Security Doesn't Get Breached. It Gets Allowed
- Captain Ajesh Sharma (Veteran)

- Mar 17
- 5 min read

What if the next serious breach in your organization does not begin with malware, lock-picking, or a sophisticated exploit? What if it begins with a smile, a routine moment, a confident tone of voice, or a busy front desk?
That is the uncomfortable conclusion of this series.
Across five articles, Katarzyna Kałużny and I examined a reality many organizations still underestimate: physical security often fails not because controls are absent, but because human behaviour quietly overrides them.
“I don’t attack people over social engineering,” Street has said. “I attack human nature.”
This series set out to map that nature. Not to blame it. To expose the ordinary instincts that open every door a badge system was built to close.
Five Articles. One Pattern.
Across the first five articles in the series Security Doesn’t Get Breached. It Gets Allowed., we explored five behavioural vulnerabilities that repeatedly weaken physical security—not through technical failure, but through predictable human response.

From excessive courtesy in Politeness Is the New Vulnerability, to the disarming effect of Authority and confidence, to the quiet drift into complacency when Normalcy is mistaken for safety, each article examined a different way human judgement can be manipulated. We also addressed how the Bystander effect in corporate lobbies diffuses responsibility, and how Human Buffer Overflow—when cognitive capacity is stretched beyond its limit—causes critical cues to be missed at exactly the wrong moment.
Taken together, these dynamics reveal a simple but too often overlooked truth:
Many security breaches begin not with sophisticated technology, but with predictable human behaviour.
The Numbers That Should Keep You Awake
The data across multiple sources paints a picture that is difficult to dismiss:
The human element is involved in 60% of all confirmed data breaches (Verizon DBIR 2025, based on 12,195 confirmed breaches — the largest dataset in the report’s eighteen-year history). Social engineering of insiders increased from 12% to 18% of recorded incidents year-over-year.

Pretexting and phishing remain the dominant social engineering tactics. Phishing accounts for 57% of social engineering incidents, with pretexting at 30% — most commonly manifesting as business email compromise scenarios. But in the physical world, pretexting is the primary vector: it requires zero technology and exploits the exact behaviors organizations train into their people.
82% of employees cannot recognize social engineering tactics when they encounter them (Gitnux 2025). 93% never receive regular security awareness training (Secureframe 2025). The average cost of a social engineering breach reached $4.76 million (IBM Cost of a Data Breach Report 2024).
These are not numbers about technology failing. They are numbers about organizations failing to account for how their own people actually behave under ordinary conditions.
Expert Perspectives: Practitioner Insights on Human Risk
To deepen the discussion, we invited two highly respected global risk leaders — Ratna Pawan and Daragh McDermott — both of whom bring extensive experience in managing security risk across complex organizational environments.
We asked them a common question:
“From your professional experience, which human behaviours create the greatest risk to physical security, and who should own that risk?”
Their reflections reinforce a conclusion that has surfaced repeatedly across this series: physical security failures are rarely caused by the absence of controls alone. More often, they emerge when human behaviour, judgement, and culture override the controls already in place.
Ratna Pawan
“Across these articles, so beautifully articulated by two respected global leaders stalwarts Capt. Ajesh Sharma and Katarzyna Kaluzny, I really connected with the theme.
While technology can help frame and enforce rules, it is behaviour that decides whether they are applied and work on ground. Unmanaged behavioural risks and biases around authority, normalcy, optimism, in-group, and the bystander effect consistently pose a risk to physical security. In my personal experience and ironically so, the very people that the Physical Security function aims to protect, is also its weakest link. Most organisations seem to have their Security guidelines and controls formally in practice but on every occasion that we have seen it fail, it's due to some human-led dynamics. For senior leadership, this is therefore the greatest governance issue that they must tackle; with accountability explicitly owned.”
Daragh McDermott “Behavioural risk is everybody’s responsibility, full stop. It is at all times a security function, a leadership responsibility, a governance issue, a training matter, a personal undertaking, and a cultural requirement. Everybody from the top to the bottom, every process from a password complexity and reset policy to a firewall configuration to communication sanitation, every last facet of a business can and should be responsible for behavioural risk.”
Together, their perspectives sharpen a critical message for leadership: technology may define the framework, but people determine whether security holds in practice. Behavioural risk may be shared across the organization, but accountability for addressing it must be explicit.
We are also grateful to the many practitioners and collaborators who engaged with the earlier articles in this series, helping to broaden the discussion through thoughtful commentary, challenge, and support. Their contributions added valuable real-world dimension to this conversation and helped keep it visible across networks.
From Insight to Action
Diagnosis without action is just an interesting conversation. This series was never intended to be only a diagnosis.

For the people at the desk: You are the last line of defense — and you deserve the tools, the authority, and the training to act on what you see. Challenge is not rudeness. Verification is not suspicion. It is professionalism. If nobody has told you that you are allowed to say "Stop — prove it" to anyone who walks through that door, regardless of rank or appearance, then the system has failed you before the social engineer even arrived.
For the people in the boardroom: Every bias in this series maps to a decision you made or a culture you permitted. Politeness is a training outcome. Authority deference is a norm you set. Normalcy bias is a monitoring gap you funded. Bystander inaction is a reporting structure you designed. Cognitive overload is a resourcing choice you signed off on. If the person at the front desk cannot say no, that is not a staffing problem. That is a governance failure — and it sits in your chair, not theirs.
The standard should be simple: design security for how people actually behave, not how policy assumes they will. Verify everyone. Train for manipulation, not just procedures. Staff for peak load, not average load. And never mistake a quiet building for a secure one.
The Final Reckoning
Security failures rarely occur because people are careless. They occur because people are behaving exactly as organizational culture, operational training, and social expectation encourage them to behave.
A smile. A clipboard. A sentence that sounds reasonable. And five instincts — trained, reinforced, rewarded — that open every door a badge system was built to close.
For modern organizations, the challenge is therefore not only to deploy better technology but also to understand and manage the subtle human dynamics that shape security decisions every day.
The next breach may not defeat your technology — it may simply understand your people better than your security design does.
So here is the question this series leaves behind:
Which of these five behavioural vulnerabilities still exists inside your organization — and what is stopping you from addressing it?

Katarzyna Kałużny
Global Leader in Operations & Enabling Functions | Executive MBA
Capt. Ajesh Sharma
Global Security Strategist & Leader | Founder, Helix Security Advisors
.png)



Comments