Introducing The Human Error: Why Cybersecurity Failures Are Never Just a Technology Problem
- 14 hours ago
- 3 min read
TBDCyber co-founder Graeme Payne's new book is available

Every major breach of the last decade followed the same sequence. A risk was acknowledged. A control was inadequately implemented. The gap was deprioritized. An attacker found it.
SolarWinds. Colonial Pipeline. MGM. The technology changes. The human and organizational conditions that turn threats into catastrophes do not.
That pattern is the subject of The Human Error: Why Cybersecurity Failures Are Never Just a Technology Problem, the new book from TBDCyber co-founder Graeme Payne, available now on Amazon in paperback and Kindle.
The book
Your organization almost certainly has a gap between the cybersecurity program on paper and the one that would withstand an attacker's scrutiny. You may not know where it is. The briefings you receive may be technically accurate yet strategically misleading, confirming compliance with a framework without discussing what it doesn't cover, and reporting vulnerabilities that have been remediated without context on which remain open. From the inside, your controls look like protection. From an attacker's perspective, they look like an opportunity.
This is not a technology problem. It is a governance problem.
The Human Error makes that argument from the inside. Graeme was a Senior Vice President at Equifax when the largest data breach in American history unfolded around him in 2017. He spent six weeks in the crisis war room. He testified before Congress, the SEC, and the New York Attorney General. Then he was publicly named as the human error; the single individual whose failure caused everything.
The House Committee on Oversight and Government Reform later concluded that his termination was "a public relations-motivated maneuver" that was "gratuitous against the backdrop of all the facts."
What the committee understood, and what this book makes precise, is that the human error is never just one person. It is an organization, a governance structure, a culture, accumulated over years, finally visible.
From there, the book traces the same pattern forward through SolarWinds, Colonial Pipeline, MGM Resorts, and other major breaches, showing that Equifax was not an isolated failure. It was the first clear look at a pattern that has repeated, under different names, ever since.
Who it's for
Board members and directors responsible for cybersecurity oversight
C-suite executives who receive security briefings but want to know if they're getting the full picture
Senior leaders who have sensed that their organization's actual exposure may be greater than what they've been told
Anyone who wants to understand how the largest data breach in American history actually happened, and why it keeps happening, under different names, to this day
A few lines from the book
"Organizations do not fail because they ignore security. They fail because they mistake the appearance of security for the substance of it."
"Different gaps. Same sequence. Acknowledge, implement inadequately, deprioritize, breach."
"The attack vector changes. The failure mode does not."
Bring it to your board
Alongside the book, we've published a companion resource: the Board and Executive Cybersecurity Governance Checklist, adapted from Appendix B, built for direct use in your next board or executive meeting. Download it here.
If the book or the checklist raises questions about your own organization's governance, that's exactly the conversation TBDCyber exists to have. Get in touch.
About the author
Graeme Payne is co-founder of TBDCyber, a cybersecurity advisory and consulting firm, and the author of The New Era in Cyber Security Breaches (2019). He advises boards and executive teams across multiple sectors on cybersecurity governance and organizational resilience. He co-hosts the Cyber Smokehouse podcast with TBDCyber co-founder Ernie Anderson.
The Human Error is available now on Amazon, in paperback and Kindle.
Read more about the book and download the companion governance checklist on The Human Error page.



Comments