HEROES.by CyBehave

Empower your champions. Strengthen your culture. Build lasting resilience.

Heroes is the security champions platform that connects people, drives behaviour change and grows a positive security culture - by choice.

  • Discover and activate your champions
  • Equip and engage with what matters
  • Measure influence and drive impact
  • Build culture that lasts
HEROES.
Security Champions Platform

Manage, engage and scale your security champions network in one powerful platform.

Champion
Management
Engagement
& Campaigns
Insights
& Impact
Learning
& Resources
One platform. Stronger champions. Safer cultures.

Your champions.
Stronger together.

Identify, support and grow your champions community, and amplify their impact across the organisation.

Engage with
purpose.

Deliver the right messages, at the right time, with tools and campaigns that drive meaningful action.

Measure what
matters.

Track engagement, influence and behaviour change to prove impact and guide smarter decisions.

Built on behavioural science Designed for real-world impact Because culture is your strongest defence.

Where behavioural science meets digital security

Vision: A world where security is intuitive, inclusive, and woven into everyday behaviours.

Mission: We turn the people already shaping security behaviour into a measurable, connected network. Through behavioural science and network analysis, we give organisations a real picture of how security spreads – who influences whom, where resilience is building, and where it isn't – so culture change can be managed rather than hoped for.

About CyBehave →

Evidence-based research

Every framework and feature is grounded in peer-reviewed behavioural science - psychology, behavioural economics, and organisational science applied to cybersecurity.

Privacy-first measurement

CyBehave measures and informs - it does not surveil. This distinction is central to how we design every product.

Human and AI behavioural risk

We address both human behavioural risks and the emerging risks from agentic AI systems within a unified framework.

Behavioural science, made practical.

Every CyBehave platform applies the same evidence base to a different part of the problem. Heroes is the one you can use today: the people who spread security through your organisation, and the evidence that it is working.

CyBehave | Heroes

Early testing

Your Security Champions programme, built on behavioural science - without you or your Champions needing to be behavioural scientists. Heroes guides the whole journey: identify your natural influencers, develop them through structured journeys and a five-stage programme, and measure the behaviour, culture and resilience change they drive - with board-ready evidence, not anecdote.

  • COM-B pulse surveys, the Security Culture Index and strategic KPIs
  • Social network analysis showing influence, coverage and gaps
  • Guided interventions, Champion journeys and a built-in Training Academy
  • Nudge, the AI behavioural guide, on hand for every Champion
Explore Heroes →

Athena and Themis extend the same model into coaching and governance, both in active development. See what we are building →

Research is how we build.

CyBehave runs an ongoing research programme in behavioural cybersecurity - and publishes the frameworks, models and methods openly, so you can see exactly what our platforms measure, how, and why.

Behaviour

Understand how and why your people act the way they do. Measure real behavioural patterns, not just policy compliance.

Culture

Build a security culture that persists beyond training. Identify cultural levers and design interventions that stick.

Resilience

Prepare your people for the threats they will actually face. Resilience is a measurable, trainable capability.

Latest from CyBehave

The newest insights, articles and Signals brief - research, practice and the week's briefing in one place.

Insight 2 Aug 2026 7 min read

We made our website readable by machines

Somebody asked an AI assistant about security champions programmes last month. It gave them an answer. Our name may or may not have been in ...

Read insight →
Insight 23 Jul 2026 7 min read

Security behaviour is a game

I don't mean a game in the trivial sense. I mean it in the formal sense that mathematicians and economists have used for eighty years: a sit...

Read insight →
Insight 20 Jul 2026 8 min read

Eighty-three theories and still nobody locks their screen

There are at least 83 published theories of behaviour change. Michie and colleagues catalogued them in 2014, and between them those theories...

Read insight →
Insight 30 Jun 2026 7 min read

Is this the end of the nudge?

For more than a decade, the nudge has been the dominant idea in applied behavioural science. Change the way a choice is presented, without r...

Read insight →
Insight 4 Jun 2026 15 min read

What You Inherit When You Acquire: The Security Culture Nobody Diagnosed

Security due diligence examines what an organisation has. Security culture integration examines what it does. Most M&A security programm...

Read insight →
Insight 1 May 2026 14 min read

Human Behaviour Under AI-Enabled Adversarial Pressure

The Discipline That Assumed a Static Threat Behavioural cybersecurity emerged as a field from a recognition that technical controls, howeve...

Read insight →
Insight 16 Feb 2026 8 min read

Behavioural Convergence Theory

Executive Summary As artificial intelligence agents increasingly participate in organisational cyber risk landscapes, a critical question e...

Read insight →
Article 1 Aug 2026 15 min

John in Sales built an app this afternoon

Polish used to be an honest signal that somebody had thought carefully about how a thing was built. It is now free. John in Sales can produce something that looks like enterprise software in an afternoon, and nobody will think to ask, because it looks finished. He will tell you it is only for him. Usually that is true. It changes nothing. The audience was never the risk.

Read article →
Article 28 Jul 2026 18 min

Give Your Agents Something to Read: Building a Normative Repository for Agentic AI

Your agents will never see a poster or absorb culture in a corridor. But they will read a file, take it literally, and act on it thousands of times a day. So write your values down properly. This piece covers building a normative repository: versioned, signed, tested through CI/CD, pulled hourly. And a detection bonus: an agent that quietly stops renewing its norms may be telling you it's compromised.

Read article →
Article 24 Jul 2026 8 min

Fighting fire with fire, when only one side is allowed to burn

Everyone's answer to the frontier AI threat is fight fire with fire. But the attacking agent has no guardrails, no legal review and nobody to answer to. Ours has all three. This week showed what that gap looks like: a company under attack by an AI with the brakes off, unable to get help from an AI with the brakes on. The answer is not removing our constraints. It is making them legible to the machine and survivable for the person.

Read article →
Article 17 Jul 2026 9 min

Security Is Not THE Priority

Security is what the literature calls a secondary task: something you must do on the way to your real goal. A salesperson opens their laptop to close a deal. A nurse logs in to treat a patient. A finance analyst signs in to reconcile month-end. Nobody, anywhere, logs in to do security. And yet we build entire programmes on the assumption that they should.

Read article →
Article 29 Jun 2026 12 min

When did awareness become a science nobody told us we had to study?

For two decades, the role was understood. You came from learning and development or communications. You wrote clear copy, built the training, ran the webinar, and reported the completion rate. It was a craft, and a valuable one. Then we moved the target from knowledge to behaviour, and quietly changed the job.

Read article →
Article 22 Jun 2026 15 min

The expertise gap: why security teams must build behavioural capability

There is a quiet contradiction at the heart of most security functions. They exist because people are the most consequential variable in organisational risk, yet they are staffed, trained and measured almost entirely in terms of technology rather than human behavioural risk. That gap was tolerable when the threat moved at human speed. It is becoming dangerous now that it does not.

Read article →
Article 20 May 2026 14 min

Measuring What Matters

This is Part 4 of a four-part series. Parts 1 to 3 covered dual process theory, cognitive biases mapped to attack vectors, and practical intervention design using the EAST framework and choice architecture. This final article addresses the measurement frameworks that connect behavioural security programmes to meaningful risk outcomes.

Read article →
Signals 10 Aug 2026 8 min

Week 33: Mind the Gap

This week's edition circles a single question: what happens in the space between knowing and doing? A peer-reviewed study puts fresh numbers on the awareness-behaviour gap, a benchmark of 14 million phishing simulations exposes how rarely people report what they spot, and the corridors of Black Hat were full of talk about social engineering that no longer bothers with the inbox.

Read briefing →

Ready to build behaviour,
culture, and resilience?

Start your free trial. No credit card required. Up and running in minutes.