In a nutshell: Punishing phishing victims leads to reporting delays that extend attacker dwell time; psychological safety reduces this critical metric.
Organizations that sanction employees for phishing errors drive them to cover up — and thereby give hackers valuable time in the network. Psychological safety measurably reduces dwell time.
The Verizon Data Breach Investigations Report demonstrates that human action plays a central role in over 70 percent of all successful security breaches — typically phishing clicks or configuration errors. In response, many organizations implement a punishment culture: affected employees receive formal warnings, lose system access rights, or are publicly shamed in departmental meetings. This strategy produces a counterproductive effect — not reduced click rates, but systematic concealment of incidents.
The central metric for security effectiveness is so-called dwell time: the period between an attacker’s entry and their detection by the security team. If an employee reports a phishing click within minutes, isolating the user account, revoking active tokens, and disconnecting the network can significantly limit damage before the attacker gains administrative rights. If the employee conceals the incident out of fear of consequences, the incident response team lacks this early warning — detection often occurs weeks later through automated alerts, when the attacker is already deeply embedded in the system. A punishment culture thus multiplies dwell time many times over.
The counter-concept is based on psychological safety, a term from organizational psychologist Amy Edmondson (Harvard Business School). Psychological safety describes a work environment in which employees are confident that they will not be humiliated or punished for asking questions, raising concerns, or admitting mistakes. Applied to IT security, this means: employees are understood as part of the defense line and as a human sensor network. An employee who reports without fear of consequences that they clicked on a suspicious file provides the security team with valuable telemetry data for rapid incident response. This transparency demonstrably reduces dwell time and is thus a direct lever for damage mitigation.
Source: www.it-daily.net · Published July 28, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.