Security Fatigue and Click Regret:
Understanding the Human Side of Cybercrime
Reading Time: 7 minutes
When we think of cybersecurity, we often picture firewalls, encryption, and AI-powered threat detection. But the truth is, the biggest vulnerability in any system isn’t the tech—it’s the people using it.
Cybercriminals know this. That’s why phishing emails are designed to trigger urgency, fear, or curiosity. It’s why password spraying works—because people reuse simple passwords across platforms. And it’s why even the most sophisticated security tools can be undone by a single click.
So, what’s really going on inside our heads when we make risky decisions online?
Cognitive Biases at Play
Humans are wired to take mental shortcuts. These are called heuristics, and while they help us make quick decisions, they can also lead us astray:
- Optimism bias: “It won’t happen to me.” This is why people ignore security warnings or delay software updates.
- Authority bias: We’re more likely to trust messages that appear to come from a boss or government agency—even if they’re fake.
- Urgency bias: When something feels urgent, we act fast. That’s exactly what phishing emails exploit.
Security Fatigue Is Real
Between MFA prompts, password resets, and constant alerts, employees can feel overwhelmed. This leads to security fatigue—a state where people start ignoring best practices just to get through the day.
The solution? Make security feel easy, not exhausting. Tools like password managers, single sign-on, and smart MFA can reduce friction and improve compliance.
Training That Actually Works
Traditional security training often fails because it’s boring, generic, or forgettable. To change behaviour, we need to tap into psychology:
- Make it personal: Show how a breach could affect the individual, not just the company.
- Use storytelling: Real-world examples stick better than dry facts.
- Gamify it: Platforms like usecure use quizzes, simulations, and microlearning to keep engagement high.
Culture Is the Ultimate Defence
Cybersecurity isn’t just an IT issue—it’s a culture issue. When employees feel safe to ask questions, report suspicious activity, and admit mistakes, the whole organisation becomes more resilient.
Psychological safety is key. If someone clicks a dodgy link, they should feel supported—not shamed. That’s how we build a team that learns, adapts, and protects itself.
Australian Cybercrime Snapshot
According to the Australian Cyber Security Centre (ACSC) Cyber Threat Report 2023–24:
- Over 76,000 cybercrime reports were filed last year—a 13% increase from the previous year. That’s one report every seven minutes.
- Business Email Compromise (BEC) caused more than $98 million in losses, with an average cost of $64,000 per incident.
- Threat actors are increasingly using AI to enhance attack sophistication, making human awareness and behaviour more critical than ever.
Final Thought
The best cybersecurity strategy isn’t just technical—it’s behavioural. By understanding how people think, feel, and act, SMEs can build defences that are not only strong, but human-proof.
Because at the end of the day, it’s not just about protecting data—it’s about protecting people.




