Vigyata.AI
Is this your channel?

Why Do Most Cyber Breaches Stem from System Failures, Not Human Error?

20 views· 20:01· Mar 24, 2026

Podcast: The Security Strategist Host: Richard Stiennon, Chief Research Analyst at IT-Harvest Guest: Michael Kennedy, Ostra Security Founder For leaders in enterprise technology, the pressure to show measurable cybersecurity outcomes has never been greater. Boards are asking tougher questions, attackers are moving faster, and conventional security awareness metrics aren’t telling the whole story. In the recent episode of The Security Strategist podcast, host Richard Stiennon, Chief Research Analyst at IT-Harvest, is joined by Ostra Security Founder Michael Kennedy, who pointed out a growing gap in how enterprises measure success. Despite years of investment in phishing training and user awareness, breaches keep happening—not because employees are failing on a large scale, but because enterprise systems aren’t designed to handle inevitable mistakes. For CIOs, CISOs, and CTOs, this signals a major transition toward outcome-based security. What Outcome-Based Cybersecurity Looks Like? The more effective approach, Kennedy argues, is to frame cybersecurity around engineering outcomes instead of user behaviour. This means evaluating how well systems perform during attacks—not how well users avoid making mistakes. The key markers of a strong enterprise cybersecurity strategy include how quickly threats are detected, how effectively security teams respond, and how well incidents are contained before they spread. These operational metrics give a clearer view of real-world readiness. This shift lines up with the growing adoption of zero trust architectures, extended detection and response (XDR), and AI-driven security operations. All these frameworks focus on containment, visibility, and fast responses rather than the unrealistic goal of perfect user behaviour. It also changes how breaches are examined. High-profile incidents are often simplified to stories about weak passwords or phishing clicks, while the more vital question—why controls failed to limit the impact—gets overlooked. For enterprise buyers and decision-makers, this can lead to misaligned investments, over-prioritising awareness training while underfunding detection engineering, identity controls, and network segmentation. Key Takeaways Cybersecurity failures are system design issues—not user mistakes. Click-rate metrics are misleading Real success is measured by containment speed and impact reduction. Strong security culture encourages users to report threats without fear of blame. Engineering outcomes (like detection speed and blast radius control) matter more than user behaviour metrics. AI is reshaping both attacks and defence, making faster, smarter response capabilities essential. Chapters 00:00 Introduction to Cybersecurity's Human Element 03:15 Reevaluating User Responsibility in Cybersecurity 06:44 Creating a Culture of Reporting 09:25 Measuring Security Outcomes Beyond Click Rates 12:05 The Role of AI in Cybersecurity 15:06 Adapting to Evolving Threats 17:44 Key Takeaways for Decision Makers For more information, please visit em360tech.com and ostrasecurity.com. Follow: EM360Tech YouTube: @enterprisemanagement360 EM360Tech LinkedIn: @EM360Tech EM360Tech X: @EM360Tech Ostra LinkedIn: Ostra Security Ostra X: @ostra_security Ostra YouTube: @OstraCybersecurity #Cybersecurity #CISO #EnterpriseSecurity #OutcomeBasedSecurity #SecurityMetrics #Phishing #ZeroTrust #AIinSecurity #NoBlameCulture #SecurityStrategist #OstraSecurity

🎬 More from Enterprise Management 360