Security tools matter. Firewalls, endpoint protection, email filtering, multi-factor authentication (MFA), backups, and monitoring all have important roles. But one of the most important control surfaces in any business is still the human layer: the decisions people make when they receive an email, approve a payment, share a file, reset a password, install a tool, or respond to an urgent request from someone who appears to be a manager, supplier, customer, or IT support person.
The human layer is not about blaming users. It is about designing safer workflows so that normal business pressure does not become an attacker's opportunity. Phishing, business email compromise (BEC), impersonation, invoice redirection, credential theft, and helpdesk social engineering all exploit a familiar combination: urgency, trust, fatigue, incomplete verification, and unclear escalation paths.
The New Zealand context makes this especially relevant. NCSC's 2025 Cyber Threat Report recorded 5,995 incident reports in 2024/25 and NZ$26.9 million in reported direct financial loss. NCSC also reported that 53% of New Zealand SMEs surveyed experienced a cyber threat between January and June 2025. In its Q4 2025 insights, phishing and credential harvesting accounted for about a third of business reports. These figures are not a reason for panic; they are a reminder that identity, payment, and verification workflows deserve the same discipline as technical controls.
Key idea: Human-layer security is not awareness training alone. It combines behaviour, business process, identity controls, reporting, and leadership expectations so that the safe action is also the normal action.
Annual security awareness training can help people recognise common threats, but real attacks do not arrive once a year in tidy training scenarios. They arrive when someone is rushing to close the books, waiting for a courier, helping a customer, approving leave, onboarding a contractor, or clearing an overloaded inbox.
Attackers use the context of ordinary work because it is more persuasive than a generic scam. A believable request may refer to an overdue invoice, a supplier bank-account change, a shared document, a password reset, a new payroll instruction, or an urgent request from senior management. NCSC has also highlighted social-engineering activity aimed at helpdesks, where attackers impersonate staff and attempt to obtain account resets or access.
Training becomes much more useful when staff also know:
Credential phishing remains effective because a convincing sign-in page can look almost identical to a real one. Traditional MFA is still far better than password-only authentication, but some MFA methods can also be phished or socially engineered. Codes can be relayed, push prompts can be abused, and users can be pressured into approving a request they did not initiate.
Where the platform supports it, higher-risk users—particularly administrators, finance staff, and people with access to sensitive systems—should progressively move toward phishing-resistant authentication, such as passkeys/FIDO2 security keys or Windows Hello for Business. Microsoft specifically recommends phishing-resistant methods for stronger protection against remote phishing attacks.
Practical controls include:
BEC is dangerous because the request may come from a real, compromised mailbox. That means checking the display name—or even recognising the sender's address—is not enough. NCSC guidance explicitly recommends a second verification channel for sensitive changes such as password resets and payment details.
In NCSC's Q1 2025 reporting, scams and fraud accounted for most recorded financial losses, with around NZ$5 million attributed to unauthorised money transfers or business email compromise. The practical lesson is straightforward: financial controls must assume that email can be compromised.
Practical controls include:
Password resets and MFA recovery are powerful processes. If an attacker can convince a helpdesk, administrator, or office manager to reset an account, the strength of the original password may no longer matter. NCSC has reported techniques in New Zealand where attackers impersonate staff to obtain access through helpdesk processes.
Controls should therefore cover the recovery path as carefully as the normal sign-in path:
Not every human-layer risk starts with a deliberate attack. Risk also appears when the approved process is too difficult or poorly understood: public file links, business information copied into personal storage, passwords kept in spreadsheets, unapproved AI or SaaS tools, or browser extensions installed without review.
Practical controls include:
The strongest human-layer controls are embedded in ordinary work. They do not expect every employee to become a security analyst. Instead, they make high-risk actions deliberately harder to complete without verification.
| High-Risk Action | Safer Workflow |
|---|---|
| Supplier changes bank details | Verify through a separate, trusted channel and record the verification. |
| Urgent payment from a senior leader | Require the normal approval path; urgency does not remove control. |
| Password or MFA reset | Verify identity using an established recovery process before making the change. |
| Unexpected file-sharing request | Confirm the recipient and data sensitivity before changing permissions. |
| New SaaS or AI tool | Use a lightweight approval process and check what data the service will receive. |
Practical rule: Any workflow involving money, credentials, sensitive data, or privileged access should include a verification step that does not depend solely on the channel that initiated the request.
Many incidents become worse because people hesitate to report them. They may worry about being blamed, feel embarrassed, be unsure whether an event is serious, or hope nothing happened. That delay can give an attacker time to create mailbox rules, reuse credentials, contact customers, move laterally, or complete a fraudulent payment.
A better internal message is simple: if something feels wrong, report it early. Early reporting gives IT more options: revoke sessions, reset credentials, isolate devices, remove malicious mailbox rules, preserve logs, warn other users, and contact external parties before the incident expands.
New Zealand businesses can also report cyber incidents to the National Cyber Security Centre. NCSC notes that reporting can help limit damage, support recovery, and contribute to wider phishing and threat-disruption activity.
Virtus Group helps New Zealand businesses reduce human-layer risk by combining practical process controls with identity, email, endpoint, and monitoring improvements. The objective is not more policy for its own sake—it is fewer avoidable incidents and a clearer response when something goes wrong.
Human-layer security works best when it is simple, repeatable, measurable, and backed by leadership. The aim is not to make staff suspicious of everything. The aim is to make verification routine when the stakes are high—and reporting immediate when something does not look right.
Here is the Phishing, BEC & Security Habits Playbook