“People Should Be More Careful Online.” But Is That Enough?
Someone loses money to an online scam.
Perhaps they clicked a link that looked as though it came from their bank. Maybe they responded to a WhatsApp message from someone they thought they knew. Perhaps they gave away a one-time password after receiving a convincing phone call. Or they transferred money to an account believing they were paying a legitimate supplier.
Then come the comments.
“Why did they click the link?”
“Why would anyone give out their password?”
“People need to be more careful online.”
Fair enough.
We all have some responsibility for protecting ourselves online. We lock our houses. We protect our bank cards. We do not normally hand our PINs to strangers. In much the same way, we should use strong passwords, enable multi-factor authentication, question suspicious messages and think carefully before sharing sensitive information online.
But there is a more difficult question hiding behind the advice to “be careful”:
How careful is careful enough?
And perhaps more importantly:
Can the security of our increasingly digital society really depend on millions of ordinary people never making a mistake?
The Problem With “Just Be Careful”
“Be careful online” is sensible advice.
The problem begins when it becomes the primary answer to cybersecurity risk.
Think about how we approach safety elsewhere.
Cars have seatbelts, airbags, anti-lock braking systems, warning lights and increasingly sophisticated collision-avoidance technologies. Roads have traffic lights, speed limits, road markings and pedestrian crossings.
We still expect drivers to behave responsibly.
But we do not design the entire road transport system on the assumption that every driver will behave perfectly every second of every journey.
Why should digital systems be different?
People get tired. They become distracted. They trust people they know. They respond quickly when frightened. They make decisions under pressure. They sometimes fail to notice small changes in an email address or website.
Cybercriminals know this.
In fact, much of modern cybercrime is specifically designed around human behaviour.
The attacker does not necessarily need to defeat sophisticated encryption. Sometimes it is easier to convince someone to open the door.
The Scammer Is No Longer Obviously a Scammer
There was a time when many fraudulent messages were relatively easy to recognise.
The spelling was terrible. The story was unbelievable. The email address looked suspicious. The website was poorly designed.
Those clues still exist, but they are becoming less reliable.
A modern phishing email can be professionally written. A fraudulent website can closely resemble a legitimate banking or e-commerce site. A criminal can impersonate a senior executive, supplier, relative or colleague.
Artificial intelligence makes this problem even more complicated.
Generative AI can help produce convincing emails in seconds. Messages can be personalised. Images can be manipulated. Voices can be cloned. Video can be fabricated.
The old advice to “look for spelling mistakes” suddenly feels inadequate.
We are approaching an environment in which identifying deception may sometimes require knowledge that an ordinary consumer simply does not possess.
That changes the responsibility conversation.
Of Course the Individual Has Responsibility
None of this means individuals should abandon responsibility for their online behaviour.
We should still learn basic digital-security practices.
Do not casually share passwords or one-time passwords. Use multi-factor authentication where available. Be suspicious of unexpected requests for money. Verify unusual instructions through another communication channel. Keep devices updated. Avoid using the same password everywhere.
Digital literacy increasingly needs to include cybersecurity literacy.
But acknowledging individual responsibility is very different from making the individual responsible for everything.
Consider an employee who receives an extremely convincing phishing email and clicks a malicious link.
We can ask:
Why did the employee click it?
But we should also ask:
Why was one click capable of causing catastrophic damage?
Did the organisation have appropriate access controls?
Was multi-factor authentication enabled?
Were employees adequately trained?
Could unusual account activity have been detected?
Were critical systems segmented?
Were backups available?
Did one employee have access to information or systems they did not actually need?
The employee's decision is one part of the incident.
It is not necessarily the whole incident.
Security Should Expect Human Error
Perhaps one of the most useful principles for thinking about cybersecurity is this:
People will occasionally make mistakes. Secure systems should be designed with that reality in mind.
This is not an excuse for reckless behaviour.
It is recognition of human nature.
Imagine a company employing 1,000 people.
Suppose every employee correctly identifies suspicious messages 99% of the time.
That sounds excellent.
But attackers do not necessarily need everyone to make a mistake.
They may only need one person, once.
If the organisation's security architecture assumes that nobody will ever click the wrong link, then perhaps the vulnerability is not simply human behaviour.
Perhaps it is also the architecture.
What About Banks and Digital Platforms?
The same argument applies to consumer-facing services.
Suppose someone normally makes relatively small transactions from Zimbabwe and suddenly their account attempts several unusual high-value transfers.
Should the bank simply process them because the correct credentials were entered?
Or should something in the system ask:
Is this normal behaviour for this customer?
Banks already invest heavily in fraud detection precisely because authentication alone cannot eliminate fraud.
Similarly, digital platforms have choices about security.
They determine password requirements.
They design account-recovery processes.
They decide when additional verification is necessary.
They develop systems for identifying suspicious logins.
They determine how easy it is to impersonate another person.
They decide how prominently security warnings appear.
These are design decisions.
And design decisions affect risk.
Digitalisation Creates Responsibility Too
There is another dimension to this debate that is particularly important in rapidly digitising economies.
Governments, banks, businesses and technology companies are encouraging people to move online.
We bank online.
We buy online.
We communicate with businesses through WhatsApp and social media.
We submit information through digital platforms.
Small businesses advertise and sell through social networks.
Payments increasingly move through electronic systems.
These developments create enormous benefits.
But if institutions encourage citizens to participate in digital systems, surely those institutions acquire some responsibility for making those systems reasonably safe for ordinary people to use.
We cannot simultaneously tell people:
“Move online. Digital is the future.”
and then, when something goes wrong:
“You should have known better.”
That contradiction deserves much more attention.
The Danger of Victim-Blaming
There is also an uncomfortable social dimension to online fraud.
When someone's house is burgled, our first reaction is not usually:
“Why did you own things worth stealing?”
Yet when someone falls victim to an online scam, discussions can quickly focus on what the victim did wrong.
Certainly, mistakes should be examined. Understanding them helps prevent future incidents.
But there is a difference between learning from behaviour and blaming the victim.
Cybercriminals deliberately exploit trust, urgency, fear, authority, curiosity and confusion.
A person receiving a message saying their bank account is about to be suspended may not behave exactly as they would while calmly attending a cybersecurity workshop.
That emotional manipulation is part of the attack.
The attacker created the situation deliberately.
We should not lose sight of that.
Perhaps We Are Asking the Wrong Question
After a cyber incident, the instinctive question is often:
Who made the mistake?
Perhaps a better question is:
Which layers of protection failed?
Imagine online security as several layers:
Individual → Organisation → Platform → Financial or Telecom Provider → Regulatory Environment
The individual has responsibilities.
The employer has responsibilities.
The technology provider has responsibilities.
Banks and telecommunications companies have responsibilities.
Government and regulators have responsibilities.
The precise balance will differ depending on the situation.
But online safety becomes stronger when these layers reinforce one another.
Responsibility Should Follow Power
One principle may help us think about where responsibility belongs:
The greater an actor's ability to prevent, detect or reduce a digital risk, the greater their responsibility should be.
An individual can control whether they share their password.
A bank controls its authentication architecture and fraud-monitoring systems.
An employer controls employee permissions and access to sensitive information.
A technology platform controls its security defaults and account-recovery processes.
A telecommunications provider controls important parts of the infrastructure through which digital identities and communications operate.
A regulator can establish minimum standards and consumer protections.
These actors do not have equal power.
It therefore makes little sense to give them equal responsibility.
A Shared Digital Responsibility
Perhaps the future of cybersecurity requires moving beyond the idea of personal responsibility towards shared digital responsibility.
Individuals must become more digitally aware.
Organisations must design systems that anticipate human mistakes.
Technology companies must make secure behaviour easier rather than expecting every user to become a cybersecurity specialist.
Banks and telecommunications companies must continue strengthening fraud prevention.
Governments and regulators must ensure that consumer protection evolves alongside digitalisation.
And cybersecurity professionals may need to reconsider one of their favourite phrases:
“Humans are the weakest link.”
Sometimes they are.
But sometimes the weakest link is a system that allows one predictable human mistake to become a disaster.
So yes, people should be more careful online.
We should educate ourselves. We should question suspicious messages. We should protect our credentials. We should take digital security seriously.
But that cannot be where the conversation ends.
Because if millions of people are going to live, work, bank, shop and communicate through digital systems, perhaps the more important question is not simply:
“Why wasn't the user more careful?”
It is:
“Did we build a digital environment that was reasonably safe for an ordinary human being to use?”
That is a much harder question.
And it is the question that organisations, technology companies, financial institutions, regulators, and all of us, need to start answering.
This is the first article in the Who Is Responsible for Your Online Safety? series, exploring individual responsibility, cybersecurity, digital platforms, institutional duty and consumer protection in an increasingly digital world.
