CyBehave applies behavioural science to digital security - through ongoing research, the SHIELD framework, and a growing family of platforms that turn the evidence base into everyday practice. See how security really spreads through your organisation, and manage culture change rather than hope for it.
Vision: A world where security is intuitive, inclusive, and woven into everyday behaviours.
Mission: We turn the people already shaping security behaviour into a measurable, connected network. Through behavioural science and network analysis, we give organisations a real picture of how security spreads – who influences whom, where resilience is building, and where it isn't – so culture change can be managed rather than hoped for.
About CyBehave →Every framework and feature is grounded in peer-reviewed behavioural science - psychology, behavioural economics, and organisational science applied to cybersecurity.
CyBehave measures and informs - it does not surveil. This distinction is central to how we design every product.
We address both human behavioural risks and the emerging risks from agentic AI systems within a unified framework.
Every CyBehave platform applies the same evidence base to a different part of the problem. Heroes is the one you can use today: the people who spread security through your organisation, and the evidence that it is working.
Your Security Champions programme, built on behavioural science - without you or your Champions needing to be behavioural scientists. Heroes guides the whole journey: identify your natural influencers, develop them through structured journeys and a five-stage programme, and measure the behaviour, culture and resilience change they drive - with board-ready evidence, not anecdote.
Athena and Themis extend the same model into coaching and governance, both in active development. See what we are building →
CyBehave runs an ongoing research programme in behavioural cybersecurity - and publishes the frameworks, models and methods openly, so you can see exactly what our platforms measure, how, and why.
The peer-reviewed research behind CyBehave - psychology, behavioural economics and organisational science applied to cybersecurity.
How COM-B and the Behaviour Change Wheel underpin the way we understand, measure and change security behaviour.
Whether human behavioural science frameworks can be extended to understand, predict and govern AI agent behaviour in security.
The Behavioural Cyber Risk Skills Framework - 30 competencies across 7 domains for building human cyber capability.
Findings from the CyBehave research programme - data, evidence and what it means for practice.
I don't mean a game in the trivial sense. I mean it in the formal sense that mathematicians and economists have used for...
Read insight →There are at least 83 published theories of behaviour change. Michie and colleagues catalogued them in 2014, and between...
Read insight →For more than a decade, the nudge has been the dominant idea in applied behavioural science. Change the way a choice is ...
Read insight →Practical guidance - how to apply behavioural science to your security programme day to day.
Your agents will never see a poster or absorb culture in a corridor. But they will read a file, take it literally, and act on it thousands of times a day. So write your values down properly. This piece covers building a normative repository: versioned, signed, tested through CI/CD, pulled hourly. And a detection bonus: an agent that quietly stops renewing its norms may be telling you it's compromised.
Read article →Everyone's answer to the frontier AI threat is fight fire with fire. But the attacking agent has no guardrails, no legal review and nobody to answer to. Ours has all three. This week showed what that gap looks like: a company under attack by an AI with the brakes off, unable to get help from an AI with the brakes on. The answer is not removing our constraints. It is making them legible to the machine and survivable for the person.
Read article →Security is what the literature calls a secondary task: something you must do on the way to your real goal. A salesperson opens their laptop to close a deal. A nurse logs in to treat a patient. A finance analyst signs in to reconcile month-end. Nobody, anywhere, logs in to do security. And yet we build entire programmes on the assumption that they should.
Read article →Start your free trial. No credit card required. Up and running in minutes.