Most security incidents involve a person doing something, or not doing something. This page explains what behavioural cybersecurity is, why the usual answer (more training) rarely works on its own, the handful of concepts you need to know, and how to start. Written for security leaders, awareness managers and anyone curious about the human side of security.
Behavioural cybersecurity is the application of behavioural science to the human side of security: understanding why people do what they do, and changing the conditions that shape those actions, rather than only telling people what they should know.
Traditional security has two toolkits. Engineering for the machines: firewalls, patching, identity, detection. And communication for the people: policies, posters, e-learning, phishing simulations. The first toolkit is rigorous and measured. The second has largely run on intuition. Behavioural cybersecurity closes that gap by bringing the same discipline to people that we already apply to systems.
The shift is subtle but important. Awareness asks "do people know the right thing?" Behavioural cybersecurity asks "do people do the right thing, and if not, why not?" The answer to the second question is almost never "because nobody told them". It is usually something about time, friction, incentives, habit, social pressure or trust, and each of those has a different fix.
It draws on established fields: cognitive psychology (how we make decisions under pressure), behavioural economics (how incentives and defaults steer choices), social psychology (how the people around us shape what we do) and organisational science (how culture forms and persists). None of this is new. What is new is applying it to security with the same rigour the research itself demands.
Phishing, business email compromise, pretexting and MFA fatigue attacks all work the same way: they target a decision, not a device. They are engineered to catch people in the fast, automatic mode of thinking that runs most of our day, using urgency, authority and familiarity to skip the slow, deliberate mode we reserve for hard problems[3,11]. The attacker is not exploiting a lack of knowledge. They are exploiting how attention works.
The obvious response, "train people harder", has been tested for decades and the results are consistently disappointing. Awareness campaigns raise knowledge scores and leave behaviour largely unchanged[10]. This is not a security-specific failure. Across health, finance and safety, the correlation between what people intend to do and what they actually do is weak: the intention-action gapThe well-documented finding that people who fully intend to do something frequently do not. Knowing and intending are necessary but not sufficient for doing.[4]. Knowledge is an input to behaviour. It is not the same thing.
There is a second reason it matters. Blaming people ("the weakest link", "the human firewall") is not just unkind, it is inaccurate. One of the founding papers of the field showed that people behave insecurely largely because security is designed without them in mind, and that treating them as the problem makes things worse[2]. When you look closely at non-compliance, it is often a rational response to rules whose cost outweighs their visible benefit[7]. Fix the design and the behaviour follows.
Most programmes are measured at the first level, promise the second, and hope for the third. Being clear about which one you are working on changes what you do and what you measure.
Knowledge of threats, policies and correct responses. Necessary, cheap to deliver, easy to measure with a quiz. On its own it changes very little, because knowledge rarely determines what people do under pressure.
Observable actions: reporting a suspicious email, using a password manager, challenging an unexpected request, locking a screen. This is where risk actually changes, and it must be measured directly rather than inferred from training completion.
Shared assumptions, norms and unwritten rules that make secure behaviour the default even when nobody is watching[14]. Culture is what sustains behaviour after the campaign ends and the champion moves on.
You do not need a psychology degree. These concepts recur so often in the research that recognising them will change how you read almost any incident.
Start with the model that ties everything together. The COM-B model, from the Behaviour Change Wheel, says any behaviour requires three things at once: the capability to do it, the opportunity to do it, and the motivation to do it[5]. If a behaviour is not happening, at least one of these is missing. Diagnose which, and you know what kind of intervention to design. Training only ever addresses the first.
Do they know how, and can they physically and mentally do it? Skills, knowledge, attention.
Does the environment allow it? Time, tools, workload, and whether the people around them do it too.
Do they want to, in the moment? Habits, emotions, beliefs about consequences, identity.
Most decisions are made quickly and automatically. Deliberate, careful reasoning is effortful and reserved for problems that feel hard[3]. Attacks are built to keep you in fast mode.
So what: design for the fast mode. Make the secure choice the obvious one, and add a deliberate pause only where it matters.
People who fully intend to behave securely frequently do not, because intention is only weakly linked to action[4].
So what: stop measuring intention (quiz scores, pledges) as though it were behaviour. Measure what people actually do.
Employees hold a finite reserve of time and effort for security. Every rule, prompt and module draws it down; once it is spent, corners get cut regardless of motivation[6].
So what: every new control has a cost. Remove or automate low-value demands before adding more.
When people feel bombarded by warnings, rules and decisions, they disengage: they stop reading, click through, and default to whatever is easiest[8].
So what: fewer, better-timed messages beat constant noise. Reduce decisions rather than adding warnings.
When official controls get in the way, people invent their own workarounds. These are often thoughtful and reveal exactly where the design fails[9].
So what: treat workarounds as diagnostic data, not disobedience. Ask why before you ban.
People take their cues from what others around them do far more than from what a policy says[11]. If the team leader ignores the process, the team will too.
So what: make good behaviour visible. Peer influence, and especially Security Champions, moves norms in ways broadcast messaging cannot.
People report mistakes, near misses and suspicious things only when they believe they will not be punished or embarrassed for doing so[13].
So what: reporting rate is a culture signal. If people are not telling you about mistakes, the mistakes are still happening.
The way a choice is presented shapes the choice. Defaults are sticky; small amounts of friction change outcomes disproportionately[12].
So what: make the secure path the path of least resistance. Add friction to risky actions, remove it from safe ones.
You do not need a big-bang programme. You need one behaviour, a baseline, a hypothesis about why it is not happening, an intervention that addresses that reason, and a measurement. Then repeat. This is the loop the SHIELD framework formalises in six stages.
Pick one behaviour, in one population, in one context. "Report suspicious emails within an hour" beats "be more security aware".
Use COM-B to work out why it is not happening now. Is it capability, opportunity or motivation? Ask people. Watch them.
Design something that addresses the actual barrier: a default, a prompt, a peer, a simpler process. Not automatically a training module.
Build it into how work already happens, so it survives without constant attention. Champions and managers carry this.
Measure the behaviour again against the baseline. Be honest about what moved and what did not. Adjust.
Take what worked to the next team or the next behaviour. Culture is built one embedded behaviour at a time.
A note on measurement. The single most common failure in this field is measuring the wrong thing. Training completion, quiz scores and campaign reach are activity metrics; they tell you what the security team did, not what the organisation does. Measure behaviour directly, keep separate signals separate rather than blending them into one score, and measure repeatedly so you can see change rather than a snapshot.
The research behind the concepts on this page, and why copying models from other domains does not work.
SHIELDSpecify, Hypothesise, Intervene, Embed, Learn, Diffuse. An open method for running behaviour change as a discipline.
Behavioural Convergence TheoryHow human and agentic behavioural risk converge, and why they need a unified approach.
Skills FrameworkSeven domains, thirty competencies and five proficiency levels for behavioural security work.
Security ChampionsWhy peer-led programmes move behaviour that broadcast messaging cannot, and how to run one well.
ResearchCyBehave's ongoing research and published insights.
Everything above is grounded in published work. Read the originals; they are worth your time.
CyBehave Heroes runs Security Champions programmes on exactly this science: specific behaviours, real measurement, peer-led change.