Whenever a user falls victim to a phishing or other social engineering attack, or makes an error, critics claim awareness efforts are useless. However, if a single user action can compromise an entire security program, the problem is the security program. This presentation will detail how technology, process and awareness should combine to stop human failings. Case studies will be presented.