An interesting article published by security guru Bruce Schneier:
=> Blaming the user is easy – but it's better to bypass them altogether
Blaming the victim is common in IT: users are to blame because they don't patch their systems, choose lousy passwords, fall for phishing attacks, and so on. But, while users are, and will continue to be, a major source of security problems, focusing on them is an unhelpful way to think.
=> Blaming the user is easy – but it's better to bypass them altogether