19.08.2025
Blog
Cyber Security

Human Firewall: The Human Factor as the Key to Resilience

In an increasingly volatile and digitalised world, resilience is no longer an option but a necessity – particularly in the public sector. Establishing a functional business continuity management (BCM) system is essential to maintaining the ability to act in crisis situations. However, technical and organisational measures alone are not enough: even the best strategy will be ineffective if the human factor is not taken into account.

Robert Stricker
Vice President, Security Consulting

That is why the ‘H’ in Materna’s RHINO principle stands for ‘Human Firewall’ – a deliberate focus on awareness, training and a culture of learning from mistakes within organisations.

Why the ‘Human Firewall’ is so important

Technical systems can be secured, networks segmented and data stored with multiple redundancies – yet any organisation is only as resilient as the people who work there. In the event of a crisis, it is not only the contingency plan but also the behaviour of staff that determines whether the organisation succeeds or grinds to a halt.

Resilience therefore begins in the mind – and in the heart. Employees who know how to respond to disruptions, who take responsibility whilst not having to fear making mistakes, form the backbone of a resilient organisation.

Establishing a culture of error – raising awareness

A key component of the ‘H’ is the establishment of a modern culture of error. Not only errors, but also ‘failures’ – that is, external disruptions – must be accepted as part of reality. The crucial difference lies in the mindset: moving away from the blame game and the search for a scapegoat, towards a solution-oriented approach.

How can this be achieved?

  • Open communication about risks and disruptions
  • Training and simulations that prepare staff for realistic scenarios
  • Knowledge sharing to alleviate fears and boost confidence in taking action

This is not about demanding perfection – but about enabling staff to act in a controlled and targeted manner in the event of a crisis, rather than falling into ‘headless chicken mode’.

‘Headless chicken mode’ – and how to avoid it

The so-called ‘headless chicken mode’ describes a behaviour frequently observed in crisis situations: frantic, haphazard, overwhelmed. In such moments, communication structures break down, priorities become blurred, and decisions are made spontaneously and in an uncoordinated manner. This behaviour is only human – but it is potentially dangerous for organisations in crisis.

The most effective countermeasure is targeted preparation through clear responsibilities and guidelines for action that have not only been communicated but also tested and practised. Awareness-raising measures help to either significantly shorten this state or avoid it altogether. Those who have already been trained in how to act in an emergency react with greater composure, clarity and focus.

Turning those affected into active participants

An often underestimated factor in building greater resilience lies in the active involvement of staff. Those who are informed about BCM measures at an early stage and in a transparent manner, and who play an active part in them, understand their purpose – and support them with conviction when an emergency arises.

The saying ‘Good intentions do not always translate into good results – especially in an emergency’ sums it up perfectly. It is therefore essential to define clear responsibilities, practise communication channels regularly and view employees not merely as recipients, but as active contributors to BCM.

Challenges and opportunities

Introducing a ‘human firewall’ is not a sure-fire success. Varying levels of acceptance, individual resilience and fear of change are real hurdles. But it is worth the effort. The following positive effects can be achieved by introducing a ‘human firewall’:

  • Employees as the first line of defence – who know what to do
  • Greater acceptance of BCM measures
  • Greater confidence in taking action in the event of a crisis
  • Stronger trust in one’s own organisation

Resilience is human

The ‘H’ in the RHINO principle stands for more than just training and awareness. It stands for a new way of thinking when dealing with crises, errors and failures. It stands for a culture in which people are prepared – and feel secure, even when things get serious.

After all, ultimately it is not the systems that carry an organisation through a crisis – it is the people who operate those systems.

Practical tip:

Talk to your staff not just about IT security, but about uncertainties too. Let them make mistakes – within the controlled environment of exercises. This is the only way to build resilience that isn’t just on paper, but that holds up when it really matters.

 

Further articles in this series:

Part 1: Resilience and business continuity in the public sector – crisis-proof and future-proof – Materna Blog

Part 2: Regulation as a strategic lever for resilience – Materna Blog

Robert Stricker
Vice President, Security Consulting

Robert Stricker is Vice President of Security Consulting at Materna.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more