
Chief Executive Officer
Published: September 22, 2026

Human layer security is the discipline of protecting the people layer of an organization: the judgment calls, conversations, approvals and identity claims that sit above the seven OSI layers and that no firewall inspects. It is commonly called Layer 8 security.
The human element was involved in 62% of breaches in the Verizon 2026 Data Breach Investigations Report, and the FBI logged $20.9 billion in 2025 cybercrime losses, including $3.04 billion from business email compromise alone.
Generative AI moved the attack from text to live voice and video. Awareness training was designed for an era when hearing a colleague’s voice counted as evidence. That era is over.
A working program runs five control domains: identity assurance, communication trust, authorization and process, behavior and culture, and measurement and response.
Use the five-stage maturity model in this post to place your program. Most enterprises sit at Stage 2 or Stage 3. The move that matters in 2026 is reaching Stage 4, where live communication is verified in real time rather than trusted by default.
Three moves inside 90 days: phishing-resistant MFA everywhere, a mandatory out-of-band callback rule for payment and credential changes, and real-time deepfake detection on the channels your finance team and executives actually use.
Human layer security is the set of controls, telemetry and processes that prevent people from being manipulated into harmful actions, and that detect the manipulation attempt while it is happening. It treats the workforce as an attack surface to be instrumented and defended, not only as an audience to be trained.
Every other security layer has both a control and a sensor. The network has segmentation and a firewall log. The endpoint has hardening and EDR telemetry. The identity layer has conditional access and sign-in logs. For most of the last two decades, the human layer had only half of that pairing: a control in the form of annual training, and almost no sensor at all. Security teams found out that an employee had been manipulated by reading the outbound wire confirmation.
Human layer security closes that gap. It keeps the education, adds enforceable process controls around the moments that matter, and instruments the channels where manipulation happens so the attempt produces a signal in real time. Netarx describes the operational practice of running this program as human defense, and the measurement sub-discipline inside it as human risk management.
In This Article
The OSI model formally stops at Layer 7, the application layer. Network engineers have used Layer 8 as shorthand for the user for decades, usually as a joke about the problem existing between the keyboard and the chair. The joke stopped being funny once attackers industrialized it. Layer 8 is now a useful architectural term because it forces the questions you would ask of any other layer: what crosses it, what controls govern it, what telemetry does it emit, and who owns it on the org chart.
The framing also exposes an uncomfortable asymmetry. An attacker who wants to cross Layer 3 has to defeat engineering. An attacker who wants to cross Layer 8 only has to be convincing for ninety seconds on a video call. The MITRE ATT&CK phishing technique family is the most commonly observed initial access path in the wild for exactly that reason.
These terms get used interchangeably in vendor marketing, which makes budget conversations harder than they need to be. Here is how they nest.
Term | What it actually means | Relationship |
|---|---|---|
Security awareness training | Scheduled education, phishing simulations, onboarding modules | One control inside the human layer |
Human risk management (HRM) | Scoring individual and team risk, then targeting interventions at the highest-risk population | The measurement sub-discipline |
Human firewall | Metaphor for employees who notice and report manipulation attempts | A desired outcome, not a control |
Human layer security (Layer 8) | The full stack of controls, telemetry and process that protects people from manipulation | The discipline itself |
Human defense | Running that discipline as an operational program with owners, SLAs and metrics | The practice of the discipline |
Three data points explain why the human layer became an architecture problem rather than a training problem.
1. The human element is still the majority path in
The Verizon 2026 DBIR put the human element in 62% of breaches. Credential abuse appeared in 39% of breaches overall. Third parties were involved in 48% of breaches, a sharp year-over-year rise, which means your Layer 8 now extends across vendors, contractors and managed service providers who never sat through your training.
2. The financial impact concentrated in social engineering
The FBI’s 2025 Internet Crime Report recorded $20.9 billion in reported losses across more than a million complaints. Business email compromise accounted for $3.04 billion of that, with 86% of BEC losses moving by wire or ACH, which is to say, effectively unrecoverable once the transfer clears. The report also introduced an AI-related crime category for the first time, with roughly $893 million in reported losses.
3. Synthetic media made live channels untrustworthy
The 2024 Arup case, in which a finance employee in Hong Kong transferred roughly $25 million after a video call with deepfaked colleagues, was the proof of concept. It is now routine tradecraft. Gartner research cited in our deepfake statistics roundup found that 62% of organizations faced at least one deepfake attack in a twelve-month window, and 37% of security leaders had encountered a deepfake on a live video call.
Meanwhile the cost of getting it wrong climbed. The IBM Cost of a Data Breach Report 2026 put the global average at $4.99 million and the US average at $11.5 million, with mean time to identify and contain rising to 247 days. Breaches involving AI-enabled attack techniques carried noticeably higher costs than the baseline.
The strategic conclusion is narrow and specific: identity proofing that relies on recognizing a face or a voice has failed as a control. Everything below follows from that.
Map your controls against these. If a path has no detective control and no process control, it is an open door.
Executive voice cloning. Three seconds of public audio is enough to produce a usable clone. The call arrives during a known travel window, references a real deal, and asks for urgency, not money, on the first contact.
Live video deepfakes in meetings. Synthetic participants in Zoom, Teams and Meet, often several at once, used to manufacture the social proof that overrides a junior employee’s doubt.
Business email compromise and vendor email compromise. Still the highest-dollar category. VEC is harder because the sending domain is legitimately the vendor’s. See our breakdown of impersonation attacks.
Help desk and account recovery manipulation. The attacker never targets the employee. They target the person who can reset the employee’s MFA. This path defeated several large enterprises with otherwise mature security programs, and is documented in the joint CISA advisory on Scattered Spider.
MFA fatigue and adversary-in-the-middle phishing. Real-time proxy kits harvest the session token, which means push-based and OTP-based MFA are bypassed rather than broken.
Candidate and insider fraud. Synthetic applicants passing video interviews to obtain legitimate credentials on day one. This is now a recruiting control problem as much as a security one, covered in our HR solutions overview.
Third-party and supply chain human risk. Contractors, MSPs and outsourced finance functions who hold your access but not your policies.
For a deeper treatment of the underlying techniques and their psychological levers, see our guide to social engineering attacks.
A program that spans only one or two of these domains fails predictably. Training without process controls produces alert employees who still get overruled by an urgent executive. Process controls without detection produce a callback policy nobody follows at 4:55pm on a Friday.
Domain A: Identity assurance
Phishing-resistant MFA as the default, not the exception. CISA’s implementation guidance and FIDO2 passkeys are the reference points here.
Documented identity proofing for help desk resets and account recovery, aligned to the assurance levels in NIST SP 800-63-4. We break down what the revision means for deepfake resilience in this analysis.
Tiered trust for who may request what. Not every verified identity should be able to move money, and our Tiers of Identity model formalizes that.
Removal of knowledge-based authentication. Anything an attacker can buy from a data broker is not a secret.
Domain B: Communication trust
This is the domain most programs are missing, and the reason Stage 4 below is the hard step. Communication trust means the live channel itself is analyzed, voice, video, email, chat and files, in the moment, with the result surfaced to the person making the decision.
Real-time deepfake and voice-clone detection on inbound calls and meetings.
In-workflow nudges rather than after-the-fact reports, so the warning arrives before the approval, not in next month’s dashboard.
Cross-channel correlation, because a single-channel detector misses the campaign that starts in email and finishes on the phone. We explain the failure mode in why deepfake detection fails without cross-channel awareness.
Coverage for file and document channels, including AI-altered invoices and identity documents.
Domain C: Authorization and process
Mandatory out-of-band callback to a number on record for any payment instruction change, bank detail change, or credential reset. The callback number must never come from the request itself.
Dual authorization above a defined threshold, with the second approver explicitly instructed that urgency is a reason to slow down.
A no-penalty stop rule: any employee may pause any transaction pending verification, and is never disciplined for a false positive.
Pre-agreed verification challenges for executives and finance staff, rotated quarterly.
Domain D: Behavior and culture
Role-targeted training driven by actual risk scores, not calendar compliance. Finance, HR, executive assistants, help desk and treasury carry most of the exposure.
Simulations that include voice and video, not only email. If your program has never simulated a cloned executive call, it has never tested the control that matters.
Psychological safety as a measurable property. Reporting rates fall in cultures that punish the reporter, and reporting rate is a leading indicator.
Post-incident handling that separates the person from the failure. Employees who were targeted by a well-built deepfake were not careless.
Domain E: Measurement and response
Human layer telemetry routed to the SOC as first-class alerts with defined runbooks.
Governance mapped to a recognized framework, typically NIST CSF 2.0 for the Govern and Protect functions and the NIST AI Risk Management Framework for AI-specific exposure.
A quarterly review that reports control coverage and detection outcomes, not training completion percentages.
Five stages. Read down the middle column and place yourself honestly, then read the "key gap" column for the next thing to build. Skipping a stage rarely works, but Stage 2 to Stage 4 can be compressed if the budget and executive sponsorship are already there.
Stage | What it looks like | Telemetry available | Key gap to close |
|---|---|---|---|
1. Ad hoc (Assumed trust) | No named owner for the human layer. Training happens at onboarding. Verification is whatever an individual decides to do that day. | None beyond email spam filtering | Assign an owner and write down a single verification rule |
2. Aware (Training-led) | Annual awareness training, quarterly email phishing simulations, a reporting button in the mail client. | Click rates and report rates on email only | Controls that hold when the attack is not email |
3. Managed (Risk-quantified) | Per-person and per-team risk scoring, targeted interventions for the high-risk population, phishing-resistant MFA rollout underway. | Risk scores, MFA coverage, repeat-clicker cohorts | Enforceable process controls on money and access |
4. Verified (Control-enforced) | Out-of-band callback is mandatory and audited. Dual authorization on payments. Help desk identity proofing documented and tested. Real-time detection deployed on voice, video, email and files. | Detection events per channel, callback compliance rate, help desk proofing audit results | Correlation across channels and automated response |
5. Adaptive (Federated trust) | Cross-channel correlation, automated containment, trust signals shared across the organization and its partners, third parties held to the same verification standard, controls tuned against observed attacker behavior. | Campaign-level attribution, third-party coverage, time-to-contain on human layer incidents | Continuous improvement rather than a gap |
The distribution matters more than the model. Most mid-market and enterprise organizations land at Stage 2 or Stage 3: credible training, increasingly credible identity controls, and no sensor at all on the live channels where the highest-dollar attacks now run. That is the Stage 4 boundary, and it is the highest-leverage investment available in 2026.
Answer yes or no. Four or more no answers means you are below Stage 4.
Can you name the person accountable for human layer security, and is it someone other than the person who runs training?
If a cloned voice of your CFO called your AP clerk right now, would any system produce a signal, or would the only control be that employee’s judgment?
Is out-of-band callback on payment changes mandatory, audited, and enforced against a number of record?
Has your help desk identity proofing process been red-teamed in the last twelve months?
Do your third parties and contractors operate under the same verification rules as your employees?
Days 1 to 30: establish the floor
Name an accountable owner and a cross-functional working group spanning security, finance, HR and legal.
Publish a one-page verification standard: what must be called back, to which number, by whom, with no exceptions for seniority.
Inventory the channels your high-risk roles actually use, including the ones not on the approved list.
Baseline three numbers: phishing-resistant MFA coverage, callback compliance on the last 90 days of payment changes, and median time from suspicion to report.
Days 31 to 60: close the identity and process gaps
Complete phishing-resistant MFA for finance, executives, IT administrators, HR and the help desk.
Rewrite help desk account recovery against NIST SP 800-63-4 assurance levels and test it with an unannounced social engineering attempt.
Turn on dual authorization above your threshold and instrument it so you can see when it is bypassed.
Run one voice or video simulation. Report the result as a control finding, not as a score for the individuals involved.
Days 61 to 90: add the sensor
Deploy real-time detection across voice, video, email, chat and file channels for the high-risk population first.
Route detections into the SOC with a written runbook, an owner and a response SLA.
Extend the verification standard into vendor contracts and onboarding for contractors.
Report to the board on control coverage and detection outcomes. Retire training completion as a headline metric.
Completion rates and click rates measure participation. These measure protection.
Metric | Why it matters | Healthy direction |
|---|---|---|
Callback compliance rate on payment and credential changes | Directly correlates to BEC loss prevention | Above 98%, audited monthly |
Phishing-resistant MFA coverage for high-risk roles | Removes the token-theft path entirely | 100% for finance, exec, IT, HR, help desk |
Median time from suspicion to report | Reporting speed, not click avoidance, determines containment | Under 10 minutes |
Detection coverage by channel | Shows where the sensor is still blind | Voice, video, email, chat and files all covered |
Help desk proofing failure rate under test | The most exploited path in recent enterprise intrusions | Zero unapproved resets per test cycle |
Third-party verification coverage | Layer 8 now extends past the payroll | Contractually required for all payment-touching vendors |
Human layer security is moving from best practice to expectation. NIST SP 800-63-4 raises the bar on identity proofing and presentation attack resistance. NIST CSF 2.0 elevated Govern to a top-level function, which puts named accountability for human risk in scope for audit. In the EU, Article 50 of the AI Act introduces transparency obligations around synthetic content. Sector rules follow the same direction: PCI DSS 4.0.1 expands security awareness requirements to include emerging threats, and financial regulators increasingly expect documented controls against authorized push payment fraud.
Netarx maps these requirements by industry and by role across financial services, banking, fraud prevention, risk and compliance teams.
Treating training as the program. Training is a control in Domain D. On its own it produces a workforce that recognizes attacks it cannot prove and has no authority to stop.
Exempting executives. The verification standard has to bind the people most likely to be impersonated, or impersonating them remains the cheapest path in.
Buying a single-channel detector. Attackers pivot between channels deliberately. A detector that sees only email will confirm that the email was clean while the call is doing the damage.
Measuring the person instead of the control. Publishing individual click rates suppresses reporting, which is the one behavior you most need.
Stopping at the employee boundary. With third parties involved in nearly half of breaches, a program scoped to badge holders is scoped to roughly half the risk.
Human layer security, or Layer 8 security, is the discipline of defending the people layer with the rigor already applied to the network and the endpoint: named ownership, enforceable controls, real telemetry and measured outcomes. The 2026 data makes the case. The human element sits in 62% of breaches, business email compromise alone accounted for $3.04 billion in reported US losses in 2025, and synthetic voice and video have removed recognition as a viable identity control.
The five control domains give you a checklist. The five-stage maturity model gives you a position and a next step. For most organizations that next step is Stage 4: adding a real-time sensor to live communication so that a manipulation attempt produces a signal at the moment of decision rather than a lesson after the wire clears.
To go deeper, read our complete guide to human defense in cybersecurity, the 2026 deepfake statistics roundup, or the TrustOps operating model. To see real-time detection running against your own channels, request a demo or browse the Netarx resource center.
SOURCES & REFERENCES
Verizon — "2026 Data Breach Investigations Report", 2026. The human element in 62% of breaches, credential abuse in 39%, and third-party involvement in 48% of breaches.
FBI — "Cryptocurrency and AI Scams Bilk Americans of Billions" (2025 Internet Crime Report), April 2026. $20.9 billion in reported 2025 losses, $3.04 billion from business email compromise, and the first AI-related crime category, with about $893 million in losses.
IBM — "Cost of a Data Breach Report 2026", July 2026. A global average breach cost of $4.99 million, a US average of $11.5 million, and 247 days mean time to identify and contain.
Gartner — "Gartner Survey Reveals Generative AI Attacks Are on the Rise", 22 September 2025. Survey of 302 cybersecurity leaders: 62% faced at least one deepfake attack in 12 months, and 37% saw a deepfake on a video call.

Chief Executive Officer
CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.
Human layer security is the practice of protecting people from manipulation that leads to harmful action, using identity controls, enforced verification process, real-time detection on communication channels, targeted training and continuous measurement. It is called Layer 8 security because it sits above the seven layers of the OSI model.