Analysis

What Is the Human Factor in Information Security?

13 March 2026 · Author: Lisbeth Loft

The human factor is not just about errors. It is about how people perceive risk, make decisions and respond in interplay with technology and organisation.

When “the human factor” is mentioned in information security, it is often used as an explanation that someone did something wrong.

But the concept is broader than that.

It is concerned, among other things, with how people assess information, which shortcuts the brain takes, how we react under time pressure, and how our decisions are influenced by experience, expectations and the situation we are in.

That is where bias becomes relevant.

What Does Bias Mean?

Bias can be described as systematic patterns in the way we assess information and make decisions.

That does not necessarily mean we think wrongly. Many biases are mental shortcuts that help us make quick decisions in a complex everyday life.

But they can also affect security behaviour.

One simple example is normality bias: if something has gone well many times before, we may begin to underestimate the risk involved.

An employee may, for example, have shared a particular type of information in the same way many times without problems. When nothing has ever happened, the action can gradually come to feel less risky, even though the formal risk is the same.

Another example is confirmation bias. If we already expect something to be legitimate or safe, we more easily notice information that confirms that expectation, and less easily notice signs of the opposite.

That matters in information security, because people rarely make decisions based on all available information at once.

People Are Not Only the Weak Part of the System

The human factor is also about the opposite.

People can detect something a system has not caught. They can respond to an irregularity, question a result or stop a process because something does not feel right.

People are therefore not only a risk to be controlled.

They are also an important part of the organisation’s ability to detect and handle problems.

Why Does It Matter?

If we reduce the human factor to “human error”, we risk choosing overly simple solutions.

More training is not always the answer.

Sometimes the problem lies in how people perceive risk. Other times in the decision-making environment, the volume of information, time pressure, culture or the way a technical solution presents the available choices.

It is therefore useful to understand human behaviour as part of the security system – not as something outside it.

From Error to Understanding

The human factor becomes interesting when the question changes from:

“Why did the person make a mistake?”

to:

“How was the decision made, and which factors influenced it?”

That gives a better basis for understanding risk and for choosing the security measures that actually fit the problem.

It is the same starting point as in “Why Don’t People Follow Security Procedures?” – before we try to change behaviour, we should understand it.