top of page

Cybersecurity is no longer just an IT issue.

Aug 7
4 min read

Organizations have invested millions in technology to protect their systems. However, many serious incidents still begin in a surprisingly simple way: with a human decision made in just a few seconds. The great transformation in cybersecurity will not be purely technological. It will be cultural.

A few weeks ago, I took part in a meeting with the management committee of a company that had been immersed in a major digital transformation process for several months.

They had upgraded many of their systems, automated processes, introduced artificial intelligence in certain areas, and redesigned their technological infrastructure. For quite some time, the conversation revolved around innovation, productivity, and new projects.

Until someone asked an apparently simple question:

—Who is responsible for cybersecurity in the company?

The answer came almost automatically:

—The Head of IT.

No one questioned that statement. It was the logical answer or, at least, the one we would all have given a few years ago.

However, as the conversation continued, it became clear that perhaps the question itself was poorly framed.

Cybersecurity no longer has a single person responsible for it. Or, to put it another way, today we are all part of it.

When technology stopped being just a tool

For a long time, we understood digital security as a highly technical discipline. If the network needed protection, new firewalls were installed. If a virus appeared, antivirus software was updated. If a server failed, the IT department found a way to restore it.

That view reflected a reality very different from today’s. Technology played an important role within organizations, but it remained a tool that supported the business.

Today, by contrast, businesses depend entirely on technology.

Information moves through cloud platforms, meetings are held by video conference, teams work from different locations, and an increasing number of decisions are made using mobile devices.

Digitalization is no longer a one-off project. It has become the normal environment in which we work.

And that completely changes the nature of risk.

Major incidents often begin with small actions

When we examine many of the cybersecurity incidents affecting companies and organizations, it is striking to see that the problem does not always begin with a sophisticated technical operation.

In many cases, it starts with something far more ordinary:

  • An email that appeared to be genuine.

  • A file opened without checking where it came from.

  • A password reused for years.

  • A bank transfer approved too quickly.

  • A conversation held at the wrong time or in the wrong place.

They do not seem like major mistakes. They are small actions.

That is precisely why they are so difficult to prevent.

We all work with a certain sense of urgency. We reply to messages quickly, approve documents while taking another call, and share information because we trust that the person requesting it really is who they claim to be.

The speed at which we work has also changed the speed at which we make decisions.

And attackers know it.

Attacking trust before technology

Cybercriminals are devoting increasing effort to understanding how people behave. They want to learn about their habits, routines, professional relationships, and everyday actions.

To a large extent, this is what social engineering involves: exploiting a person’s trust before attempting to breach a security system directly.

An urgent message apparently sent by a manager, an invoice that seems to come from a regular supplier, or a call from someone claiming to belong to the technical support team can be enough to cause an incident.

It is an uncomfortable idea because it forces us to accept that even the best technology in the world cannot always compensate for a poor decision made in just a few seconds.

This does not mean that technology has become less important. Quite the opposite: it has never been more necessary.

It is simply no longer sufficient on its own.

Cybersecurity must become part of corporate culture

Organizations that manage these risks most effectively no longer view cybersecurity as the exclusive responsibility of the IT department.

They integrate it into employee training, corporate culture, and everyday working practices. They talk about security in the same way they talk about quality, risk prevention, or customer service.

This is not because every employee needs to become an IT expert, but because everyone makes decisions that can have consequences for the organization.

In fact, it is similar to road safety. Nobody expects us to understand the internal workings of an engine to drive responsibly. It is enough to understand a few basic rules and recognize that our decisions also affect the people travelling with us.

The same principle applies in the digital environment.

Check before you act

Creating a security culture does not mean working in constant suspicion or bringing processes to a standstill with unnecessary controls.

It means developing simple habits:

  • Check before opening a link or file.

  • Confirm urgent or unusual requests through a separate channel.

  • Use different passwords and enable two-factor authentication.

  • Ask questions when something seems unusual.

  • Report any potential incident immediately.

  • Understand that protecting information is also part of everyday work.

Training should not be limited to an annual presentation that employees complete simply because it is mandatory. To be effective, it must be practical, easy to understand, and connected to real situations that may arise during the working day.

Security becomes part of the culture when it is no longer perceived as an imposed rule and instead becomes a natural part of how people work.

Trust also needs protection

Companies that understand this change early will gain an important advantage. They will not only reduce the risk of incidents but will also be better prepared to operate in an environment where trust has become one of the most valuable assets.

Customers, employees, suppliers, and investors need to trust that an organization will protect their information properly and respond responsibly when a problem arises.

Trust, like reputation, takes years to build and can be lost in just a few minutes.

Digital transformation will continue to advance. Artificial intelligence will reshape processes, new tools will emerge, and we will continue working in ways that we can barely imagine today.

All of this will continue to happen.

What is unlikely to change is a much simpler reality: behind every technology, there will still be a person making decisions.

And that person will probably remain, for many years to come, the first and last line of defence of every organization.


 
 
 

Comments


Stories of the day

News straight to your inbox. Subscribe to our weekly newsletter.

¡Gracias por suscribirte!

  • X

© 2025 by The Global Journey. Powered and protected by Wix

bottom of page