Cybersecurity Awareness Starts With People: Why Businesses Must Keep Humans In The Loop

Authored by Martha Peterson, Security Incident Program Manager at Pipedrive

 

Cybersecurity Awareness Month is a timely reminder that protecting a business is not solely the responsibility of the IT or security team. In an increasingly connected workplace, every employee who handles customer information, uses business software or interacts with digital systems has a role to play in keeping an organisation secure.

At a time when one in three businesses are being hit by cyber attacks, this is particularly important for SMBs. While larger organisations may have dedicated security teams and extensive resources, smaller businesses are often managing security alongside a range of competing priorities. They may not have the budget, expertise or capacity to respond to every emerging threat with a new tool. For these businesses, building a culture of awareness can be one of the most effective ways to strengthen their resilience.

 

 

Security Is Everyone’s Responsibility

 

Phishing and social engineering remain among the most common ways for attackers to gain access to organisations. These attacks do not necessarily rely on sophisticated code. Instead, they exploit trust, urgency and routine: an email that appears to come from a colleague, a message asking for sensitive information or a link that looks legitimate at first glance.

Technology can help identify and block many of these threats, but it cannot replace informed decision-making. Employees need to understand what suspicious activity looks like, when to pause before responding and how to report a potential incident. Regular training should therefore be practical and relevant to the way people work, rather than treated as a one-off compliance exercise.

Alongside threat-detection training, businesses should establish a strong foundation of basic security hygiene. Multi-factor authentication, antivirus protection, encryption, regular software updates, good password hygiene and appropriate access controls are all important safeguards. Organisations should also ensure that employees only have access to the information and systems they need to perform their roles. Limiting unnecessary access can reduce the potential impact if an account is compromised.

However, security cannot be reduced to certifications or a box-ticking exercise; it must be part of how an organisation operates every day. The overall goal should be to make security a culture, building a strong human firewall where employees feel informed, confident and supported to make responsible decisions when handling data and using new technologies.

 

AI’s Role In Change

 

AI is reshaping the threat landscape, giving attackers new ways to create convincing phishing messages, clone voices for vishing attacks, generate AI deepfakes, automate scams and target organisations at scale. At the same time, businesses are using AI to detect threats, analyse patterns and automate repetitive processes. This creates both an opportunity and a challenge. AI can strengthen security, but it can create new threat vectors too.

Systems can make mistakes, produce inaccurate outputs or be manipulated by poor-quality or compromised data. As AI agents increasingly connect to other systems and tools, one of the biggest challenges is managing their permissions, particularly the risk of selecting “always allow” when executing code or granting access without human oversight. Human judgement remains essential to assess context, challenge recommendations and make informed decisions.

Pipedrive’s 2026 Hidden Cost of Selling report found that nearly 68% of professionals experience uncertainty about what to prioritise at least several times a week, while 58% spend three or more hours on administrative tasks that pull them away from customer-facing work. In this environment, security processes that are unclear, overly complicated or disconnected from everyday workflows are unlikely to be followed consistently.

The same report found that only 25% of respondents considered AI fully integrated into their daily work, with uncertainty about when AI-generated output could be trusted identified as the leading barrier to adoption. Professionals were most interested in AI acting as a co-pilot: 43% wanted it to draft emails, summaries and notes for human review, while 22% were uncomfortable with AI completing tasks autonomously.

Cybersecurity awareness needs to keep pace with the way AI is being used. The aim is not to make every employee a cybersecurity expert. It is simply to ensure that people know what to look for, understand when to pause and have a clear route for getting help.

 

The Foundations of Good Security Hygiene

 

Employees should know how AI tools work, what information they can safely share and when a decision needs to be reviewed by a person. Businesses also need clear rules around sensitive data, access permissions, approved tools and accountability. Regular checks are important too, particularly around how AI systems are trained and updated, to make sure inaccurate or manipulated information is not affecting their outputs or exposing confidential data.

Cybersecurity Awareness Month is a good time for businesses to review their security processes and refresh employee training. It is also an opportunity to consider whether their use of AI is transparent and properly overseen. Technology can help organisations spot threats earlier, but it cannot replace human judgement. Employees still need to understand the situation, question unusual results and decide what action to take.

As AI becomes more common, keeping people involved in those decisions will remain important. Businesses that invest in security awareness, responsible use of technology and a broader range of cybersecurity talent will be better placed to protect their data and maintain customer trust.