
Human Risk Management, Behavioural Science
Community monthly digest: What human risk looks like in practice?
Security teams spend a lot of time thinking about attack surfaces in purely technical terms. Vulnerabilities, exposed systems, misconfigurations. It makes sense why: those are measurable. But a lot of attacks take a far more ordinary route. That is the territory Andrew Rose, former SoSafe CSO and career security practitioner, has been exploring in the SoSafe Community: a space where leaders tackle problems best not solved in isolation. As an Ambassador, he helps drive those discussions by challenging easy assumptions with real-world experience.
In a recent run of four deep dives, he looks at human risk from a few practical angles: what happens when trust becomes the attack path, why well-meaning employees still get caught out, and where teams can step in before a deceptive message turns into a breach.
When you take all four pieces together, they really boil down to one simple thing. People do not notice they are opening up a gap while they are doing it. To them, it just looks like doing their job. They are busy, the request fits whatever is happening that week, and nothing sets off alarm bells.
That is why these situations deserve a closer look. Here is a recap of his key takeaways, why work pressure changes how people act, and where the discussion goes next.
Is ‘trust, but verify’ just a comfort blanket?
To kick things off, Andrew looked at the BePrime breach. It shows how easily gaps open up, even for security providers serving major businesses including Whirlpool and companies connected to Starbucks. An attacker claimed to have exploited admin accounts without MFA, stolen 12.6 GB of data, accessed nearly 1,900 network devices, and viewed live surveillance feeds.
He paired that with a story from his own past: a spreadsheet of database passwords that almost turned a routine pen test into a real incident. Different scale, exact same issue: relying on silent assumptions instead of built-in safeguards.
Which got him thinking about how people actually use the phrase “trust, but verify”. Too often, it is just a comfort blanket. Policies get written expecting someone to check the work, but without automated systems to back them up, the extra effort just lands back on busy people.
Striking a balance here is tough. Heavy-handed monitoring gets in everyone’s way, but doing nothing leaves wide-open blind spots.
So Andrew posed a question to the community: has “trust, but verify” become an excuse for incomplete controls, or does something like Zero Trust actually fix it?
Read the full post and weigh in
The deficit thinking trap
Next, Andrew took on a question security teams wrestle with all the time: if people already know not to click suspicious links, why do they still do it?
To explain, he pointed to neurologist Antonio Damasio’s book, Descartes’ Error, which looks at how the brain actually makes choices. Damasio studied patients with damage to brain regions involved in emotion and decision-making. Some retained normal intelligence but struggled badly with everyday choices. His work showed that emotion plays a major role in decision-making, alongside facts and logic.
That changes how we have to look at training. A course done six months ago is rarely top of mind when an email creates artificial pressure. Andrew calls relying purely on knowledge “deficit thinking”—an approach widely criticised in behaviour-change research, even if security awareness still often leans on it.
His proposed alternative, Adaptive Defence, shifts the focus from “did they complete the training?” to “what drove their choice in that moment?” It comes down to supporting people right at the moment of risk, rather than expecting them to recall a training module from six months ago.
How ShinyHunters targets the helpdesk
Andrew also examined ShinyHunter and recent attacks linked to the name, including incidents involving Kodak, One Medical, and Madison Square Garden Sports. Across dozens of breaches this year, exposing data on over 400 million people, almost all of them targeted people rather than software flaws. Outside of an Oracle PeopleSoft zero-day that hit over 100 organisations, the entry point came down to human decisions, not code.
The tactics show why this happens. The group uses AI-generated phone calls to impersonate IT support, create fake outages, and convince helpdesk staff to reset credentials or read out one-time passcodes. They often pair that with MFA fatigue, flooding someone’s phone with push notifications until they tap approve just to make it stop.
Andrew outlines a few practical ways to close these gaps:
- Verifying callers through an independent channel.
- Requiring higher approval levels for any reset touching MFA.
- Setting clear authentication standards for third-party service desks.
He also points to phishing-resistant MFA as the long-term answer, which he will be diving into next month.
Explore his specific recommendations
Protect your business from SIM-swapping
In one of his community posts, Andrew broke down SIM swapping, an attack that lives almost entirely at the human layer yet remains poorly understood outside security teams. Attackers gather personal details from breaches or phishing, then call a victim’s mobile provider and talk their way into moving the number to a SIM card they control. Every text-based verification code that follows goes straight to the attacker, while the victim is left with “No Service”.
He grounded the risk in two real-world cases:
- Kroll, a risk advisory firm, had an employee’s number swapped by T-Mobile without any contact or verification with Kroll, exposing customer data.
- Scattered Spider, who combined SMS phishing with SIM swapping to target high-value targets, resulting in over $8 million in stolen crypto.
Andrew highlights two clear takeaways: treat a sudden loss of phone signal as a security event rather than a network glitch, and audit internal systems to see where text messages are still being used as an authentication step.
Read his full breakdown and action checklist
Bring your perspective to the community
What ties all four posts together is that Andrew turns each incident into a genuinely open question: where the line between flexibility and control belongs.
Rather than handing down textbook answers, he wants to talk about what happens when policy meets real-world pressure, and how other teams are managing those trade-offs:
- Is your helpdesk genuinely empowered to say no to a pushy caller?
- What has actually worked to close the gap between knowing the rules and following them?
- Where does your team draw that line in practice?
If you have a take and you’re a SoSafe customer, jump into his threads in our SoSafe Community Best Practices space to join the conversation.











