Most breaches don't begin with a broken control. They begin with an intact human responding exactly as their wiring predicts. These are the ten most exploited routes into the layers beneath your technology — the ones your stack was never built to see.
Framework v0.3 — the layer-based model, before the 8th Habit pathways were introduced. Compare with v0.5 →
Technology and process sit at the top of the defended stack. Beneath them run layers no firewall inspects: the conscious decision window, the belief systems that decide what feels safe, and the nervous-system responses that fire before thought. Attackers have moved down to these layers because that is where the controls end.
Each entry below names the layer it exploits, how the attack lands, and the defensive read — the architectural implication for the controls you already own.
Business email compromise, CEO fraud and executive-impersonation vishing exploit a near-automatic deference to perceived authority. Under apparent hierarchy, the verification step isn't forgotten through ignorance — it's skipped by a compliance response that fires below conscious choice. The target knows the rule and breaks it anyway, because the wiring is older than the policy.
Artificial deadlines and "last chance" framing push a decision out of slow, deliberate reasoning and into fast, reactive processing, where scrutiny drops sharply. The urgency isn't context around the attack — it is the payload. Remove the time pressure and most of these attacks fail on inspection.
Compromised-vendor email, thread hijacking and lookalike domains ride on relationships that already exist. The heuristic that makes collaboration efficient — known sender equals safe sender — is the exact surface being exploited. The trust was earned by someone; the attacker simply spends it.
Extortion, fake legal notices and account-lockout scares trigger an acute stress response that narrows attention onto the threat and away from its implausibility. A frightened person is not a worse thinker — they are temporarily a different one, with deliberate reasoning taken partly offline.
Pretexting that opens with help, a gift, or a shared confidence creates an unconscious sense of debt. The target discharges that debt by complying — granting access, bending a rule, making an exception — without ever consciously weighing the trade.
Alert fatigue, constant context-switching and sheer decision volume deplete the finite resource that careful security choices draw on. Insecure shortcuts then appear — predictably, not randomly — at the moments the human layer is most loaded. Attackers time their approach to the busy hour.
Under pressure, people fall back on consistent default patterns — freeze, comply, or appease. Skilled social engineers read which one a target runs and steer it. The response feels like a personal failing afterwards; it is in fact a predictable survival pattern that was engineered against.
Social proof, shared-identity pretexts and insider recruitment exploit the drive to belong. "One of us" reads as "safe" — the same badge, the same lingo, the same cause — and verification relaxes for anyone who clears the in-group test instead of the security test.
Every small policy bypass that goes unpunished and uneventful resets the baseline of "normal". Over time the control exists only on paper while the lived practice has drifted somewhere else entirely. No single decision looks reckless; the aggregate is an open door.
Burned-out teams miss signals, disengage and route around controls — the human SOC failing silently while the dashboards stay green. Unlike a server, an exhausted analyst doesn't page an alert when their capacity drops. The degradation is invisible until something gets through.
A focused briefing for CISOs and risk leaders: where the human layer sits in your current architecture, which of these ten you're most exposed to, and the controls that close the gap.