Building Champions. Building Behaviours. Building Resilience.

Security is a behaviour. We apply behavioural science to how people behave around security, to the Security Champions who spread good behaviour and the Champions Networks that make them a capability. That is Secure Behaviour Management, delivered through people.

Where behavioural science meets digital security

Vision: A world where security is intuitive, inclusive, and woven into everyday behaviours.

Mission: We turn the people already shaping security behaviour into a measurable, connected network. Through behavioural science and network analysis, we give organisations a real picture of how security spreads – who influences whom, where resilience is building, and where it isn't – so culture change can be managed rather than hoped for.

About CyBehave →

Evidence-based research

Every framework and feature is grounded in peer-reviewed behavioural science - psychology, behavioural economics, and organisational science applied to cybersecurity.

Privacy-first measurement

CyBehave measures and informs - it does not surveil. This distinction is central to how we design every product.

Secure behaviour, human and AI

Secure Behaviour Management for people and for agentic AI systems, addressed within a unified framework.

Founded on the science. Built for practitioners.

CyBehave is founded on behavioural science, and we know that not everyone in cybersecurity is a behavioural scientist or a cyberpsychologist. So we make it our job to bring the science to you in a consumable, practical form: designed for practitioners and scientists alike, and published openly so you can see exactly what our platforms measure, how, and why.

Latest from CyBehave

The newest insights, articles and Signals brief - research, practice and the week's briefing in one place.

Insight 4 Oct 2026 7 min read

Nobody Told the Agents How We Do Things Here

A new joiner learns how an organisation behaves long before they read a policy. They watch who gets challenged at the door. They hear what t...

Read insight →
Insight 3 Oct 2026 4 min read

Nudge and boost were built for a world without an opponent. Security has one.

Picture a finance officer on a Thursday afternoon. An email arrives from a supplier she has dealt with for years, asking her to update their...

Read insight →
Insight 16 Sep 2026 8 min read

Behaviour Change in Complex Systems

Most organisations treat security behaviour as a plumbing problem. There is a pipe. Training goes in one end; compliant behaviour comes out ...

Read insight →
Article 9 Oct 2026 14 min

Volunteer, voluntold or chosen: how to recruit champions who change behaviour

Volunteers bring motivation without reach. Appointment brings reach without motivation. Neither starts from what a champion is for: their position in the working relationships of their team. There is a third approach. Map the network, find the central people and the bridges, and ask them personally why they were chosen. Being asked for a reason, and given a real choice, produces champions who are influential, who chose the role, and who stay.

Read article →
Article 2 Oct 2026 13 min

Where to start: the first ninety days of a champions programme

The hardest part of a champions programme is the first three months, when the idea is agreed and nothing exists yet. The early choices set the shape of everything that follows. Write down what champions are for before you recruit any, secure a sponsor who will still be there in two years, map where the behaviour gap sits, choose a first cohort for influence rather than availability, and measure from day one. Get the shape right and it scales.

Read article →
Article 25 Sep 2026 13 min

Making the business case for security champions

Most champions programmes never get properly funded. They start as a side project, survive on goodwill, and fade when the sponsor moves on. The reason is nearly always the same: nobody wrote the business case. This is how to build one a finance director will accept, from problem and mechanism through a benefits register, conservative attribution, honest costing of champion time, leading indicators, and the risks the board will raise.

Read article →
Signals 5 Oct 2026 8 min

SIGNAL: Week 41 - Creatures of Habit

Attackers are creatures of habit, and this week the research proves it. Analysis of 2.9 million phishing emails finds endless stories but one dominant ask. New telemetry shows 98 per cent of data loss risk sitting with 10 per cent of users, a different 10 per cent each year. Plus ENISA's view from Europe, Japan's scam confidence trap, and why this year's Awareness Month slogan is that rare thing: a campaign line that is actually true.

Read briefing →
Signals 28 Sep 2026 8 min

SIGNAL: Week 40 - Hang Up, Call Back

Fake police on the phone, faked voices on work calls, and a payroll app that never existed. This week we look at the industrialisation of institutional impersonation, and the one habit that beats it: hang up, call back. Plus Apple builds scam detection into iOS 27, and a study of Switzerland and Cameroon asks whether your universal security training really travels. Five verified sources, an eight minute read.

Read briefing →
Signals 21 Sep 2026 9 min

SIGNAL: Week 39 - Charm Offensive

Charm is now a delivery mechanism. This week: fake recruiters running whole job interviews, fraudulent hires holding real credentials, an Aalto University study on how a phish actually feels, polite AI bots that slip past 6 in 10 of us, spyware that begins as a friendship, and a $23.80 fake ChatGPT bill. Five verified stories on attacks that win by being warm, and what a human risk leader should do with each.

Read briefing →

Ready to build champions,
behaviours and resilience?

Start your free trial. No credit card required. Up and running in minutes.