
It may be that humans are not the weakest link after all (photo by Travis Juntara, CC BY 2.0)
Most fields of research and practice have their own sayings. Sayings that are said and repeated without much thinking. Sayings that are taken as truisms, but sayings that may be folklore. Cyber security is not immune either, which is curious enough given the field’s underpinnings.
Let me demonstrate.
Recently, I peer reviewed a manuscript that contained the age-old claim that “humans are weakest link in cyber security”. The claim has been repeated throughout the years and decades so repeatedly that its origins have been lost. Sometimes, the claim and its associated phrasings are augmented with qualifying adjectives and adverbs; sometimes it is even phrased such that humans are always the weakest link. Nouns and verbs seldom wake me up, but making an assertion even stronger with qualifying words is like morning coffee for my engine.
Before continuing, apologies for my colleagues in usable security and related domains, legends, and some who do not know their own language. All clear, then: one, two, three. Go.
One: as a good knowledge commons, I did a literature search. While walking in the swamp for some time, which is increasingly drowning nowadays, I came with a Master’s thesis. After walking a while further, or deeper and damper, I concluded the thesis to be the best evidence available. Already in the abstract it says that the “phrase, as well as its various versions, has been used extensively in security literature, although scientific evidence on the role of human as the weakest link was not found in the research“. I could not agree more.
Two: the saying belongs to a whole domain of research investigating questionable, unfounded, or even faulty claims without any evidence backing them. Within computing fields, software engineering has been particularly active investigating these claims; for instance, that legal requirements are overbearing for engineers. Similarly, unhelpful assumptions have been cataloged in cyber security. In fact, so common have the sayings been that a phrasing about “Leprechaun claims” has been used.
But what to make out of all this? After all, disinformation and misinformation are rampart. And no one would deny about weaknesses of humans in cyber security. But academics should know better and do better with language; the correct phrasing would perhaps be that “humans are a weak link”.
Third: I recommended a revision.


