There are at least 83 published theories of behaviour change. Michie and colleagues catalogued them in 2014, and between them those theories contain more than 1,700 component constructs. Sitting alongside the theories is a taxonomy of 93 distinct behaviour change techniques, each one a separate lever you might pull. That is the toolbox available to anyone whose job is to get people to report phishing, verify payment requests, or stop reusing passwords.
You would think this abundance was a gift. In practice, it is one of the biggest reasons security behaviour programmes fail.
The paralysis problem, and its opposite
Put yourself in the position of a security awareness manager on a Monday morning. The board wants click rates down. You have a budget, a quarter, and 83 theories. Do you build around COM-B or the Fogg Behavior Model? Protection Motivation Theory or the Extended Parallel Process Model? Is this a nudge situation or a habit situation? Should you be reading Ajzen, Bandura, or Prochaska?
Faced with that, most practitioners do one of two things, both of which are rational responses to an impossible choice.
The first is paralysis resolved by default: skip the theory entirely and buy what the market sells, which is training, simulated phishing and a content library. Not because any diagnosis pointed there, but because it is procurable, measurable in the shallow sense, and defensible in front of an audit committee.
The second is cherry-picking. A theory gets selected after the intervention has already been decided, then quoted in the slide deck as justification. Davis and her colleagues reviewed how theory is actually used in intervention research and found a small handful of frameworks doing almost all the work, cited far more often than they are applied. The theory becomes decoration. I have read vendor whitepapers where "nudge" describes what is, on inspection, a monthly newsletter.
Neither route involves theory doing its actual job, which is to explain why a specific behaviour is not happening so you can fix the right thing.
Theories describe. Very few prescribe.
Here is the uncomfortable part that the compendiums do not advertise. Most behaviour change theories were built to explain variance in past behaviour, not to tell you what to do next Tuesday. They are descriptive achievements, and often impressive ones, but description and prescription are different products.
The clearest evidence sits in the intention-behaviour gap. Webb and Sheeran's meta-analysis found that even a medium-to-large change in intention produces only a small-to-medium change in actual behaviour. Decades of intention-centred models, and the thing they predict best still is not the thing we need. Every security professional has met this gap personally: the employee who scored 100 per cent on the training, agreed enthusiastically that verification matters, and paid the fraudulent invoice anyway.
So a practitioner who reads deeply is rewarded with a subtler problem: the theories are true in the way a map of geology is true, while the job needs a route.
The field cannot agree what words mean
The second challenge is quieter and more corrosive. The 1,700 constructs overlap, duplicate, and contradict one another. Self-efficacy in one theory is perceived behavioural control in another and ability in a third, and the three are not quite the same thing, except when they are. Two vendors can both claim to measure "security culture" while measuring entirely different objects, and both can cite literature in support.
This matters commercially, not just academically. When constructs are interchangeable, evidence becomes interchangeable, and a market emerges where any product can borrow any theory's credibility. The buyer cannot tell theory-led design from theory-washing, because the vocabulary provides no traction. I have argued elsewhere that this is how the human risk market ended up scoring people on telemetry and calling it behavioural science.
Security is the awkward guest at the theory table
There is a third problem specific to our field. Most of the 83 theories were developed and tested on health behaviours: smoking cessation, exercise, medication adherence. In those settings, the person performing the behaviour is the person who benefits, and the behaviour is, at least in part, the point of the moment.
Security behaviour inverts both conditions. The benefit is invisible when it works and lands mostly on the organisation, while the cost in time and attention lands on the individual, who is in the middle of doing their actual job. Beautement, Sasse and Wonham named the consequence the compliance budget: a finite reserve of effort that employees will spend on security before they start cutting corners. Herley went further and showed that ignoring much security advice is economically rational, because the aggregate cost of following it exceeds the loss it prevents.
A theory imported from health promotion carries none of this in its assumptions. Apply it unmodified, and it will keep recommending motivation work for what is actually an opportunity problem, more conviction for people who already believe, delivered into a budget that is already spent.
What working practitioners should actually do
I do not think the answer is a new grand theory, although I have tried, and I am suspicious of anyone selling one knowing just how difficult this is and what already exists. The answer is a change in how theories are used. Four practices make the difference.
- Select by function, not fashion. A theory earns its place by the question it answers. COM-B earns its place at diagnosis because it forces the question "is this a capability, opportunity or motivation problem?" and each answer routes to a different intervention. Fogg earns his place at delivery because prompt placement is a design decision. Diffusion of Innovations earns its place at scale. No single theory covers the journey, and pretending one does is how programmes end up with a hammer and a world of screws.
- Carry a small working set. Five or six models, understood deeply, chosen because together they cover diagnosis, design, delivery, measurement and scale. Depth in a few beats a citation for every occasion. The 83 are a library, not a shopping list.
- Tie every theory to a prediction that can fail. If the diagnosis says the problem is motivation, state in advance what the intervention will change, by how much, and by when: this feedback loop will lift reporting rates by ten points within eight weeks. If the prediction fails, the diagnosis was wrong, and you go back to diagnosis rather than shouting the same message louder. A theory that cannot be wrong in your hands is not being used; it is being worn
- Translate before you apply. Every imported model needs adjusting for security's inverted economics: secondary task, invisible benefit, individual cost, adaptive threat. If a theory's recommendation ignores the compliance budget, the recommendation is incomplete for our field, whatever its evidence base elsewhere.
This is the thinking built into SHIELD, the behavioural change framework that underpins how CyBehave works. SHIELD does not add an 84th theory. It sequences a small, openly cited working set into an operating cycle, so that each model does the one job it is actually good at, and every claim has to survive measurement. The theories are the instruments. The framework is the discipline of playing them in order.
The field does not have a knowledge problem. It has a selection problem, a translation problem and an accountability problem. Eighty-three theories are only a burden if you try to carry them all.
Check out CyBehave | SHIELD today at https://cybehave.com/shield-framework
Sources and further reading
- Beautement, A., Sasse, M.A. and Wonham, M. (2008) 'The compliance budget: Managing security behaviour in organisations', Proceedings of the New Security Paradigms Workshop (NSPW), pp. 47–58.
- Davis, R., Campbell, R., Hildon, Z., Hobbs, L. and Michie, S. (2015) 'Theories of behaviour and behaviour change across the social and behavioural sciences: A scoping review', Health Psychology Review, 9(3), pp. 323–344.
- Herley, C. (2009) 'So long, and no thanks for the externalities: The rational rejection of security advice by users', Proceedings of the New Security Paradigms Workshop (NSPW), pp. 133–144.
- Michie, S., Richardson, M., Stralen, M.M. van, et al. (2013) 'The behavior change technique taxonomy (v1) of 93 hierarchically clustered techniques', Annals of Behavioral Medicine, 46(1), pp. 81–95.
- Michie, S., West, R., Campbell, R., Brown, J. and Gainforth, H. (2014) ABC of Behaviour Change Theories. London: Silverback Publishing.
- Michie, S., van Stralen, M.M. and West, R. (2011) 'The behaviour change wheel: A new method for characterising and designing behaviour change interventions', Implementation Science, 6, 42.
- Webb, T.L. and Sheeran, P. (2006) 'Does changing behavioral intentions engender behavior change? A meta-analysis of the experimental evidence', Psychological Bulletin, 132(2), pp. 249–268.