October 10, 2026
Firewalls — Why People, Process, and Technology Must Work Together in Cybersecurity
INTRODUCTION

By Philip
8 min read
When most people hear the word Cybersecurity, they immediately think of firewalls, antivirus software, and complex encryption algorithms. Although technology is a critical component of cybersecurity, focusing on it alone is a recipe for failure.
In the cause of my journey at AltSchool Africa, I was exposed to the core reasons why these three pillars (People, Process and Technology) must work together to keep an organization more secured.
In this article, I will lead you to the full knowledge, understanding and discover of the following:
· The definition of each pillar.
· Why the three pillars must work together.
· Explore real-world examples.
· Proffer practical steps to help you assess and strengthen all three in your organization.
The three pillars of cybersecurity are people, technology, and process. They work together to create a robust defense strategy.
- People: These are the human element that focuses mainly on the security awareness training, hiring of competent and skilled personnel as well as fostering a culture of cybersecurity so as to mitigate human error.
- Technology: This centers on the software and hardware tools used to prevent and detect cyber-attack, such as the Endpoint Detection and Response , and Endpoint Detection and Prevention (EDR & EDP) tools, firewalls,
- Process: This deals with the policies and guidelines that defines how organizations governs data, responds to security risk and manage risk.
Why the three pillars are needed in every organization.
- It help to reduce human error and insider threats because it is believed that a well-trained people make fewer mistakes.
- This maximizes ROI on security tools because technology only works best when guided by sound processes and skilled users.
- It equally creates consistent, repeatable and secure workflows as processes ensures reliability over time.
- This also ensures that compliance and regulatory requirements are met. Frameworks such as ISO 27001 and NIST required to be balance across the three pillars.
The People Pillar
People remains the greatest asset and your greatest risk within these pillars. No matter how advanced the technology you deployed are, an employee that clicks a malicious link or a contractor that mishandles data can bypass every technical controls.
The important elements under People centered pillar includes:
- Professional training of your personnel on Security awareness: This is to equip employees with the knowledge and skills ti identify, avoid, and responds to cybersecurity threats like phishing, malware and social engineering.
Core Objectives/Benefits includes:
· Risk reduction: Educate users on secure practices, such as using strong passwords and recognizing suspicious links, which lower the risk of success rate of attacks.
· Regulatory compliance: This helps organizations meet legal requirements for data protection, including GDPR, HIPAA, and PCI_DSS.
· Cultural Shift: Foster a security first mind set where employees understand their role in protecting organizational assets and feel empowered to report incidents.
-
Phishing simulations — This is designed to test employees safely to build resilience. This mimic real-world attacks to identify vulnerability in human behavior, and ensures that staff are trained to recognize and report social engineering tricks before they are being exploited. This reinforces the human layer of protection and ensures that employees do not become the weakest link in an organization's security posture
-
Security culture: This is seen as the human-centric element that binds the three pillars of people, processes and technology together, to ensure that they function as a cohesive defense instead of isolated components. This is rooted on the believe that leadership must model good behavior.
The key aspects includes:
· Shared ownership — This creates a mindset where staff actively report suspicious activities and takes personal responsibility for security, reducing risk of human error which is often the weakest link
· Behavioral Alignment: This makes sure that employees consistently adhere to defined processes (such as access controls and incident response), and judiciously utilize technology tools (such as multi-factor authentication and encryption).
· Resilience: A strong security culture enables organizations to remain vigilant against evolving threats, ensuring that even when technology fails or processes are bypassed, the workforce remains the first line of defense
- Defined roles and responsibilities — This addresses the question of who does what during an incident. The three pillars of cybersecurity are People, Processes and Technology, each with distinct roles and responsibilities in safeguarding digital assets.
· People maintains security-aware culture and acts as the first line of defense. Thus employees must undergo frequent cybersecurity training to recognize threats like phishing and social engineering.
· Processes define the policies, procedures and governance frameworks that guide security operations. Responsibilities should include establishing security policies ( such as password and incidence response protocols), conducting regular risk assessments and audits and ensuring compliance with regulations like GDPR or HIPAA.
· Technology: This involves the tools and systems used to prevent, detect, and respond to cyber threats. IT professionals are responsible for deploying and managing firewalls, encryption, Endpoint Detection and Response (EDR), and Multi-Factor Authentication (MFA)..
Take for instance, the 2020 Twitter hack, which stands as one of the most significant social media security breaches in history. A Twitter employee was socially engineered into revealing the login credentials, allowing the attacker to gain access to twitter administrative tools.
This incident highlights that even organizations with advanced security system can be vulnerable when human factors are exploited. It also raised serious concern about insider factors, employee's security awareness, and also the need for stronger authentication and access controls. The hack equally shows that cybersecurity does not only depends on technology, but also on effective processes and well-trained personnel.
The Technology Pillar
This moves beyond basic perimeter defense to include layered technologies that address identities, endpoints, networks, and cloud environment. Technology provides the tools to detect, prevent, and respond to threats. However, technology without skilled people and well-designed processes often becomes expensive
Key components include:
- Firewalls — First line of defense for network traffic.
- EDR (Endpoint Detection and Response) — Monitors and protects endpoints.
- IAM (Identity and Access Management) — Controls who has access to what.
- Encryption — Protects data at rest and in transit.
- Monitoring (SIEM/SOAR) — Centralized logging and automated responses.
- Penetration Testing — Proactively finds weaknesses.
- Software Updates & Patching — Closes known vulnerabilities.
- Software Testing (SAST/DAST) — Identifies flaws before deployment.
A very good example is the "Equifax Breach" in 2017, which stands as one of the largest data breach in history. Cyber criminals exploited an unpatched vulnerability in the company's application and gained access to sensitive data, which lead to the exposure of about 147 million personal information.
This breach reveals major weaknesses in Equifax's cybersecurity practices, particularly on its failure to apply critical security updates promptly. It equally shows the importance of timely patch management, continuous system monitoring and effective incident response in protecting sensitive information.
The Process Pillar
This acts as the structural glue that binds people and technology together. It tries to define the specific rules, policies and actions an organization should follow to mitigate risk, responds to threats, as well as ensure consistent compliance with industry standards.
Key components of the Process pillar include:
· Policies and Procedures: This talks about the written guidelines for acceptable use, data classification and password management.
· Incident Response (IR) Plans: A clear step-wise instructions for detecting, containing, and recovering from cyber-attacks. This ensure a calm and organized response as against panic during a breach.
· Governance and Compliance: This emphasizes on the strategy that aligns cybersecurity with the overall business objectives and regulatory frameworks (for example, NIST, ISO 27001, HIPAA, COBIT, GDPR)
· Third-Party/Vendor Management: This provides a guideline for assessing and managing the security risks introduces by external partners, contractors, and supply chain vendors.
· Audit and Continuous Improvements: Emphasizes on regular reviews and testing of the security program such as penetration testing and risk assessments to determine the effectiveness and identify areas for improvement.
To audit your organizational cybersecurity maturity across the three pillars, you must access how effectively your people, processes and technology interacts to manage and mitigate risks.
Here is the structured approaches to conduct this audit:
- Evaluate the People by carrying out the following study;
· Training Effectiveness: This is done by reviewing phishing simulation click rate and completion metrics for security awareness training.
· Role-Based Security: This tries to verify that high-risk roles (for example, finance, HR, IT) receive specialized security training.
· Access Control Culture: Audit on whether employees practice strong passwords hygiene and proper handling of sensitive data.
- Evaluate the Process: In doing this, you carry out an assessment of policies, governance and compliance by looking into the following:
· Policy Documentation: Verify to ensure that core policies (Incident response, Acceptable Use, data Governance) are documented, updated annually and officially approved.
· Incident Response preparedness: Take a review of the records of recent tabletop exercises to ensure the security team knows how to react during a breach.
· Vendor Risk management: Ensure that third-party vendors are vetted for security compliance before accessing internal networks
- Evaluate the "Technology" Pillar — this tries to assess defense mechanisms and technical controls through the following means:
· Asset Management: Looks into the hardware, software and cloud assets to ensure that a complete inventory exists.
· Vulnerability and Patching: You must check the frequency of vulnerability scans and the average time it takes to patch critical flaws.
· Identity Defense: You must make sure that Multi-Factor Authentication (MFA) is enforced globally across all corporates accounts and applications.
- Choose a maturity Framework — by mapping your audit findings to a scale to measure progress by doing the following:
· CMMC (Cybersecurity Maturity Model Certification): This uses a 3-level model (Foundational, Advanced, and Expert) to measure process institutionalization.
· NIST Implementation Tier: Rates maturity from Tier 1 (partial/Reactive) to Tier 4 (Adaptive/Proactive).
Conclusion
Cybersecurity isn't just about firewalls and encryption. It is a delicate dance between people, technology, and process. Drawing from my learning journey at AltSchool Africa, I have come to realize that even the most advanced security tools crumble when employees are not properly trained or when clear policies do not exist. The 2020 Twitter hack and the Equifax breach painfully remind us that attackers frequently exploit human errors and outdated systems, not just software flaws.
True resilience comes from balancing all three pillars: skilled personnel who spot threats, robust tools that detect and block attacks, and a well-documented processes that guide every response. When these elements are aligned, organizations reduce human error, maximized their security investments, and stay compliant with frameworks like NIST and ISO 27001.
Take ten minutes this week to audit your own organization. Which pillar is your weakest link? Start with one small improvement today. Your security depends on it.
Credits:
- AltSchool Africa — Most of what I have shared in this article was shaped by my journey in the AltSchool Africa Cybersecurity Program. The curriculum introduced me to NIST, ISO 27001, firewalls, intrusion detection, encryption, and most importantly how these pieces are interwoven in the real world.
· CIO.com (2024) — Differentiating people, process, and technology problems.
- COBIT — A framework for developing, implementing, monitoring, and improving IT governance and management practices.
- Equifex Breach (2017) — Ars Technica and SecureWord.
· Euro One (2025) — Why the People, Process, Technology framework should be applied in a modern IT security strategy.
- ISO/IEC 27001:2022 — Information Security Management.
- NIST Cybersecurity Framework (CSF 2.0).
- Paz, S. (2023). Cybersecurity Standards and Frameworks.
- SANS Institute — Security Awareness and Culture Resources.
- Sherweb (2025) — The 4 pillars of a strong cybersecurity program.
- Twitter Hack (2020) — TechCrunch and AP News.
Special Thanks
I would like to thank and Adewale Mustapha] for providing insightful guidance and practical cybersecurity knowledge as I progress in my learning journey at AltSchool Africa. Their teaching materials and real-world examples have greatly enriched my understanding of cybersecurity principles and best practices
About the Author
Phill is a lecturer, researcher, technical writer, and cybersecurity analyst currently advancing his cybersecurity expertise through a Diploma Program at AltSchool Africa. He is passionate about cyber awareness, digital resilience, and emerging security technologies.
Connect with me on LinkedIn: [www.linkedin.com/in/philip-uche]
#Cybersecurity #CyberAwareness #InformationSecurity #CyberHygiene #ZeroTrust #CloudSecurity #ArtificialIntelligence #DigitalSafety #TechEducation #AltSchoolAfrica