SafeITExperts

SafeITExperts

Your expert guide to cybersecurity and digital privacy. Security hardening for all platforms : Windows, macOS, Linux, and Android. Solutions aligned standards : NIST and ANSSI for comprehensive digital protection.


Demystifying Cybersecurity for the General Public

Publié par Marc sur 3 Mai 2026, 06:22am

Catégories : #phishing IA, #public security, #social engineering, #data protection

60 % of data breaches involve human error (Verizon DBIR 2025). Discover why you are the target, assess your own risk in 5 minutes, and apply immediate actions to turn that vulnerability into a strong defense — on Windows, macOS or Linux.

60 % of data breaches involve human error (Verizon DBIR 2025). Discover why you are the target, assess your own risk in 5 minutes, and apply immediate actions to turn that vulnerability into a strong defense — on Windows, macOS or Linux.

Demystifying Cybersecurity for the General Public | SafeITExperts
Open table of contents

Demystifying Cybersecurity for the General Public

Introduction – What if the weakest link was me?

The latest Verizon DBIR 2025 is unequivocal. After analyzing more than 22,000 incidents and 12,000 confirmed breaches across 139 countries, the researchers conclude that 60% of data breaches involve a non‑malicious human element – mishandling, haste, misplaced trust. Attackers are not only targeting sophisticated software vulnerabilities: their main entry point is still a simple human click.

Reading note: Words in highlighted orangeHover over them to see a short definition have a tooltip. Hover over them to display the definition.
Cybersecurity human factor illustration
📊
60% of breaches
involve a human factor (Verizon DBIR 2025). Humans are the attackers' preferred entry point.
🏢
96% of organizations
have incomplete protection against human risk (Mimecast 2026).
👤
74% of CISOs
identify human error as the top vulnerability (IBM citing Proofpoint).
📈
+70% increase in reports
of phishing in France in 2025 (Infosecurity Magazine).

Take a few seconds to think about your own digital behavior. Have you ever clicked on a link without checking its real destination? Do you use the same password for your email and your bank account? If the answer is yes, you may have been, at some point, that “weakest link”. And that’s perfectly normal. We all are, at one time or another.

This article is not meant to make you feel guilty. Its purpose is to help you understand the psychological mechanisms that cybercriminals exploit, and above all to give you concrete, immediate actions to turn that vulnerability into a strength – whether you are on Windows, macOS, Linux, or simply using your smartphone.
📊 Key figures 2025‑2026 🖱️ Click on the items on the left to navigate
6 indicators
Statistics
60% of breaches involve a human factor Verizon DBIR 2025
Out of more than 12,000 confirmed breaches, 60% have a non‑malicious human component: clicking on a phishing link, misconfiguration, accidental data sending. Source: Verizon DBIR 2025
Definition: Human factors
The set of non‑malicious user actions that facilitate a breach: clicking on a link, configuration error, accidental sending of sensitive data.
Real cases
• An employee clicks on a phishing link received by email.
• An administrator leaves an RDP port open on an exposed server.
• A colleague sends a payroll file to the wrong address.
96% of organizations have incomplete protection Mimecast 2026
Almost all companies admit gaps in their coverage of human risk. Source: Mimecast 2026
Definition: Incomplete protection
When security measures exist but do not cover all human risks: lack of training, absence of MFA, unclear policies.
Real cases
• MFA enabled only on email but not on the VPN.
• Cybersecurity training not completed by employees.
• Absence of privileged access management (local admin).
74% of CISOs identify human error as the main vulnerability IBM/Proofpoint 2024
Security leaders put the human factor at the top of their concerns. Source: IBM citing Proofpoint
Definition: Vulnerability
A weakness in a system or process that attackers can exploit. Here, human error is perceived as the primary vulnerability.
Real cases
• A CISO notices that an employee shared their password.
• Users reuse the same credentials across multiple services.
• A colleague ignores a legitimate security alert.
+51% data exfiltration incidents in France ANSSI 2025
196 reported exfiltration incidents, up sharply from 2024. Source: Infosecurity Magazine
Definition: Data exfiltration incidents
Theft of sensitive data (customers, strategy, IP) outside the organization, often via a compromised remote access or configuration error.
Real cases
• A hospital sees patient records published on the dark web.
• An SME loses its contracts due to a commercial data leak.
• A subcontractor exfiltrates a product’s plans before its release.
22% of initial accesses come from compromised credentials Verizon DBIR 2025
Nearly one quarter of successful intrusions start with the reuse of stolen credentials. Source: Verizon DBIR 2025
Definition: Compromised credentials
Email/password pairs stolen during a third‑party data breach, then reused by attackers on other services.
Real cases
• A hacked Netflix account allows the reset of the professional email password.
• A SaaS administrator account is reused on a forum whose database has leaked.
• Compromised personal credentials open access to the corporate VPN.
42% of internal incidents are intentional Mimecast 2026
Humans are no longer just clumsy: the share of internal malice is increasing. Source: Mimecast 2026
Definition: Insider incidents
Security violations deliberately caused by employees, subcontractors or partners, for various reasons.
Real cases
• A disgruntled employee sells customer data.
• An IT provider exfiltrates intellectual property.
• An employee uses their access to commit fraud before leaving.

Anatomy of human risk: Why your brain clicks before it thinks

2.1 Cognitive biases: the hacker in your head

Attackers are not just IT experts. They are, above all, amateur psychologists. They know the shortcuts our brain uses to make quick decisions. These shortcuts, called cognitive biasesAutomatic mental shortcuts that influence our decisions without us being aware of them., are predictable and universal.

🧠 The 4 cognitive biases exploited by cybercriminals 🖱️ Click on the items on the left to navigate
Psychology
Biases
⏰ The urgency bias CRITICAL
Mechanism: When we perceive an immediate threat, our brain bypasses rational analysis to act quickly. Cybercriminals artificially create this time pressure.
Concrete examples
• “Your account will be suspended in 30 minutes”
• “Immediate action required – your parcel is blocked”
• “Last chance: your subscription expires today”
• “Security alert: suspicious login detected”
How to counter it
Apply the 120‑second rule: close the message, stand up, breathe, come back with fresh eyes. In 99% of cases, the scam becomes obvious.
👑 The authority bias CRITICAL
Mechanism: We are conditioned to obey authority figures. An email that seems to come from your bank, the tax authorities, or your CEO triggers a reflex of obedience before any critical analysis.
Concrete examples
• “Your CEO requests an urgent transfer”
• “The tax office informs you of a refund”
• “Your bank has detected suspicious activity”
• “The IT department must update your computer”
How to counter it
Always verify through a different channel: if the email comes from your bank, call your advisor. If your CEO asks for a transfer, call them directly. Never reply directly to the suspicious message.
🕵️ The curiosity bias (FOMO) PSYCHOLOGICAL
Mechanism: The desire to know, to access exclusive information or to understand what is going on is often stronger than suspicion. Attackers exploit our fear of missing out.
Concrete examples
• “Confidential document: 2026 salaries”
• “Someone has viewed your LinkedIn profile”
• “Are you in this video?”
• “Your parcel has been delivered – see the photo”
How to counter it
Ask yourself: “Would this information legitimately be communicated in this way?”. An HR document would never be sent by unsolicited email. A social network would notify you via the application, not by SMS.
🏠 The familiarity bias PSYCHOLOGICAL
Mechanism: We naturally trust the brands we know. An email bearing the logo of La Poste, Amazon, or Microsoft instantly benefits from a credit of trust, even if the real sender is a cybercriminal.
Concrete examples
• Email with Amazon logo: “Your order has been shipped”
• SMS from La Poste: “Your parcel is waiting”
• Email from Microsoft: “Your password expires today”
• Netflix notification: “Your subscription has failed”
How to counter it
Check the actual sender address (not the displayed name)
Hover over links before clicking to see the destination URL
Go directly to the service via its official application
Enable MFA: even if your credentials are stolen, they will be unusable

2.2 Social engineeringA set of psychological manipulation techniques used to deceive a person and obtain confidential information or compromising actions. techniques

Did you know? PhishingA fraudulent technique consisting of sending an email mimicking a legitimate service to steal credentials or banking data. remains the main initial intrusion vector, accounting for 60% of observed cases according to ENISA. More than 80% of phishing campaigns were AI-assisted in early 2025, generating perfectly written and personalized messages.
🎣 Social engineering techniques 🖱️ Click on the items on the left to navigate
5 techniques
Techniques
📧 Classic phishing (60% of intrusions) MAIN VECTOR
Mass‑sent email, mimicking a legitimate service (bank, telecom, delivery service). The goal is to steal your credentials or banking data.
Concrete example
“Your Netflix subscription has expired. Update your payment information by clicking here.” The link leads to a perfect copy of the Netflix site.
How to recognize it
• Suspicious sender address (e.g., netflix@service-client-verification.com)
• Spelling or grammar mistakes
• Artificial sense of urgency
• Link that does not point to the official domain
🎯 Spear‑phishing (personalized targeting) DANGEROUS
Personalized targeting. The attacker has researched you (LinkedIn, social media) to make their message extremely credible.
Concrete example
An email that mentions your name, your company name, your position, and an ongoing project. The attacker may impersonate your direct manager.
How to recognize it
• The attacker knows personal information (found on social media)
• The request is unusual for the channel used
• The sender pressures you to act quickly
• The tone of the message differs slightly from that of the real colleague
📞 Vishing (voice phishing) PHONE
Fraudulent phone call. The attacker pretends to be IT support or a bank advisor. With AI, voice deepfakes make this technique formidable.
Concrete example
“Hello, this is the fraud department of your bank. We have detected a suspicious transaction of €1,200. Can you confirm your security code to cancel it?”
How to recognize it
• The bank will never ask for your MFA code over the phone
• Hang up and call back the official number of your bank
• The attacker creates urgency (“transaction in progress”)
• They may know your last transactions (prior phishing)
💬 Smishing (SMS phishing) SMS
Phishing via SMS. Fraudulent messages imitate delivery services, tax authorities, or fines.
Concrete examples
• “Parcel waiting: confirm your delivery address here”
• “Unpaid fine: regularize your situation”
• “Your health card is about to expire”
How to recognize it
• Government agencies never contact you by SMS for a fine
• The numbers are often personal 06 or 07 numbers
• The link is shortened or does not point to an official site
• When in doubt, go directly to the service via its official website
📱 Quishing (QR code phishing) QR CODE
A malicious sticker is placed on a legitimate poster (restaurant menu, charging station, parking). You scan the QR code and it redirects you to a fraudulent site.
Concrete example
You scan a QR code to pay for parking. The fraudulent site mimics the payment interface to steal your banking data.
How to recognize it
• Check that the QR code is not a sticker placed over the original
• Check the URL displayed before continuing: it must match the official site
• Use a scanning application that shows the URL before opening it
• Prefer official applications rather than QR codes

2.3 Cognitive and decision fatigue

Even the most vigilant person eventually lowers their guard. Cognitive fatigueThe progressive exhaustion of our attention and decision‑making capacities after too many digital solicitations. is a real phenomenon: at the end of the day, after hours of notifications and digital solicitations, we click “OK” mechanically, without reading.

⏱️ The 120‑second rule — Five steps to regain control
1
Close the email or SMS that triggers the emotion.
2
Stand up from your chair.
3
Breathe deeply for 30 seconds.
4
Come back with a fresh pair of eyes.
5
Verify through a different channel (phone, official application).
💡 In the vast majority of cases, the feeling of urgency fades and the scam becomes obvious.
Further reading: Read our article on voice deepfakes and discover how cybercriminals use AI to impersonate voices.

Personal life = Professional risk: Adopt Personal Zero Trust

Many people think their personal digital security has no impact on their professional life. This is a fundamental mistake. The boundary between the two worlds has become extremely porous.

🏠 Adopt Personal Zero Trust 🖱️ Click on the items on the left to navigate
3 best practices
Risks
3.1 Password reuse CRITICAL
65 to 75% of people reuse their passwords. A single hacked site exposes all your accounts.
Attack mechanism
1
An e‑commerce site gets hacked.
2
Your credentials are published in a database.
3
An automated tool tests these credentials against thousands of other services (credential stuffing).

Source: Verizon DBIR 2025 — 22% of initial accesses come from compromised credentials.

3.2 Personal email as a recovery option AVOID
Using your personal email address as the recovery address for your professional account is a risky practice. If your personal mailbox is compromised, the attacker can reset your professional password.
3.3 Connected objects (IoT) ENTRY POINT
Cameras, speakers, light bulbs… These objects often share the same Wi‑Fi network as your work computer. ENISA regularly warns about the growing risk they represent as entry points into information systems.
Solutions
Simple solution: create a “Guest” Wi‑Fi network on your router and connect all your personal objects to it.
Advanced Linux: isolation with firewalld, beware of multicast. Config: firewalld-tumbleweed-config.
Trap to avoid:
“My Facebook account has no value for a hacker. I am not an important person.”
False. A hacker is interested in your email address, your friends list, your employer. Each piece of information is a piece of the puzzle.

Real case analyzed: The fake bank advisor scam

To make these concepts more tangible, here is the story of a real compromise, anonymized but representative of thousands of similar cases.

👩‍💼
Context
Victim: Sophie, 42, administrative manager in an SME.
Problem: She uses the same password for her bank, Amazon, and her personal email.
DayEventAnalysis
D‑30Data leak from an e‑commerce site. Sophie’s credentials exposed.Sophie ignores the leak.
D‑7Attempt to connect to her professional email. Failed thanks to MFA.✅ MFA played its barrier role.
D‑3Call from the fake bank advisor who knows personal details.⚠️ Sophie is in a state of trust and stress.
D‑0The fake advisor asks for the MFA code received by SMS. Sophie gives it.❌ Fatal mistake.
D+5Fraudulent transfer of €4,500.❌ No phone verification of the bank account details.
Lesson to remember: An MFA code is like the key to your house. Never give it to a stranger, even if they wear a uniform. Always verify through a different channel: hang up and call back the official number.
Technical alert: The limits of classic MFA
SMS‑ or app‑based MFA (TOTP) is no longer foolproof. Cybercriminals now use Adversary‑in‑the‑Middle (AitM) attacks via malicious reverse proxies (e.g., Evilginx). These tools create a perfect copy of the legitimate site, intercept your password, your MFA code, and steal the valid session cookie. Only physical security keys or Passkeys (FIDO2/WebAuthn) resist this attack because they cryptographically bind the authentication to the real domain name of the site.

Your personal action plan (15 minutes)

Enough theory. Let’s take action. Honestly answer the 10 questions below, then check your score and the recommended actions.

Interactive self‑audit 🖱️ Click on the items on the left to navigate
Self‑assessment
Navigation
Self‑assessment questionnaire
Check each statement that is true for you. Be honest, nobody is watching!
Your cybersecurity score
0
out of 10 points
“5 minutes to secure the essentials” checklist
Golden backup rule: the 3‑2‑1 method
3 copies of your important data
On 2 different types of media (external hard drive AND cloud)
Including 1 copy stored off‑site
“Human Factor” maturity assessment grid
LevelDescriptionRecommended action
1. VulnerableReused passwords, no MFA5‑min checklist
2. AwareMFA enabled, recognizes suspicious emailsInstall a password manager
3. ProtectedPassword manager, MFA everywhere, backupsSwitch to Passkeys (FIDO2)
4. ResilientPasskeys, 3‑2‑1 backupsBecome a security ambassador
5. ExemplaryImpeccable digital hygieneContribute to collective awareness
6. AI‑ResilientDetects deepfakes and AI‑generated contentUse AI detection tools

Choosing a password manager

Here is a comparison of the main password managers, suitable for all operating systems.

🗄️ Password Manager Comparison 🖱️ Click on the items on the left to navigate
5 tools
Tools
🔵 Bitwarden — The easiest to get started RECOMMENDED
Open source, free (unlimited) manager, automatic synchronization across all your devices. Compatible with Windows, macOS, Linux, Android, iOS. Supports Passkeys (FIDO2) in the Premium version. Ideal for both beginners and advanced users.
Features
✅ Free unlimited
✅ Open source (auditable)
✅ Automatic synchronization
✅ Browser extensions
✅ Passkeys (Premium)
🌐 bitwarden.com
🔒 KeePassXC — Full control, 100% local storage RECOMMENDED
Password file stored locally (you alone hold it). Compatible with Windows, macOS, Linux. On mobile, use KeePassDX (Android) or Strongbox (iOS/macOS). Ideal for those who want total control without cloud.
Features
✅ 100% local (no cloud)
✅ Open source
✅ Free
✅ Compatible with KeePassDX (Android) and Strongbox (iOS)
❌ Manual synchronization
🌐 keepassxc.org
🟣 1Password — Intuitive interface, native Passkeys SUBSCRIPTION
High‑end proprietary solution. Proprietary core, but open‑source CLI and libraries. Native Passkey support, very polished interface. Subscription required.
Features
✅ Excellent user interface
✅ Native Passkeys
✅ Travel mode (vault hiding)
❌ Paid subscription
⚠️ Proprietary core
🌐 1password.com
🟢 Proton Pass — Integration into the Proton ecosystem FREE (LIMITED)
Open‑source manager integrated into the Proton ecosystem (Mail, VPN, Drive). Free version is limited but functional; paid version is complete.
Features
✅ Open source
✅ Proton integration (Mail, VPN, Drive)
✅ Free version available
❌ Advanced features paid
🌐 proton.me/pass
🟠 Dashlane — VPN and dark web monitoring included 25 PASSWORD MAX (FREE)
Proprietary solution with integrated VPN and dark web monitoring. The free version is limited to 25 passwords, insufficient for complete security.
Features
✅ Integrated VPN
✅ Dark web monitoring
❌ Free limited to 25 passwords
❌ Proprietary
🌐 dashlane.com
Recommendations:
Beginner: Bitwarden (free, simple, automatic sync).
Total control: KeePassXC (local file, compatible with KeePassDX/Strongbox).
Maximum security: Choose a manager that supports Passkeys (FIDO2).
New in 2026: Passkeys (FIDO2)
Passkeys represent a major advance: an authentication that is completely resistant to phishing and AitM attacks. Unlike passwords or MFA codes, Passkeys are never exposed on the network and cryptographically bind the authentication to the real domain name of the site.

Tools & Appendices

7.1 Glossary

TermDefinition
MFA / 2FAMulti‑Factor Authentication: requires at least two proofs of identity (password + code).
FIDO2 / PasskeysPasswordless authentication, resistant to phishing and AitM attacks.
Credential stuffingAutomated attack by reusing stolen credentials.
AitM (Adversary‑in‑the‑Middle)Session interception attack that bypasses classic MFA.
RansomwareMalware that encrypts data for ransom.

7.2 Free verification tools

🛠️ Free verification tools 🖱️ Click on the items on the left to navigate
3 tools
Tools
🦠 VirusTotal FREE
Analyze a suspicious file or URL with more than 70 antiviruses simultaneously. VirusTotal is a Google‑owned service that aggregates the results of many detection engines.
How to use it
1. Go to virustotal.com
2. Upload a suspicious file or paste a URL
3. Check the detection report
⚠️ Warning: do not upload confidential files (files are shared with the community).
🔗 URLScan.io FREE
Visualize a suspicious site without visiting it. URLScan.io takes a screenshot of the site and analyzes its behavior, preventing you from exposing your IP address or browser.
How to use it
1. Go to urlscan.io
2. Paste the suspicious URL
3. Click “Scan”
4. View the screenshot and technical details (redirects, contacted domains)
Check if your email address has been compromised in a data leak. This service created by Troy Hunt lists public data breaches and lets you know which sites have exposed your information.
How to use it
1. Go to haveibeenpwned.com
2. Enter your email address
3. View the list of breaches
4. Immediately change the password on compromised sites

7.3 English‑language resources

🎓
Free European resources and training for all levels.
🛡️
Cybersecurity awareness resources for individuals and families.
🇬🇧
Official guidance from the UK's National Cyber Security Centre.

Prospective conclusion: AI is coming, humanity remains

The threat is evolving. Generative AI is becoming a formidable weapon. ENISA warns: more than 80% of phishing campaigns were AI‑assisted in early 2025. CERT‑FR confirms that this trend is accelerating. The Mimecast 2026 report also points out that 42% of internal incidents are now intentional.

Humans are not the weakest link. They are the sensitive link – the one who feels, doubts, adapts. And it is precisely this sensitivity that becomes the ultimate rampart.

— SafeITExperts

Faced with this sophistication, our weapons remain simple and human:

🐢
Slow down
When you feel urgency, take time to reflect.
🔍
Verify
Through a channel different from the one used by the contact.
🤔
Cultivate constructive doubt
A healthy skepticism is your best defense.

Take back control. Today.

What about businesses?
A dedicated article on mitigation strategies for enterprises is in preparation. In the meantime, here are the key axes:
Reporting culture: reward reporting, do not punish.
Useful friction: explicit confirmations for critical actions.
Phishing simulations: educational feedback, not "name and shame".
Continuous training: regular micro‑learnings.
Least privilege: access limited to the strictly necessary.
Passkeys (FIDO2): deployment of phishing‑ and AitM‑resistant authentication.

Verified sources

SourceYearKey data
Verizon DBIR202560% of breaches involve a human factor. 22% of initial accesses = compromised credentials.
ENISA Threat Landscape2025Phishing = 60% of initial intrusions. >80% of phishing AI‑assisted.
Infosecurity Magazine (ANSSI data)2025196 exfiltration incidents (+51%). 128 ransomware incidents.
Infosecurity Magazine2025Phishing reports +70% in France.
Mimecast202696% of organizations have incomplete protection. 42% of insider incidents are intentional.
IBM (citing Proofpoint)202474% of CISOs: human error = main vulnerability.
FIDO Alliance / NIST2025‑2026Passkeys = authentication resistant to phishing and AitM attacks.
CERT‑FR2026Threat landscape in France. Increase in AI‑assisted phishing.

Further reading from SafeITExperts

🔑
Complete guide to creating and managing strong passwords following ANSSI recommendations.
🌍
Security comparison of Windows, macOS, and Linux in 2026.
🛡️
Complete guide to proactive protection for Linux, Windows, and macOS.
🎙️
Analysis of voice deepfakes and how to protect against them.
🔐
Understanding Passkeys, Push MFA, and Device Trust.
🛡️
Multi‑platform practical guide to secure your devices.

About the author

Marc is the editor‑in‑chief of SafeITExperts, a bilingual FR/EN technical blog dedicated to cybersecurity, Linux, and digital sovereignty.

NetworkLink
Websitesafeitexperts.com
X (Twitter)@crisisdav
FacebookSafeITExperts
Bluesky@crisis23.bsky.social
Mastodon (Infosec)@safeitexperts
Emailsafeitexperts@safeitexperts.com

Article published on May 1, 2026 by Marc — SafeITExperts.
© SafeITExperts — Reproduction allowed with attribution.

Pour être informé des derniers articles, inscrivez vous :
Commenter cet article

Archives

Nous sommes sociaux !

Facebook X Bluesky Mastodon GitHub Reddit RSS

Articles récents