Most data breaches don't start with a broken firewall — they start with a person. The good news: that same human factor can become your best defence.
Data security stopped being purely an IT department problem a long time ago. You can have the best firewalls, encryption and impeccably written policies — yet if an employee clicks the wrong link or sends a file to the wrong person, all those measures can be bypassed in a second.
The numbers confirm it: according to industry studies, roughly 82% of security breaches involve a human element. So the real question is not "are people a risk?" but "have I done anything to turn them into a defence?".
A serious attacker knows it is far easier to fool a person than to break a well-configured system. That is why most attacks are not "technical" but manipulative: an email that looks like it's from the boss urgently asking for a payment, a message imitating the bank, a call from someone pretending to be IT support.
They all use the same levers: haste, fear of getting it wrong, the wish to be helpful, and the assumption that "if it looks official, it is official". None of this is about intelligence — it's about context and habit. Which is exactly why it can be trained.
In day-to-day work, incidents rarely look dramatic. Most often they are mundane gestures:
None of these require bad intent. They are shortcuts taken by busy people who were never helped to see where the red line is.
An informed employee does the opposite: they notice when something "doesn't feel right", don't click, ask and report. They effectively become a security sensor. And an organisation with hundreds of such sensors is far harder to attack than one relying on technology alone.
Training that actually works shares a few traits:
We've written more on this in our articles on cybersecurity culture and human resource security in ISO 27001, if you want to go deeper.
Training is not a "nice to have" extra — it follows directly from the law. Article 32 requires appropriate technical and organisational measures, and prepared people are a basic organisational measure. Article 39 gives the data protection officer (DPO) the express task of raising awareness and training staff. And the accountability principle (Article 5(2)) requires you not only to be compliant, but to be able to demonstrate it.
During checks, evidence of real training sessions is an important mitigating factor. A completely untrained team, by contrast, is hard to defend. For what employee data protection means in concrete terms, see our article on employee data protection in HR.
Good intentions are not enough; you also need a system that makes training simple and demonstrable. Two things help the most:
If you want all of this coordinated by someone who knows your organisation, we also provide an outsourced DPO, and our GDPR services package includes building a training programme tailored to your risks.
The human factor is, by nature, neither a weak link nor a line of defence. It becomes one or the other depending on how much you invest in people. Prevention — a short training, a self-assessment done in time, a question asked of an assistant before a click — is always cheaper than a breach handled under the pressure of sanctions. And the company that understands this doesn't just avoid fines: it signals, in every interaction, that it treats people's data seriously.
Yes. Industry studies consistently show that around 74-82% of breaches have a human element at their root: a phishing click, a weak password, an email sent to the wrong recipient or a careless configuration. Technology matters, but attackers most often target people, not the firewall.
The practical recommendation is: at onboarding, then at least once a year, plus whenever there are significant changes (new procedures, new tools, a relevant incident). Short, frequent sessions work better than one marathon course every few years.
The GDPR does not require a course with a specific name, but training follows directly from the law: Article 32 requires appropriate organisational measures, Article 39 gives the DPO the task of raising awareness and training staff, and the accountability principle (Article 5(2)) requires you to be able to demonstrate what you have done. In practice, having no training at all is hard to justify before the supervisory authority.
Keep evidence: attendance lists, session dates, the materials used and, ideally, the results of short knowledge checks. An e-learning platform keeps these records automatically, and a training register shows clearly who completed what, and when.
Start with a free self-assessment on askGDPR.ro, train your people with our online courses and, if you wish, leave the coordination to an outsourced DPO.