Choice architecture is the deliberate design of the moment in which a person makes a decision: what they see first, what the default is, how much effort each option takes, and what everyone around them appears to be doing. Every security decision your people make already has an architecture. The only question is whether you designed it, or whether it was left to chance and to the people trying to get in.
Richard Thaler and Cass Sunstein coined the phrase in 2008 to describe something people had been doing for centuries without a name for it. Whoever lays out the canteen decides what gets eaten. Whoever sets the default on a pension form decides how many people save. Whoever writes the order of a menu decides what gets ordered. None of these people force anyone to do anything. They simply arrange the choice so that one option is easier, more visible or more obviously normal than the others, and most people, most of the time, take that option.
In security the same thing is true, and it cuts both ways. When a phishing email arrives with a big blue button, a countdown timer and the name of your finance director at the bottom, that is choice architecture. Somebody designed that moment very carefully so that clicking was the easy, obvious, urgent thing to do. The attacker is a choice architect. A rather good one.
Most security teams are not. They put the secure option behind three extra clicks, write the guidance in a policy nobody opens, and then run a course explaining why people should try harder. Choice architecture is the discipline of taking that moment back: making the secure choice the one that requires the least thought, the least effort and the least courage.
Think about when a security decision actually gets made. Rarely in a training session. Almost always in the middle of something else: forty seconds before a meeting, on a phone, with a manager waiting for an answer. In that moment nobody is reasoning from first principles. They are doing whatever is quickest, whatever they did last time, and whatever looks like what everyone else does.
This is not a character flaw. It is how attention works when it is scarce, and it is scarce for everybody. You can spend a great deal of money trying to make people more careful and move the needle a little. Or you can change what the careless, hurried, default choice actually is, and move it a lot.
Choice architecture is also honest about who else is in the room. In health or pensions the architect is on the person's side. In security there is a second architect actively designing for the wrong outcome. Every moment you leave undesigned is a moment they will design for you. The levers on the right are the ones you have to work with.
What happens if the person does nothing. The single strongest lever there is. If the secure setting is the default, most people will keep it. If it is opt-in, most people will not opt in.
How many steps, clicks or seconds each option costs. Add friction to the risky path and remove it from the safe one. Even a single extra click changes what most people do.
What is noticed first. A report button in the ribbon gets pressed; one buried in a menu does not. Attackers use salience relentlessly. Security teams mostly forget it exists.
When the prompt arrives. Guidance at the point of decision works; guidance three weeks earlier in a course is gone by the time it is needed.
What the person believes everyone else does. Say that most of the team already report suspicious emails and reporting goes up. Say that hardly anyone does and it goes down.
What the person learns afterwards. If reporting a phish produces silence, people stop. If it produces a thank-you within the hour, they do it again.
The method is simple and it is meant to be. The mistake most teams make is starting at step four, picking a clever nudge they read about and bolting it on without knowing which behaviour it is for, or what the moment looks like from the inside. Start with one behaviour. Do all six steps. Then do the next one.
Name it so precisely that you could watch somebody do it. Not "be more secure" or "think before you click". Something like "report a suspicious email using the button rather than deleting it" or "lock the screen when leaving the desk". If you cannot observe it, you cannot design for it.
Work out where and when the decision actually happens. What device, what time pressure, what else is on screen, who else is watching. Go and look. Ask a Champion to walk you through it. The moment is nearly always messier and faster than the security team imagines.
Ask why the risky option currently wins. Is it the default? Is it fewer clicks? Is it what the manager does? Is the secure option invisible, or slow, or does it make the person look awkward in front of colleagues? Be specific. There is usually one dominant reason and it is rarely ignorance.
Match the diagnosis to a lever. If the problem is the default, change the default. If it is effort, remove steps from the safe path or add them to the risky one. If it is visibility, move the option. If it is timing, put the prompt in the moment. Resist the urge to use all six at once.
Make the change for one team, one site or one system first. Keep the change small enough that you can tell what caused what. Measure before and after using something you can actually count: reports, enrolments, locked screens observed, tickets raised.
If it worked, roll it out and write down why. If it did not, do not add a poster. Go back to step three; the diagnosis was probably wrong. Either way, the moment you redesigned will drift as systems and teams change, so put someone in charge of watching it.
These are composites drawn from programmes we have run and seen. None of them needed a budget line. All of them needed somebody to stop writing the message and go and look at the moment.
Nobody in the pilot unit received any new training. The message about reporting had been the same for three years. What changed was that reporting became the easiest thing to do with a suspicious email, and doing it produced a reply.
The automatic acknowledgement turned out to matter more than the button placement. When it was briefly switched off during a mail system change, reports dipped within a fortnight.
The reminder emails had been well written and were sent three times. They were not the problem. The problem was that the secure option had been made optional at the exact moment people had least reason to choose it.
Changing a default is not a nudge in the gentle sense. It is a decision about what happens to people who do nothing, and it should be owned and explained as such. Nobody objected once the reasoning was visible.
Half of this example is simply removing steps from the safe path. The other half is what Champions said in team meetings, which shifted the belief about what was normal. The confirmation step on its own, tested earlier without the other two changes, was mostly just clicked through.
The feedback loop from Champions was what stopped the friction becoming an annoyance. That is the part most teams skip, and it is the part that decides whether a redesign survives contact with real work.
The hardest part of choice architecture is step two. Security teams do not sit in the moments where decisions are made. Champions do. A working Security Champions Network gives you people in every team who can describe the moment, test the redesign, tell you when it is misfiring and report what colleagues actually did. CyBehave Heroes is built to run that loop.
Champion check-ins and the peer pulse bring back what people actually do at the point of decision, rather than what the policy assumes they do.
Tasks with completion tracking let you ask a set of Champions to run a redesign locally and see who has done it, so pilots happen in weeks rather than quarters.
Feedback from Champions reaches the people who own the control, so friction that lands in the wrong place gets tuned instead of quietly worked around.
The Behaviour Index, observed by colleagues, gives you before-and-after evidence for the behaviour you redesigned, in language a sponsor will accept.
Start your free trial of CyBehave Heroes - no credit card required.