Insights

We Can't Have Security Rules for Everything

Published on July 30, 2026 5 minute read
Practical ERP Solutions Background

Why Human Judgment Remains One of Cybersecurity’s Biggest Challenges

Recently, a cybersecurity incident investigation revealed a familiar pattern. As leadership worked to understand what happened, the discussion kept returning to the same question:

What was missing?

Was it a security tool, an unimplemented control, more monitoring, or a larger security budget?

These are fair questions. In many cases, stronger controls, better monitoring, enhanced identity protections, and more advanced security tools do reduce risk. But as investigators worked through the details, a different picture emerged.

The root cause was not a missing firewall, an unpatched server, or the absence of a specific security technology. At its core, the incident resulted from people making decisions in situations where technology and policy could not fully eliminate risk.

This is not about blame. Human error exists in every organization. The individuals involved were doing their jobs and making decisions based on the information available to them at the time. Unfortunately, those decisions created an opportunity for an attacker to succeed.

The experience highlights a broader reality: while cybersecurity is supported by technology, it is often determined by human judgment.

No matter how many policies, procedures, or controls an organization creates, there will always be situations that fall outside them. Eventually, people must decide what to do.

Looking for What Failed

After a cyber incident, organizations naturally search for the missing layer of protection.

The questions are familiar:

  • What technology should have stopped this?
  • What control was not in place?
  • What additional investment could have prevented it?

These questions make sense because technology is tangible. Organizations can purchase tools, deploy controls, and measure outcomes. Technology provides something concrete to improve.

The challenge is that focusing exclusively on technology can create the illusion that every risk can be solved with another product, dashboard, or security control.

In reality, cybersecurity is a business risk managed through a combination of technology, processes, and people.

Organizations can invest in stronger monitoring, advanced detection capabilities, and better security controls. Those investments are valuable and necessary. Yet many incidents ultimately trace back to a human decision:

  • A user approves a login request.
  • An employee opens an attachment.
  • A finance professional updates banking information.
  • A manager shares a file.
  • A leader responds to an email appearing to come from a trusted colleague.

Different actions. Different roles. Different circumstances.

But each represents a moment where human judgment directly influences organizational security.

The Limits of Rules

Most people learn an important lesson early in life:

Rules are important, but they cannot cover every situation.

Policies and procedures provide guidance, establish expectations, and reduce risk. Yet no organization can anticipate every circumstance employees may encounter. Inevitably, situations arise that fall outside documented processes and require people to rely on judgment.

The same principle applies to cybersecurity.

Organizations create policies to govern acceptable use, data handling, access management, vendor interactions, financial processes, and countless other activities. These policies are essential. They create consistency, establish accountability, and reduce exposure to known risks.

However, policies have limits.

Threat actors constantly evolve their tactics. Business requirements change. Employees face unique situations that no procedure specifically anticipated. Eventually, a decision must be made without a step-by-step instruction manual.

That is where judgment becomes critical.

When Technology Reaches Its Limits

Organizations should continue strengthening their security posture. More visibility improves detection. Additional controls reduce risk. Better tools help identify threats faster. What technology cannot do is eliminate the need for people to make decisions.

Every employee will eventually face a situation that falls outside the rulebook — an unexpected request, an unusual business circumstance, or a scenario that no training course specifically addressed.

In those moments, security stops being purely a technology issue and becomes a judgment issue. The most resilient organizations understand this. They invest not only in technical defenses but also in developing employees' ability to make sound decisions under uncertainty

Security awareness is not simply teaching people what not to do. It prepares them to recognize risk and make informed decisions when policies, procedures, and controls do not provide all the answers. The reality is that No organization can create security rules for every possible situation.

Security Is Everyone’s Responsibility

One of the most persistent misconceptions in cybersecurity is that security belongs exclusively to IT.

IT teams manage systems. Security teams implement controls. Leadership establishes governance and policy. But every employee contributes to managing risk through the decisions they make each day.

  • An employee pauses before clicking a link.
  • A manager questions an unusual request.
  • A finance professional independently verifies payment instructions.
  • Someone reports suspicious activity rather than dismissing it.

Any one of these actions can prevent an incident long before technology has a chance to intervene.

Technology, policies, and awareness programs are essential components of a strong security strategy. But even the most sophisticated controls ultimately depend on the people using them.

In many organizations, one of the most effective security controls is not a piece of software.

It is an employee who stops and asks:

"Does this make sense?"

A Practical Guide to Modern Security

Organizations that build resilient security cultures often reinforce a set of practical behaviors that help employees make sound decisions when unexpected situations arise.

  • Take a Moment Before You Act
    Many security incidents occur when people are rushed, distracted, or pressured to respond immediately. A brief pause often creates the opportunity to recognize warning signs that would otherwise be missed.
  • Protect Information Entrusted to You
    Organizations depend on employees to safeguard company, customer, and partner information. Sharing sensitive data only with authorized individuals remains one of the most fundamental security responsibilities.
  • Speak Up When Something Does Not Seem Right
    Questions are often a security control, not an inconvenience. A quick verification today can prevent a significant incident tomorrow.
  • Take Ownership
    Security is not solely the responsibility of IT or the security team. Every employee influences the organization's security posture through the decisions they make each day.
  • Use Your Common Sense
    Organizations cannot create policies for every possible situation. Security teams cannot anticipate every circumstance employees will encounter.

Technology provides guardrails. Policies provide guidance. Training provides preparation. But there will always be moments when people must rely on judgment. When those moments arrive, good judgment becomes one of the most valuable security controls an organization has.

The Security Control Behind Every Other Control

Ask ten security professionals to identify the most important security control, and you will likely receive ten different answers.

Some will point to multi-factor authentication. Others will emphasize endpoint protection, email security, identity governance, threat detection, or data protection.

All are important. Yet, they share a common dependency: people.

  • Someone must recognize a suspicious request.
  • Someone must question unusual activity.
  • Someone must verify instructions before approving a payment.
  • Someone must pause before granting access.

No budget can eliminate every mistake. No policy can cover every scenario. No technology can predict every situation an employee may encounter.

That is why the most resilient organizations invest not only in technical defenses but also in cultivating a security-minded culture — one that encourages employees to ask questions, challenge unusual requests, and seek help when uncertainty exists.

Cybersecurity is enabled by technology, but it is ultimately practiced by people.

Why Judgment Remains Essential

Following a cybersecurity incident, organizations naturally focus on what can be improved. Discussions often center on stronger controls, enhanced monitoring, better processes, and additional technologies.

Those conversations are important. They should continue. But they should not obscure a fundamental reality: every security program eventually reaches the human layer.

Organizations should absolutely invest in stronger defenses and more advanced security capabilities. Yet no matter how sophisticated technology becomes, there will always be moments when people must make decisions technology cannot make for them.

  • A request must be evaluated.
  • Information must be shared — or protected.
  • An email must be trusted — or questioned.

Technology provides guardrails. Policies provide direction. Training provides preparation.

People provide judgment.

And when the rules run out, that judgment may be the most important security control an organization possesses.

Need Help Building Security Training That Actually Changes Behavior?

Effective security awareness is not about creating more rules — it is about helping employees make better decisions when they encounter situations the rules never anticipated. The most successful organizations combine strong technical controls with practical, role-based training that align with their culture, risks, and business objectives.

If your organization is evaluating its current security awareness program or looking to build training that drives real behavioral change, speak with one of Citrin Cooperman’s security specialists. We can help assess your organization's needs, identify opportunities for improvement, and develop security education programs that empower employees to recognize threats, respond appropriately, and become an active part of your defense strategy.