top of page

The Human Error | Cybersecurity Governance Book by Graeme Payne|

The Human Error

Your organization almost certainly has a gap between the cybersecurity program on paper and the one that would withstand an attacker's scrutiny.

You may not know where it is. The briefings you receive may be technically accurate yet strategically misleading — confirming compliance with a framework without discussing what it doesn't cover, reporting vulnerabilities that have been remediated without context on which remain open. From the inside, your controls look like a form of protection. From an attacker's perspective, they look like an opportunity.

​

This is not a technology problem. It is a governance problem.

eBook Cover (1).jpg
images (1).png

"Organizations do not fail because they ignore security. They fail because they mistake the appearance of security for the substance of it."

Every major breach of the last decade followed the same sequence.

A risk was acknowledged. A control was inadequately implemented. The gap was deprioritized. An attacker found it.

 

SolarWinds. Colonial Pipeline. MGM. The technology changes. The human and organizational conditions that turn threats into catastrophes do not.

 

The Human Error makes that argument from the inside. Graeme Payne was a Senior Vice President at Equifax when the largest data breach in American history unfolded around him in 2017. He spent six weeks in the crisis war room. He testified before Congress, the SEC, and the New York Attorney General. Then he was publicly named as the human error. The single individual whose failure caused everything.

 

The House Committee on Oversight and Government Reform later concluded that his termination was "a public relations-motivated maneuver" that was "gratuitous against the backdrop of all the facts."

 

What the committee understood, and what this book makes precise, is that the human error is never just one person. It is an organization, a governance structure, a culture, accumulated over years, finally visible.

"Different gaps. Same sequence. Acknowledge, implement inadequately, deprioritize, breach."

Who This Book is For

  • Board members and directors responsible for cybersecurity oversight
     

  • C-suite executives who receive security briefings but want to know if they're getting the full picture
     

  • Senior leaders who have sensed that their organization's actual exposure may be greater than what they've been told
     

  • Anyone who wants to understand how the largest data breach in American history actually happened and why it keeps happening, under different names, to this day

"The attack vector changes. The failure mode does not."

About the Author

Graeme Payne

Graeme Payne is co-founder of TBDCyber, a cybersecurity advisory and consulting firm, and the author of The New Era in Cyber Security Breaches (2019). He advises boards and executive teams across multiple sectors on cybersecurity governance and organizational resilience.

​

In 2017, as Senior Vice President and CIO of Global Corporate Platforms at Equifax, Graeme spent six weeks in the crisis war room as the largest data breach in American history unfolded. He testified before Congress, the SEC, and the New York Attorney General, and was then publicly named as the human error behind it. The House Committee on Oversight and Government Reform later found his termination to be a public relations-motivated decision, not one grounded in the facts of his role.

 

Read more about Graeme →

​

499aa7b6e10599f55c85018354cfa0bf.webp

Hear more from Graeme 

 

Graeme co-hosts Cyber Smokehouse with TBDCyber co-founder Ernie Anderson. Real conversations with the leaders shaping cybersecurity- no fluff, no filters.

​

Listen to Cyber Smokehouse →

​

"The gap between what a policy says and what an organization does is not primarily a compliance problem. It is a governance problem."

Bring the Book's questions to your next Board Meeting

Appendix B of The Human Error is a working checklist: the questions every board and executive team should be able to answer about their organization's cybersecurity governance.

 

We've adapted it into a standalone resource for boards, audit committees, and executive teams to use directly.

 

Complete the form to download the Board and Executive Cybersecurity Governance Checklist

​​​

Board checklist image.jpg

This book is the starting point. Here's where the work continues...

Management & Board Reporting

​

Give your board the visibility to ask the right questions and the confidence to know the answers hold up. â€‹

 

Learn more →

Cyber Risk Assessments

​

Know where your actual exposure is, not where your policy says it should be. 

​​

​

Learn more →

Virtual CISO Services

​

Executive-level cybersecurity leadership without the wait for a full-time hire.​

​​

​

Learn more →

AI Governance

​

The same governance gaps that caused Equifax are showing up again, faster, in how organizations adopt AI.

​

Learn more →

Bring this thinking to your Board

If The Human Error raised questions about your own organization's governance, TBDCyber can help you answer them.  Contact us  to learn more.

bottom of page