Top 10 Human-Layer Threats — Psyche-Cyber Framework v0.3
Human System Risk · Threats

The Top 10 human-layer threats

Most breaches don't begin with a broken control. They begin with an intact human responding exactly as their wiring predicts. These are the ten most exploited routes into the layers beneath your technology — the ones your stack was never built to see.

Framework v0.3 — the layer-based model, before the 8th Habit pathways were introduced.  Compare with v0.5 →

Author
Jakub — Enterprise Security Architect
Discipline
Senior Cybersecurity Architect
Framework
Human Systems Security · v0.3
How to read this list

Every threat targets a specific layer of the human system.

Technology and process sit at the top of the defended stack. Beneath them run layers no firewall inspects: the conscious decision window, the belief systems that decide what feels safe, and the nervous-system responses that fire before thought. Attackers have moved down to these layers because that is where the controls end.

Each entry below names the layer it exploits, how the attack lands, and the defensive read — the architectural implication for the controls you already own.

The defended stack — top to root
TechnologyEndpoints, network, identity systems
ProcessPolicy, controls, governance
Conscious mindDeliberate judgement & verification
Belief systemWhat is assumed safe, trusted, normal
Nervous systemFight / flight / freeze — faster than thought
The list

Human System Threats — HST-01 to HST-10

Ranked by prevalence
across enterprise incidents
HST-01 Authority Compliance ExploitationImpersonated authority overrides individual verification. Layer · Deference response+

Business email compromise, CEO fraud and executive-impersonation vishing exploit a near-automatic deference to perceived authority. Under apparent hierarchy, the verification step isn't forgotten through ignorance — it's skipped by a compliance response that fires below conscious choice. The target knows the rule and breaks it anyway, because the wiring is older than the policy.

Defensive readOut-of-band verification must be mandatory and socially sanctioned for anyone, at any level — never a discretionary courtesy that authority can wave through.
HST-02 Urgency & Scarcity HijackManufactured time pressure collapses deliberate judgement. Layer · Conscious window+

Artificial deadlines and "last chance" framing push a decision out of slow, deliberate reasoning and into fast, reactive processing, where scrutiny drops sharply. The urgency isn't context around the attack — it is the payload. Remove the time pressure and most of these attacks fail on inspection.

Defensive readHigh-risk actions need enforced cooling periods, not faster approval paths. Speed is a feature for the attacker, not the business.
HST-03 Trust TransferenceEstablished trust is borrowed to carry the attack. Layer · Belief system+

Compromised-vendor email, thread hijacking and lookalike domains ride on relationships that already exist. The heuristic that makes collaboration efficient — known sender equals safe sender — is the exact surface being exploited. The trust was earned by someone; the attacker simply spends it.

Defensive readTrust is re-verified per transaction, not inherited from relationship history. A known counterparty is a higher-value target, not a lower-risk one.
HST-04 Fear & Threat ConditioningInduced fear bypasses rational evaluation. Layer · Fight / flight / freeze+

Extortion, fake legal notices and account-lockout scares trigger an acute stress response that narrows attention onto the threat and away from its implausibility. A frightened person is not a worse thinker — they are temporarily a different one, with deliberate reasoning taken partly offline.

Defensive readPre-rehearsed responses — a known "this is what we do when threatened" — keep judgement online when the stress response would otherwise take over.
HST-05 Reciprocity & Obligation LoopsA small given favour buys a costly compliance. Layer · Social contract+

Pretexting that opens with help, a gift, or a shared confidence creates an unconscious sense of debt. The target discharges that debt by complying — granting access, bending a rule, making an exception — without ever consciously weighing the trade.

Defensive readName the tactic explicitly in training so the felt obligation is recognised for what it is and can be discharged safely, instead of with access.
HST-06 Cognitive Load SaturationOverloaded attention degrades secure behaviour. Layer · Processing capacity+

Alert fatigue, constant context-switching and sheer decision volume deplete the finite resource that careful security choices draw on. Insecure shortcuts then appear — predictably, not randomly — at the moments the human layer is most loaded. Attackers time their approach to the busy hour.

Defensive readTreat human attention as a rate-limited resource. Design alerting volume and approval flows around it, the same way you'd protect any saturated control.
HST-07 Predictable Stress ResponseIndividual stress patterns are profilable and steerable. Layer · Nervous system+

Under pressure, people fall back on consistent default patterns — freeze, comply, or appease. Skilled social engineers read which one a target runs and steer it. The response feels like a personal failing afterwards; it is in fact a predictable survival pattern that was engineered against.

Defensive readRegulation — recognising the response and down-shifting it — is a trainable control, not a fixed personality trait. It can be drilled like any other capability.
HST-08 Identity & Belonging ManipulationIn-group signals quietly lower the guard. Layer · Group identity+

Social proof, shared-identity pretexts and insider recruitment exploit the drive to belong. "One of us" reads as "safe" — the same badge, the same lingo, the same cause — and verification relaxes for anyone who clears the in-group test instead of the security test.

Defensive readVerification standards must be identity-blind and apply equally inside the perceived in-group. Belonging is not a credential.
HST-09 Normalisation of DevianceRepeated exceptions quietly become the standard. Layer · Collective belief drift+

Every small policy bypass that goes unpunished and uneventful resets the baseline of "normal". Over time the control exists only on paper while the lived practice has drifted somewhere else entirely. No single decision looks reckless; the aggregate is an open door.

Defensive readMonitor for drift in actual behaviour over time, not just point-in-time compliance. The gap between the policy and the practice is the real risk surface.
HST-10 Vigilance Collapse & BurnoutChronic dysregulation degrades the human detection layer. Layer · Sustained regulation+

Burned-out teams miss signals, disengage and route around controls — the human SOC failing silently while the dashboards stay green. Unlike a server, an exhausted analyst doesn't page an alert when their capacity drops. The degradation is invisible until something gets through.

Defensive readSustainable vigilance is a capacity to be resourced and measured, like uptime on any other control. Burnout is a security event, not just an HR one.
Brief your leadership

Map these threats against the controls you already own.

A focused briefing for CISOs and risk leaders: where the human layer sits in your current architecture, which of these ten you're most exposed to, and the controls that close the gap.