Cybersecurity strategies do not fail solely because technology is inadequate. More often, the problem lies in security models that depend too heavily on people making the right decision every time. Kaseya’s 2026 Cybersecurity Report illustrates just how persistent that vulnerability remains.
Phishing, misconfigurations, overlooked warnings and ill-considered clicks have become routine features of the cybersecurity landscape. Kaseya’s latest report, Building Security That Survives Human Error, confirms that human behaviour remains one of the most difficult variables for security teams to control.
The study draws on responses from 1,132 managed service providers and IT professionals across more than 60 countries. Sixty-eight per cent of respondents identify human error as one of their most significant security concerns for the coming twelve months. Email-based threats follow at 55 per cent.
The findings point to a fundamental weakness in many contemporary security architectures: protection mechanisms often work effectively only if users consistently recognise warning signs, follow established procedures and make the correct decisions under pressure.
In operational reality, that is an unrealistic assumption.
Security must be designed to tolerate mistakes
The issue becomes particularly apparent among organisations that have already experienced a security incident. Human behaviour and inadequate security training rank among the factors most frequently associated with successful attacks.
The appropriate response, however, cannot be limited to additional employee training. Security awareness remains essential, but it cannot compensate for an architecture that allows a single mistake to escalate into a major incident.
The more important question is therefore not whether errors will occur, but how much damage one error can cause.
If compromised credentials immediately provide extensive privileges, or if a successful phishing attack allows an adversary to move freely across systems, responsibility cannot be attributed solely to the individual user.
Modern cyber resilience therefore relies on multiple, independent layers of defence. These include multi-factor authentication, tightly controlled access privileges, endpoint and network detection, email security, as well as robust backup and recovery capabilities.
The objective is no longer simply to prevent every possible incident. Organisations must also be capable of detecting attacks quickly, containing their impact and restoring critical operations in a controlled manner.
Security investment is failing to keep pace with risk
The report also reveals a significant gap between the evolving threat environment and the resources available to defend against it.
Only one in five IT departments reports that cybersecurity budgets are increasing in line with actual risk. At the same time, 77 per cent of respondents consider their resources inadequate in at least one area.
Managed service providers observe a similar pattern among their customers. Roughly two-thirds believe that organisations are investing too little in cybersecurity relative to their exposure.
This compounds a familiar structural problem: security teams are expected to protect increasingly complex infrastructures while budgets and staffing levels often fail to grow at the same rate.
Automation and artificial intelligence are therefore becoming more important. Used effectively, they can help overstretched teams improve monitoring, accelerate threat detection and prioritise large volumes of alerts.
Compliance is not the same as operational security
A further disconnect becomes visible in the area of compliance.
A substantial proportion of respondents consider their organisations broadly prepared for an audit. Yet the same organisations continue to report weaknesses in documentation, incomplete implementation of security controls and shortcomings in security awareness programmes.
The implication is clear: an organisation may satisfy formal regulatory requirements while remaining operationally vulnerable.
Cyber resilience therefore requires more than compliance with individual control frameworks. Security measures must be continuously tested, incident-response procedures exercised and recovery processes validated under realistic conditions.
According to Kaseya, higher-performing managed service providers are more likely to test incident-response and backup procedures regularly and to deploy additional technologies such as SIEM, network detection and response, and cloud security solutions.
Resilience matters more than perfection
Perhaps the most important conclusion of the report cannot be reduced to a single percentage.
Human error cannot be eliminated from cybersecurity.
What organisations can control is the extent to which their systems are able to absorb it.
A resilient organisation identifies mistakes early, limits their consequences and maintains the capability to restore critical systems rapidly after an incident.
People will therefore remain a central element of cybersecurity. They become a systemic vulnerability only when technical and organisational safeguards are designed on the assumption that people will never make mistakes.



