Nobody chooses in a vacuum.
Somebody designed the room.

Choice architecture is the deliberate design of the moment in which a person makes a decision: what they see first, what the default is, how much effort each option takes, and what everyone around them appears to be doing. Every security decision your people make already has an architecture. The only question is whether you designed it, or whether it was left to chance and to the people trying to get in.

Show me how to do it → Worked examples What is a Security Champion?
What it is

The term comes from behavioural economics. The problem is older than that.

Richard Thaler and Cass Sunstein coined the phrase in 2008 to describe something people had been doing for centuries without a name for it. Whoever lays out the canteen decides what gets eaten. Whoever sets the default on a pension form decides how many people save. Whoever writes the order of a menu decides what gets ordered. None of these people force anyone to do anything. They simply arrange the choice so that one option is easier, more visible or more obviously normal than the others, and most people, most of the time, take that option.

In security the same thing is true, and it cuts both ways. When a phishing email arrives with a big blue button, a countdown timer and the name of your finance director at the bottom, that is choice architecture. Somebody designed that moment very carefully so that clicking was the easy, obvious, urgent thing to do. The attacker is a choice architect. A rather good one.

Most security teams are not. They put the secure option behind three extra clicks, write the guidance in a policy nobody opens, and then run a course explaining why people should try harder. Choice architecture is the discipline of taking that moment back: making the secure choice the one that requires the least thought, the least effort and the least courage.

Telling people what to do
The awareness approach
  • Assumes people decide by weighing up information
  • Puts all the effort into the message and none into the moment
  • Secure option is often the harder, slower or more awkward one
  • Works for the motivated minority who were already going to comply
  • When people fail, the explanation is that they did not listen
Designing the moment of choice
The choice architecture approach
  • Assumes people decide quickly, under pressure, with habits and shortcuts
  • Puts the effort into the default, the layout, the friction and the timing
  • Secure option is the path of least resistance
  • Works for the busy majority who never read the policy
  • When people fail, the explanation is that the moment was badly designed
Why it is needed

People do not fail security. Moments do.

Think about when a security decision actually gets made. Rarely in a training session. Almost always in the middle of something else: forty seconds before a meeting, on a phone, with a manager waiting for an answer. In that moment nobody is reasoning from first principles. They are doing whatever is quickest, whatever they did last time, and whatever looks like what everyone else does.

This is not a character flaw. It is how attention works when it is scarce, and it is scarce for everybody. You can spend a great deal of money trying to make people more careful and move the needle a little. Or you can change what the careless, hurried, default choice actually is, and move it a lot.

Choice architecture is also honest about who else is in the room. In health or pensions the architect is on the person's side. In security there is a second architect actively designing for the wrong outcome. Every moment you leave undesigned is a moment they will design for you. The levers on the right are the ones you have to work with.

✓

Defaults

What happens if the person does nothing. The single strongest lever there is. If the secure setting is the default, most people will keep it. If it is opt-in, most people will not opt in.

✓

Friction

How many steps, clicks or seconds each option costs. Add friction to the risky path and remove it from the safe one. Even a single extra click changes what most people do.

✓

Salience

What is noticed first. A report button in the ribbon gets pressed; one buried in a menu does not. Attackers use salience relentlessly. Security teams mostly forget it exists.

✓

Timing

When the prompt arrives. Guidance at the point of decision works; guidance three weeks earlier in a course is gone by the time it is needed.

✓

Social proof

What the person believes everyone else does. Say that most of the team already report suspicious emails and reporting goes up. Say that hardly anyone does and it goes down.

✓

Feedback

What the person learns afterwards. If reporting a phish produces silence, people stop. If it produces a thank-you within the hour, they do it again.

How to do it

Six steps. One behaviour at a time.

The method is simple and it is meant to be. The mistake most teams make is starting at step four, picking a clever nudge they read about and bolting it on without knowing which behaviour it is for, or what the moment looks like from the inside. Start with one behaviour. Do all six steps. Then do the next one.

Step 1

Pick one behaviour

Name it so precisely that you could watch somebody do it. Not "be more secure" or "think before you click". Something like "report a suspicious email using the button rather than deleting it" or "lock the screen when leaving the desk". If you cannot observe it, you cannot design for it.

Ask: What exactly do I want to see more of, or less of?
Step 2

Find the moment

Work out where and when the decision actually happens. What device, what time pressure, what else is on screen, who else is watching. Go and look. Ask a Champion to walk you through it. The moment is nearly always messier and faster than the security team imagines.

Ask: Where is this person, what are they doing, and what is competing for their attention?
Step 3

Diagnose the pull

Ask why the risky option currently wins. Is it the default? Is it fewer clicks? Is it what the manager does? Is the secure option invisible, or slow, or does it make the person look awkward in front of colleagues? Be specific. There is usually one dominant reason and it is rarely ignorance.

Ask: What makes the wrong choice the easy one right now?
Step 4

Choose the lever

Match the diagnosis to a lever. If the problem is the default, change the default. If it is effort, remove steps from the safe path or add them to the risky one. If it is visibility, move the option. If it is timing, put the prompt in the moment. Resist the urge to use all six at once.

Ask: Which one change would shift the balance the most?
Step 5

Redesign and pilot

Make the change for one team, one site or one system first. Keep the change small enough that you can tell what caused what. Measure before and after using something you can actually count: reports, enrolments, locked screens observed, tickets raised.

Ask: Did the behaviour move, and can I show it?
Step 6

Keep, scale or drop

If it worked, roll it out and write down why. If it did not, do not add a poster. Go back to step three; the diagnosis was probably wrong. Either way, the moment you redesigned will drift as systems and teams change, so put someone in charge of watching it.

Ask: Who owns this moment now, and how will I know if it slips back?
Worked examples

Three moments, walked through.

These are composites drawn from programmes we have run and seen. None of them needed a budget line. All of them needed somebody to stop writing the message and go and look at the moment.

Reporting suspicious email

Lever: friction and salience
  1. Behaviour. Report a suspicious email with the report button rather than deleting it or forwarding it to a colleague.
  2. Moment. Inbox, mid-morning, on a laptop or phone, with thirty other unread messages. The decision takes about two seconds.
  3. Diagnosis. Delete is one keystroke and always visible. The report button lives under a dropdown on desktop and does not exist on the mobile client. Reporting also produces no response, so people assume nothing happens.
  4. Lever. Move the button into the ribbon on desktop, add it to the mobile client, and send an automatic acknowledgement within the hour.
  5. Pilot. One business unit of around 400 people for six weeks, comparing report rate against the previous quarter and against a similar unit that did not change.
  6. Outcome. Report rate roughly tripled in the pilot unit and held. Rolled out to the rest of the organisation with the acknowledgement kept as standard.
What changed and what did not

Nobody in the pilot unit received any new training. The message about reporting had been the same for three years. What changed was that reporting became the easiest thing to do with a suspicious email, and doing it produced a reply.

The automatic acknowledgement turned out to matter more than the button placement. When it was briefly switched off during a mail system change, reports dipped within a fortnight.

Multi-factor authentication enrolment

Lever: defaults and timing
  1. Behaviour. Enrol a second factor on the corporate account within the first week.
  2. Moment. New starter, day one or two, working through a long list of setup tasks, keen to look competent and get on with the actual job.
  3. Diagnosis. Enrolment was optional for thirty days, reached by a link in a welcome email that arrived alongside eleven other welcome emails. It was also the only setup task with no obvious benefit to the person doing it.
  4. Lever. Make enrolment the default at first sign-in rather than something to come back to, and place it before the step that grants access to email. Frame it as the thing that lets you work from your phone.
  5. Pilot. All new starters in one region for two months, measuring enrolment by day seven against the previous cohort.
  6. Outcome. Day-seven enrolment moved from under half to nearly everyone. Support tickets about MFA went down, not up, because people set it up while the onboarding team was on hand.
What changed and what did not

The reminder emails had been well written and were sent three times. They were not the problem. The problem was that the secure option had been made optional at the exact moment people had least reason to choose it.

Changing a default is not a nudge in the gentle sense. It is a decision about what happens to people who do nothing, and it should be owned and explained as such. Nobody objected once the reasoning was visible.

Sharing files outside the organisation

Lever: friction and social proof
  1. Behaviour. Share a document with an external party using the approved sharing link rather than attaching it to an email or uploading it to a personal cloud account.
  2. Moment. A client or supplier has asked for something, the person is in a hurry, and email is already open with the file sitting in a recent folder.
  3. Diagnosis. Attaching takes two drags. The approved route took six clicks, required choosing between four permission levels nobody understood, and gave the impression that only the compliance team used it.
  4. Lever. Cut the approved route to a single "share externally" option with sensible permissions pre-set, add a light confirmation step to external attachments over a size threshold, and ask Champions to tell their teams that the link is what most people now use.
  5. Pilot. Two client-facing teams for eight weeks, counting external attachments and approved shares from the mail and collaboration platforms.
  6. Outcome. Approved sharing overtook attachments within a month. The confirmation step was tuned twice after Champions reported it firing on legitimate internal traffic.
What changed and what did not

Half of this example is simply removing steps from the safe path. The other half is what Champions said in team meetings, which shifted the belief about what was normal. The confirmation step on its own, tested earlier without the other two changes, was mostly just clicked through.

The feedback loop from Champions was what stopped the friction becoming an annoyance. That is the part most teams skip, and it is the part that decides whether a redesign survives contact with real work.

Where Heroes fits

Champions are your eyes on the moment.

The hardest part of choice architecture is step two. Security teams do not sit in the moments where decisions are made. Champions do. A working Security Champions Network gives you people in every team who can describe the moment, test the redesign, tell you when it is misfiring and report what colleagues actually did. CyBehave Heroes is built to run that loop.

Find the moment

Champion check-ins and the peer pulse bring back what people actually do at the point of decision, rather than what the policy assumes they do.

In Base
Pilot with a team

Tasks with completion tracking let you ask a set of Champions to run a redesign locally and see who has done it, so pilots happen in weeks rather than quarters.

In Base
Hear when it misfires

Feedback from Champions reaches the people who own the control, so friction that lands in the wrong place gets tuned instead of quietly worked around.

In Base
Show it moved

The Behaviour Index, observed by colleagues, gives you before-and-after evidence for the behaviour you redesigned, in language a sponsor will accept.

In Base
Explore Heroes → What is a Champions Network? Base platform and modules

Pick one moment. Redesign it this month.

Start your free trial of CyBehave Heroes - no credit card required.