Cybersecurity’s Most Critical Blind Spot: The Human Factor
Cybercrime has grown into a global challenge of extraordinary scale. But as attacks grow more sophisticated—and increasingly difficult to contain—a more fundamental question demands attention: Are organizations focusing on the vulnerabilities that matter most?
For Scott Augenbaum, a retired FBI Supervisory Special Agent who spent more than three decades investigating cybercrime, the answer begins by looking beyond technology and toward the people, decisions, and partnerships that determine how effectively an organization can prevent, withstand, and respond to an attack.
Augenbaum shared this perspective during “Cybersecurity Talk: Cybercrime Without Borders – What the Philippines Can Learn from US Cases,” convened by the Asian Institute of Management (AIM) through the Washington SyCip Graduate School of Business, in collaboration with the United States (U.S.) Embassy in Manila. The discussion brought together professionals and students from banking and finance, technology, law enforcement, higher education, and the Executive Master in Cybersecurity Management (EMCSM) community.
The trajectory of cybercrime illustrates how rapidly the landscape has changed.

“When I was with the FBI in 2016, I was telling the general public that the cybercrime problem was a $3 trillion problem. By 2021, the cybercrime problem globally was supposed to go up to a $6 trillion problem. Today, the cybercrime problem is probably a $15 trillion global problem,” Augenbaum said. “There are no borders in cybercrime because bad guys can impact us anywhere in the world.”
However, he emphasized that scale does not mean organizations are powerless. In fact, Augenbaum’s experience points to a significant opportunity: many cyber incidents can be mitigated before they become full-scale breaches.
“Nobody expects to be a victim. Recovery is difficult, and arrests are hard. That is what we need to know. But it is not hopeless. Prevention is possible,” he noted. “Even to this day, almost 90% of what I dealt with could have been prevented if my end users were only armed with a couple of key pieces of information.”
That insight brings the human dimension of cybersecurity into sharper focus. Technical infrastructure remains indispensable, but it does not operate in isolation. Even the most sophisticated security architecture ultimately depends on how people understand, use, and respond to it.

“There are two parts of an attack. We have the technical component. This is what we have to worry about from the corporate view—malware, credential theft, account takeover. This is what is creating the opportunity. But let me tell you, with the 90% that I dealt with, it doesn’t live in the technical component; it lives in the human component. It lives in the emotions that happen,” Augenbaum explained.
Moreover, the human aspect becomes especially significant as cybercriminals increasingly exploit behavior rather than simply attempting to defeat technical defenses.
“The first door is to manipulate the person. It’s a socially engineered message that triggers it. But everyone goes, ‘I’ve got great email protection in my company. So what?,” he questioned. “It’s social engineering—tricking people into doing something they normally wouldn’t do. It’s been around since the beginning of time.”
For organizations, the implication extends well beyond cybersecurity teams. A single compromised credential, manipulated employee, or overlooked warning can quickly become a financial, operational, regulatory, or reputational crisis. Cybersecurity, therefore, cannot be treated as a siloed technical function. It is increasingly intertwined with how organizations govern risk, make decisions, and protect stakeholder trust.
This is where cybersecurity becomes a leadership discipline.

The Executive Master in Cybersecurity Management (EMCSM) at AIM reflects this broader imperative by positioning cybersecurity within the context of management, strategy, governance, and organizational decision-making. Rather than approaching cyber risk as an isolated technical concern, the program equips professionals with essential skills for cybersecurity, preparing them to navigate the field as a complex organizational challenge—one that demands specialized expertise and the ability to lead across functions.
For the next generation of cybersecurity professionals, Augenbaum framed that responsibility even more directly:
“This is what the next generation really has to understand. This is a team effort. It’s the cybersecurity students. It’s all of you realizing that you’re the future here. You’re going to go into organizations, you’re going to go into companies, you’re going to go into leadership.”
The responsibility, however, does not stop at the organizational and personal boundaries.
“It takes a community to be safe. It’s community, it’s partnership, it’s law enforcement, it’s the government at every level, it’s the banking sector, it’s us,” he highlighted.
Cybercrime may cross borders with ease, but effective cybersecurity depends on the strength of the networks built to confront it. For the Philippines, that means bringing together expertise from business, government, law enforcement, technology, academia, and other sectors to build a more coordinated and resilient cybersecurity ecosystem.

For AIM, this reinforces the value of advancing cybersecurity courses and developing cybersecurity professionals who can operate at the intersection of technology and management.
Because the future of cybersecurity will not be determined by technology alone—it will be shaped by whether organizations understand the human behaviors behind the breach, the leadership decisions behind resilience, and the partnerships required to stay ahead of a threat that recognizes no borders.

