Primer

Behavioural Cybersecurity 101

12 minute read No prior knowledge assumed

Most security incidents involve a person doing something, or not doing something. This page explains what behavioural cybersecurity is, why the usual answer (more training) rarely works on its own, the handful of concepts you need to know, and how to start. Written for security leaders, awareness managers and anyone curious about the human side of security.

What it is

A definition you can use in a meeting.

Behavioural cybersecurity is the application of behavioural science to the human side of security: understanding why people do what they do, and changing the conditions that shape those actions, rather than only telling people what they should know.

Traditional security has two toolkits. Engineering for the machines: firewalls, patching, identity, detection. And communication for the people: policies, posters, e-learning, phishing simulations. The first toolkit is rigorous and measured. The second has largely run on intuition. Behavioural cybersecurity closes that gap by bringing the same discipline to people that we already apply to systems.

The shift is subtle but important. Awareness asks "do people know the right thing?" Behavioural cybersecurity asks "do people do the right thing, and if not, why not?" The answer to the second question is almost never "because nobody told them". It is usually something about time, friction, incentives, habit, social pressure or trust, and each of those has a different fix.

It draws on established fields: cognitive psychology (how we make decisions under pressure), behavioural economics (how incentives and defaults steer choices), social psychology (how the people around us shape what we do) and organisational science (how culture forms and persists). None of this is new. What is new is applying it to security with the same rigour the research itself demands.

Why it matters

Attackers already use psychology. Most defenders do not.

Phishing, business email compromise, pretexting and MFA fatigue attacks all work the same way: they target a decision, not a device. They are engineered to catch people in the fast, automatic mode of thinking that runs most of our day, using urgency, authority and familiarity to skip the slow, deliberate mode we reserve for hard problems[3,11]. The attacker is not exploiting a lack of knowledge. They are exploiting how attention works.

2 in 3
Roughly two thirds of breaches involve a human element: an error, a stolen credential, a manipulated decision[1]. A defence that only addresses the technical third is defending a minority of the problem.

The obvious response, "train people harder", has been tested for decades and the results are consistently disappointing. Awareness campaigns raise knowledge scores and leave behaviour largely unchanged[10]. This is not a security-specific failure. Across health, finance and safety, the correlation between what people intend to do and what they actually do is weak: the intention-action gapThe well-documented finding that people who fully intend to do something frequently do not. Knowing and intending are necessary but not sufficient for doing.[4]. Knowledge is an input to behaviour. It is not the same thing.

There is a second reason it matters. Blaming people ("the weakest link", "the human firewall") is not just unkind, it is inaccurate. One of the founding papers of the field showed that people behave insecurely largely because security is designed without them in mind, and that treating them as the problem makes things worse[2]. When you look closely at non-compliance, it is often a rational response to rules whose cost outweighs their visible benefit[7]. Fix the design and the behaviour follows.

Three levels

Awareness, behaviour and culture are not the same thing.

Most programmes are measured at the first level, promise the second, and hope for the third. Being clear about which one you are working on changes what you do and what you measure.

Level 1

Awareness

"Do people know?"

Knowledge of threats, policies and correct responses. Necessary, cheap to deliver, easy to measure with a quiz. On its own it changes very little, because knowledge rarely determines what people do under pressure.

Level 2

Behaviour

"Do people do it?"

Observable actions: reporting a suspicious email, using a password manager, challenging an unexpected request, locking a screen. This is where risk actually changes, and it must be measured directly rather than inferred from training completion.

Level 3

Culture

"Is it just how we do things here?"

Shared assumptions, norms and unwritten rules that make secure behaviour the default even when nobody is watching[14]. Culture is what sustains behaviour after the campaign ends and the champion moves on.

Core concepts

Eight ideas that explain most security behaviour.

You do not need a psychology degree. These concepts recur so often in the research that recognising them will change how you read almost any incident.

Start with the model that ties everything together. The COM-B model, from the Behaviour Change Wheel, says any behaviour requires three things at once: the capability to do it, the opportunity to do it, and the motivation to do it[5]. If a behaviour is not happening, at least one of these is missing. Diagnose which, and you know what kind of intervention to design. Training only ever addresses the first.

C

Capability

Do they know how, and can they physically and mentally do it? Skills, knowledge, attention.

O

Opportunity

Does the environment allow it? Time, tools, workload, and whether the people around them do it too.

M

Motivation

Do they want to, in the moment? Habits, emotions, beliefs about consequences, identity.

Cognition

Fast and slow thinking

Most decisions are made quickly and automatically. Deliberate, careful reasoning is effortful and reserved for problems that feel hard[3]. Attacks are built to keep you in fast mode.

So what: design for the fast mode. Make the secure choice the obvious one, and add a deliberate pause only where it matters.

Cognition

The intention-action gap

People who fully intend to behave securely frequently do not, because intention is only weakly linked to action[4].

So what: stop measuring intention (quiz scores, pledges) as though it were behaviour. Measure what people actually do.

Effort

The compliance budget

Employees hold a finite reserve of time and effort for security. Every rule, prompt and module draws it down; once it is spent, corners get cut regardless of motivation[6].

So what: every new control has a cost. Remove or automate low-value demands before adding more.

Effort

Security fatigue

When people feel bombarded by warnings, rules and decisions, they disengage: they stop reading, click through, and default to whatever is easiest[8].

So what: fewer, better-timed messages beat constant noise. Reduce decisions rather than adding warnings.

Effort

Shadow security

When official controls get in the way, people invent their own workarounds. These are often thoughtful and reveal exactly where the design fails[9].

So what: treat workarounds as diagnostic data, not disobedience. Ask why before you ban.

Social

Social norms and social proof

People take their cues from what others around them do far more than from what a policy says[11]. If the team leader ignores the process, the team will too.

So what: make good behaviour visible. Peer influence, and especially Security Champions, moves norms in ways broadcast messaging cannot.

Social

Psychological safety

People report mistakes, near misses and suspicious things only when they believe they will not be punished or embarrassed for doing so[13].

So what: reporting rate is a culture signal. If people are not telling you about mistakes, the mistakes are still happening.

Environment

Defaults, friction and choice architecture

The way a choice is presented shapes the choice. Defaults are sticky; small amounts of friction change outcomes disproportionately[12].

So what: make the secure path the path of least resistance. Add friction to risky actions, remove it from safe ones.

Common myths

Six things the industry gets wrong.

"If people knew better, they would do better."
Knowledge is one input among several. Most people who click a phishing link already know what phishing is. Look at capability, opportunity and motivation together.
"Humans are the weakest link."
People are the most adaptive control you have, and the only one that can spot something the rules did not anticipate. Poorly designed security is the weak link. The person is where it shows[2].
"Phishing click rate tells us how secure we are."
Click rate measures one behaviour, under one set of conditions, with a simulated lure. It ignores reporting, which matters more, and is easy to game. Measure a small set of behaviours that matter, including reporting.
"Punishing repeat clickers fixes the problem."
Punishment suppresses reporting and drives behaviour underground. People stop telling you what happened[13]. You trade a visible problem for an invisible one.
"Annual training covers it."
One-off events produce a short-lived knowledge bump and no lasting behavioural change[10]. Behaviour change is continuous work, done in small, measured cycles.
"We can just import a model from health or safety."
The underlying science transfers. The specifics do not: security threats adapt, feedback is delayed or absent, and the "patient" rarely sees the harm. Frameworks need to be built for the domain, then tested in it.
How to start

Treat behaviour change as an experiment, not a campaign.

You do not need a big-bang programme. You need one behaviour, a baseline, a hypothesis about why it is not happening, an intervention that addresses that reason, and a measurement. Then repeat. This is the loop the SHIELD framework formalises in six stages.

S

Specify

Pick one behaviour, in one population, in one context. "Report suspicious emails within an hour" beats "be more security aware".

H

Hypothesise

Use COM-B to work out why it is not happening now. Is it capability, opportunity or motivation? Ask people. Watch them.

I

Intervene

Design something that addresses the actual barrier: a default, a prompt, a peer, a simpler process. Not automatically a training module.

E

Embed

Build it into how work already happens, so it survives without constant attention. Champions and managers carry this.

L

Learn

Measure the behaviour again against the baseline. Be honest about what moved and what did not. Adjust.

D

Diffuse

Take what worked to the next team or the next behaviour. Culture is built one embedded behaviour at a time.

A note on measurement. The single most common failure in this field is measuring the wrong thing. Training completion, quiz scores and campaign reach are activity metrics; they tell you what the security team did, not what the organisation does. Measure behaviour directly, keep separate signals separate rather than blending them into one score, and measure repeatedly so you can see change rather than a snapshot.

Glossary

Terms you will meet.

Behaviour change technique (BCT)
A specific, replicable component of an intervention, such as goal setting, prompts or feedback, as catalogued in the Behaviour Change Wheel literature[5]. Not to be confused with Behavioural Convergence Theory, CyBehave's own framework, which shares the abbreviation.
Choice architecture
The design of the environment in which people make decisions: defaults, ordering, friction, framing[12].
COM-B
A model stating that behaviour requires Capability, Opportunity and Motivation simultaneously. The diagnostic core of the Behaviour Change Wheel[5].
Compliance budget
The finite effort people will spend on security before cutting corners[6].
Human risk management
An umbrella term for identifying, measuring and reducing security risk arising from people's behaviour. Behavioural cybersecurity is the science underneath it.
Intention-action gap
The gap between what people intend to do and what they do[4].
Nudge
A small change to choice architecture that steers behaviour without removing options or changing incentives[12]. Useful for simple, repeated behaviours; insufficient on its own for complex ones.
Psychological safety
A shared belief that it is safe to speak up, admit mistakes and ask questions without punishment[13]. A precondition for reporting.
Security Champion
A member of a business team who acts as a local advocate and point of contact for security. Champions shift social norms because they are peers, not the security department.
Security culture
The shared assumptions, values and practices that shape security behaviour in an organisation, especially when nobody is watching[14].
Security fatigue
Disengagement caused by too many security demands, warnings and decisions[8].
Shadow security
Informal workarounds people create when official controls obstruct their work[9].
Read next

Go deeper.

Sources

References

Everything above is grounded in published work. Read the originals; they are worth your time.

  1. Verizon (2024) Data Breach Investigations Report. Verizon Business.
  2. Adams, A. and Sasse, M.A. (1999) 'Users are not the enemy', Communications of the ACM, 42(12), pp. 40–46.
  3. Kahneman, D. (2011) Thinking, Fast and Slow. London: Allen Lane.
  4. Sheeran, P. (2002) 'Intention–behavior relations: a conceptual and empirical review', European Review of Social Psychology, 12(1), pp. 1–36.
  5. Michie, S., van Stralen, M.M. and West, R. (2011) 'The behaviour change wheel: a new method for characterising and designing behaviour change interventions', Implementation Science, 6, 42.
  6. Beautement, A., Sasse, M.A. and Wonham, M. (2008) 'The compliance budget: managing security behaviour in organisations', Proceedings of the New Security Paradigms Workshop (NSPW), pp. 47–58.
  7. Herley, C. (2009) 'So long, and no thanks for the externalities: the rational rejection of security advice by users', Proceedings of the New Security Paradigms Workshop (NSPW), pp. 133–144.
  8. Stanton, B., Theofanos, M.F., Prettyman, S.S. and Furman, S. (2016) 'Security fatigue', IT Professional, 18(5), pp. 26–32.
  9. Kirlappos, I., Parkin, S. and Sasse, M.A. (2014) 'Learning from “shadow security”: why understanding non-compliant behaviors provides the basis for effective security', Proceedings of the Workshop on Usable Security (USEC).
  10. Bada, M., Sasse, M.A. and Nurse, J.R.C. (2015) 'Cyber security awareness campaigns: why do they fail to change behaviour?', Proceedings of the International Conference on Cyber Security for Sustainable Society, pp. 118–131.
  11. Cialdini, R.B. (2007) Influence: The Psychology of Persuasion. Revised edn. New York: Harper Business.
  12. Thaler, R.H. and Sunstein, C.R. (2008) Nudge: Improving Decisions About Health, Wealth, and Happiness. New Haven: Yale University Press.
  13. Edmondson, A. (1999) 'Psychological safety and learning behavior in work teams', Administrative Science Quarterly, 44(2), pp. 350–383.
  14. Alshaikh, M. (2020) 'Developing cybersecurity culture to influence employee behavior: a practice perspective', Computers & Security, 98, 102003.

Ready to move from awareness to behaviour?

CyBehave Heroes runs Security Champions programmes on exactly this science: specific behaviours, real measurement, peer-led change.