Skip to content

AI Is Making Cybersecurity's Human Risk Problem Worse

CYBR.Minded’s post-Hacker Summer Camp episode examines burnout, cognitive overload, AI and why human cybersecurity risk starts with how organizations design security.

This article is based on the latest episode of CYBR.Minded with Dr. Dustin Sachs. Check out the full episode:

Lessons from Hacker Summer Camp
Dr. Dustin Sachs reflects on Hacker Summer Camp, sharing insights on burnout, decision-making, culture, behavior, and cybersecurity’s human side

Cybersecurity spent another Hacker Summer Camp talking about artificial intelligence.

How AI will transform the SOC. How autonomous agents will hunt threats, find vulnerabilities and respond to attacks. How organizations can keep humans in the loop while machines increasingly perform work that once belonged exclusively to security practitioners.

But there is another side to that conversation that received considerably less attention in Las Vegas: What happens to the humans left in that loop?

That question runs through a special post-Hacker Summer Camp episode of CYBR.Minded, hosted by Dr. Dustin Sachs. Rather than focusing on another new security technology, Sachs assembled perspectives from conversations at Black Hat alongside current and upcoming CYBR.Minded guests around the question at the center of the podcast:

What does the human side of cybersecurity actually mean?

The answers suggest cybersecurity may have been thinking about the problem backward.

Full Hacker Summer Camp coverage:

Hacker Summer Camp 2026: Complete Black Hat, BSidesLV, Ai4 & DEF CON Coverage
The CYBR.SEC.Media crew is in Las Vegas to bring you all the insights coming from this week’s proceedings.

AI Doesn't Automatically Reduce the Human Burden

When cybersecurity talks about artificial intelligence, automation is usually presented as part of the solution to an increasingly difficult workload problem.

One of the perspectives Sachs highlights challenges that assumption.

Organizations are deploying more tools and more AI without necessarily understanding how those technologies affect the cognitive workload of the people expected to use them. That problem becomes particularly acute with agentic AI.

Security teams increasingly talk about keeping a "human in the loop" as a safeguard against autonomous systems making the wrong decisions. But if those humans are expected to continually review, validate and approve an expanding stream of machine-generated decisions, the safeguard can create another problem.

"We've just turned people into a bunch of rubber stampers," one speaker says.

Instead of eliminating cognitive overload, AI could simply change its shape.

That observation is particularly relevant for security operations teams that were already struggling with alert fatigue long before generative AI arrived. One participant describes having run a global NOC/SOC where analysts were burned out by the volume of alerts they were expected to process.

Adding AI on top of that environment doesn't necessarily fix it.

The real question is whether the technology removes meaningful cognitive work or simply gives already-overloaded analysts another system they must supervise.

Burnout Is a Cybersecurity Risk

That leads to another recurring theme in the episode: cybersecurity burnout shouldn't be treated exclusively as an employee wellness issue.

It can become an organizational security problem.

One speaker describes a persistent "hero mentality" within cybersecurity—the idea that practitioners should always be available, always fighting the next incident and willing to carry enormous workloads.

That culture can be celebrated as dedication.

It can also produce exhausted analysts whose ability to make good decisions deteriorates precisely when organizations depend upon them most.

The technology matters, the speaker argues, but organizations have to remember that humans still operate it.

Other participants return to the same point from different directions. Stress, competing priorities and cognitive fatigue don't exist separately from cybersecurity controls. They affect whether those controls work.

If security teams consistently operate at maximum capacity, failures shouldn't be surprising.

One participant uses the analogy of running a car engine continuously at maximum RPM. Eventually something is going to break.

The Policy Says Patch. Reality Says Something Else.

The disconnect between cybersecurity's technical expectations and human reality extends beyond the SOC. One of the strongest examples in the episode is remarkably simple. An organization can write a cybersecurity policy declaring that systems "shall patch in one day." That doesn't mean the organization can actually patch them in one day.

Security leaders have to understand the processes behind the policy, how employees actually work and whether the organization has made it practical for people to do the right thing.

"It doesn't matter what's on paper," one participant says. "It doesn't matter what tool does something. It matters how the people implement the tool."

Cybersecurity has spent decades creating policies, frameworks and technical controls designed to dictate secure behavior. When those controls fail, the explanation frequently lands on the human being who failed to follow them.

The CYBR.Minded conversations suggest organizations should ask another question first:

Was the security system designed around how people actually work? A phishing simulation provides an obvious example. Employees can know they're not supposed to click a malicious link and someone will eventually click one anyway.

The measure of a resilient organization isn't whether it can eliminate human failure. It's whether its security architecture assumes that failure will sometimes happen and prevents one mistake from becoming a catastrophe.

Human Risk Is Bigger Than Phishing

Part of the difficulty may be cybersecurity's definition of the "human element."

For years, human risk has often been reduced to phishing, passwords, identity and security awareness training.

The episode presents a much broader definition. It includes trustworthy decision-making. It includes how departments communicate about risk. It includes workload, incentives, organizational pressure, ambiguity and competing priorities.

And it includes the people doing the security work themselves: SOC analysts, threat hunters, architects, engineers, GRC practitioners and security leaders.

As one participant puts it, organizations spend enormous amounts of time discussing security technology while paying considerably less attention to "the environmental conditions for the people who are working the technology."

Those conditions matter because security doesn't happen in a policy document or product dashboard. It happens when a person has to make a decision.

Cybersecurity Has a Human-Behavior Expertise Gap

Perhaps the most uncomfortable observation in the episode concerns the expertise organizations bring to the problem.

Cybersecurity teams routinely employ specialists in malware, penetration testing, identity, cloud security, application security, threat intelligence and countless other technical disciplines.

But how many employ someone whose expertise is human behavior? One participant points out that few cybersecurity organizations have dedicated specialists in human factors, cognitive psychology, behavioral science or neuroscience helping them understand how people actually behave inside the security environments they've created.

That's a strange omission for an industry that routinely identifies humans as one of its largest sources of risk.

The speaker goes further, arguing that addressing the human element isn't solely an industry problem. Government, academia and industry all have roles to play.

The underlying argument is difficult to dismiss: If cybersecurity wants to manage human risk, it needs to understand humans.

The Problem Beneath the Problem

That brings the conversation back to Sachs' broader premise for CYBR.Minded: looking beyond controls to find the problem beneath the problem.

A security control can exist and still fail.

It can fail because someone is under pressure. Because priorities conflict. Because incentives encourage the wrong behavior. Because instructions are ambiguous. Because an analyst is exhausted. Because the secure process is considerably harder than the insecure one.

Or, increasingly, because a human being is expected to supervise an expanding collection of automated systems operating at machine speed.

Hacker Summer Camp provided plenty of evidence that AI will become a bigger part of cybersecurity.

The harder question is what that means for the people operating alongside it.

For years, cybersecurity has asked how organizations can make humans behave according to their security controls.

The better question may be how organizations can build security controls around how humans actually behave.

Because the human may not be the weakest link.

The environment we're asking the human to operate in may be.

HOU.SEC.CON CTA

Latest