We’ve all said it: people are the weakest link. But that’s lazy thinking. People are also the only flexible part of our defence model, the part that can sense, adapt, and recover faster than any system we’ll ever build. If you train that muscle well, it will outperform any tool.
The real challenge isn’t awareness… it’s fatigue. Everyone’s been told to stop clicking links, to use MFA, to report the phishing simulation they just failed. The gap now isn’t knowledge, it’s belief. Do people genuinely think their actions matter? Because when they do, they behave differently.
We’re seeing more business-driven CISOs, fewer command-and-control models. Awareness programs that act like part of the operating system, not an annual campaign. Risk teams borrowing from marketing, psychology, and crisis management, not to scare people, but to make them capable.
2026 will test how well we’ve built awareness into the rhythm of our organizations. It’s not about another toolkit or training cycle. It’s about knowing whether we’ve built a culture that knows how to act when the playbook isn’t enough.
That’s what still actually works.
By Karl-Fredrik “Kalle” Larsson, CISO at ID North
October 2025
ID North proudly annonces that we have been chosen by Ikano Bank as the strategic implementation partner for an IAM implementation of a hybrid solution consisting of both Sailpoints Identity and Governance platform, IdentityIQ..
As we look ahead to 2025, it’s clear that businesses are facing an increasingly complex landscape of cybersecurity and identity security challenges. New attack surfaces, the rise of AI-driven threats, ransomware tactics, and the..
We are proud to announce our new partnership with IAMONES, a modern, AI-native Identity Governance and Administration (IGA) platform built for speed, usability, and automation. Designed to simplify how digital identities are governed, IAMONES helps..
















