For all the focus on tools and technology, cybersecurity remains a very human challenge. Matthew Mackay, Security Practice Lead at Logiq, explains.
Summary:
- Organisations with successful cybersecurity are those who continuously adapt and improve their practices
- Cybersecurity disasters are rarely about a single vulnerability, and more often a result of systemic failures
- Learning from mistakes or near misses is key, and doesn't happen automatically; it requires building a learning-orientated culture
- Creating a culture of psychological safety which encourages open feedback loops and transparency over mistakes is key
- Organisations who build the systems and culture to enable fast learning and adaptation will be those who succeed
Cybersecurity is inherently sociotechnical, shaped by the interaction of people, processes and technology. Despite this, the human element is too often overlooked. The difference between organisations that recover and strengthen and those that suffer lasting damage lies in their ability to learn, adapt and continuously improve. Open feedback loops, where organisations actively use failure data to adapt systems and prevent recurrence, are therefore not simply a ‘nice-to-have’.
These three distinct perspectives converge on the same truth: in cybersecurity, we must learn from our mistakes.
Cybersecurity is a human system
BBC Cyber Correspondent and author Joe Tidy’s account of the Kivimäki breach of a Finnish psychotherapy provider in ‘Ctrl-Alt-Chaos’ is a stark demonstration. The attack itself was not technically groundbreaking. The real failure lay in the organisation’s inability to recognise the sensitivity of the data it held, to implement basic controls, and to prepare for the consequences of a compromise.
The result was catastrophic. Tens of thousands of individuals were personally extorted using their most private therapy records. This was not just a data breach; it was a large-scale human crisis.
What this incident exposes is that cybersecurity failures are rarely about a single vulnerability. More often, they are systemic failures of governance, awareness, prioritisation, and learning. Without mechanisms to detect weaknesses, provide feedback lessons and adapt controls, organisations unknowingly carry risk forward until it manifests.
The role of feedback
This is where ‘black box thinking’ becomes critical. As author Matthew Syed highlights in the book of the same name, in the aviation industry, every incident is analysed, understood and used to improve the system. This illustrates how high-performing organisations learn from small failures and near misses before they become disasters, resulting in one of the safest industries in the world.
The point is proportionality: high-hazard industries such as aviation invest heavily in learning because failure can create large-scale human consequences, not just operational disruption.
Learning does not happen automatically after failure. It requires structured reflection, investigation, and institutional memory. Organisations need mechanisms for capturing lessons, not just good intentions.
Cybersecurity demands the same culture and approach. Near misses, minor breaches and audit findings should be treated as valuable data points to optimise and learn from experience. Each one is an opportunity to strengthen the system before an adversary exploits the weakness.
In cybersecurity, it is easy to blame a user for clicking a link or an analyst for missing an alert. Still, perhaps the more valuable question is: what flaw in the system made that error likely or hard to detect?
Organisations fail to learn when people are chided for mistakes. In cybersecurity, this is particularly relevant, as teams may hide errors, near misses, or weak controls if they fear reputational or professional consequences. A blame culture suppresses the very information needed to improve security. As aviation has a ‘just safety’ culture, we need a ‘just security’ culture in cybersecurity.
Continuous improvement
The book The Phoenix Project (Kim et al.) shows how this learning is operationalised. Its ‘three ways’ of DevOps — flow, feedback and continuous learning — provide a blueprint for turning insight into action. Although this is geared toward the context of an IT department and DevSecOps, the implications are equally relevant to cybersecurity.
In cyber security, ‘flow’ means understanding how security controls support business processes end-to-end rather than operating in isolation, positioning cyber security as a business enabler.
For you
Be part of something bigger, join BCS, The Chartered Institute for IT.
‘Feedback’ means rapidly identifying when controls fail or are bypassed and ensuring that information reaches decision-makers, so that security continues to serve the organisation and protect what matters most.
‘Continuous learning’ means embedding improvements into architecture, processes and behaviours, rather than simply fixing the immediate issue. Organisations often fix the obvious direct cause but miss the deeper root cause; techniques such as the ‘5 Whys’ help expose and address the underlying systemic issue.
This is where many organisations struggle. They treat incidents as discrete events rather than signals of systemic weaknesses. As a result, fixes are localised and temporary, rather than structural and enduring.
From compliance to learning
A recurring challenge, particularly in regulated environments, is the dominance of compliance-driven thinking. Frameworks are implemented, audits are passed and controls are evidenced. However, compliance poses a few challenges. Principally, the illusion of security, but also, how do we learn from experience to ensure we are suitably protecting what truly matters?
The Kivimäki case illustrates this clearly. Even where controls exist on paper, without active feedback and continuous improvement, they may be ineffective and possibly untested in practice. True cyber security maturity comes when organisations move beyond asking, ‘are we compliant?’, to asking, ‘what have we learned, how does this align to our risk appetite, and how can we improve?’.
Creating a learning culture
At its core, this is a cultural challenge. Open feedback loops depend on psychological safety, so that people feel able to report issues, mistakes, and near misses without fear of reprisal. They also rely on transparency, ensuring that incidents and findings are shared rather than hidden, and accountability at the system level, where the focus is on improving processes rather than blaming individuals.
Without this, critical information is lost. Teams optimise locally rather than collectively, leaving leadership with a false sense of security.
The practical implication
For cybersecurity leaders, the implication is clear. Resilience is not built through more controls alone; it is built through better learning systems.
In practice, that means treating every risk assessment, control assessment, audit and incident as an opportunity to improve, creating structured mechanisms to capture and act on feedback, and embedding continuous improvement into governance rather than treating it as an afterthought.
In a world of constant threat, the organisations that continue to thrive are not those that avoid failure but those that learn faster than their adversaries can adapt. The point here is that compliance approaches don’t necessarily ‘test’ controls; real life and adversaries do.
Closing thought
‘Ctrl Alt Chaos’ showcases the cost of failure, ‘black box thinking’ highlights how organisations can learn from it, and The Phoenix Project emphasises how that learning can be turned into operational discipline. Together, they point to a simple but powerful conclusion: in cybersecurity, the strongest defence is not perfect prevention but the capacity to learn, adapt and continuously improve.
This is also one of the many arguments in my forthcoming book, Cyber Security for Business Leaders, to be published by BCS in October 2026. The book reframes cyber security as a business risk and a resilience challenge, not simply an IT problem, and focuses on the questions that matter most: what do we need to protect, what can we not afford to lose, how secure do we need to be, and how do we know when we are secure enough?
In a threat landscape that never stands still, the organisations that endure will not be those that chase the illusion of perfect security, but those that build the discipline to learn faster, adapt sooner, and improve before the next failure becomes a crisis.
Take it further
Interested in this and similar topics? Explore BCS' books and courses: