institute of Financial Services Zug IFZ, Lucerne School of Business (HSLU), and Cyberdise AG. Funded in part by Innosuisse, grant Innocheck 73275.1 INNO-ICT.

CYBERDISE, Behavioral Defense Engineering press release, June 2026.

CYBERDISE, BDE security engineer use-case materials.

Enjoyed reading? Subscribe to our blog!