Skip to main content
Close
Security

Social engineering: the most expensive firewall is human

Gabriel Ferraresi· CEO | Tech86October 6, 20263 min
social-engineeringphishingawarenesssecurityvishingshadow-it

90% of cyberattacks start with human error. The statistic is old and repeats across every security report. Still, most companies keep investing millions in firewalls while treating the user as a supporting actor.

Firewalls filter packets and see little of intent. If an employee is tricked into handing over a password, the attack walks through the front door with a legitimate credential. Perimeter technology stays intact. The damage does not.

The vector distribution is brutal

Phishing and spear phishing account for roughly 90% of breaches. Software exploits, 7%. Brute force, 3%.

When the preferred vector is human, budget that only buys technology is defending the 10% of the problem with 90% of the money. The firewall is not wrong: what is missing is the second chapter, the one that trains whoever holds the credentials.

The favorite target and its four costumes

The scam arrives convincing and personalized: fake emails that fool directors, CEO Fraud that steals credentials and authorizes transfers, vishing over the phone, smishing over SMS. And there is shadow IT, the non-approved services that create invisible gaps IT cannot see.

This year brought two public confirmations that the human link is the preferred surface: the Jack Henry incident started with a phone call, and AI made phishing 14x more effective against MFA users. The attacker gained speed and cut the cost per attempt: training humans stopped being an HR program and became a security control.

What turns the weak link into the front line

Tech86 runs awareness programs on one premise: a security culture is built through education, not prohibition. The package in practice:

  1. Unlimited phishing simulations, test emails that mimic real threats in the workflow. Whoever clicks lands into an instant micro-training: the teachable moment.
  2. Gamified trainings under 5 minutes a week. No PowerPoint slides nobody reads.
  3. A report button for Outlook and Gmail: report suspicious email in one click, feeding the company’s defense intelligence.
  4. A human risk dashboard with a Human Risk Score, identifying High Risk Users for focused corrective action, deployed centrally via GPO or Admin Console.

The entire design follows one rule: the program cannot compete with operations. Programs that get in the way get turned off in the first month.

From click to culture

The typical curve of a well-run program: in the first simulation, the click rate scares. With a cycle of simulation, micro-training, and active reporting, the rate falls and the most valuable behavior changes: employees start reporting before clicking.

That is the maturity signal no firewall delivers: an organization where the attack that slipped past technology dies on the finger of someone who grew suspicious. The most effective firewall of 2026 has a name and an employee badge.

Conclusion

The question was never whether your company will be targeted by phishing. The real question is when, and whether the team will recognize it on the spot.

The weakest link and the strongest one are the same component: what changes is the investment. 5 minutes a week of training, simulations in the flow, and a report button cost less than a single incident with a stolen credential. The firewall of the decade wears a badge, and installing it starts with one simulation.

Interested in this solution?

Explore our managed services and infrastructure.

Security Awareness Program

Frequently Asked Questions

Phishing and spear phishing account for roughly 90% of breaches. Software exploits take 7% and brute force 3%. The statistic is old and repeats across report after report: the preferred vector is not technological, it is human.

Because firewalls filter packets and see little of intent. If an employee is tricked into handing over a password, the attack walks in through the front door with a legitimate credential: perimeter technology stays intact, the damage does not. [The Jack Henry case](https://www.tech86.com.br/en/blog/jack-henry-ransomware-fourth-party-risk-bancos), where the entry point was a vishing call, is the year’s example.

It is the micro-training triggered at the instant of the mistake: the employee clicks the phishing simulation and receives, on screen, in minutes, the lesson for that exact type of scam. Training at the error moment has far higher retention than scheduled training, because attention is already on the subject.

It is a plugin for Outlook and Gmail that lets anyone report suspicious email in one click. Reports feed defense intelligence (other recipients of the same scam get protected) and change the employee’s role: from possible victim to active sensor.

Under 5 minutes a week: short gamified trainings in the workflow, simulations disguised as routine, and reports nobody but the manager needs to read. The whole design exists to avoid competing with operations, because programs that get in the way get turned off in the first month.

Blog, Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.