The Lab

Where the research happens

Everything CyBehave builds starts as a question about behaviour. The Lab is where those questions are worked through - the frameworks, models and studies behind our platforms, published openly so you can see exactly what we measure, how, and why.

Explore the frameworks → Read the latest research
A researcher and an AI agent working together at a desk, reviewing behavioural data.
In progress

Active research

An honest status board. Early means a question we are still shaping; active means work running now; published means the work is finished and available.

Interventions
Intervention effect and decay
Early

Which interventions actually shift behaviour, how long the shift lasts once attention moves elsewhere, and what has to be in place for a change to embed rather than rebound.

Decay is the part the industry tends to skip. An intervention that works for six weeks and is never measured again is indistinguishable from one that did nothing.

Disruption
Behaviour and culture under disruption
Early

What happens to security behaviour and culture during a major disruptive event - an incident, a merger, a disposal, a change of strategy - and whether the damage can be anticipated and managed rather than discovered afterwards.

Early work, but the pattern is familiar enough to be worth studying properly: attention spikes, then the programme absorbs the disruption and quietly loses ground.

Measurement
Peer-observed behaviour measurement
Active

Testing whether behaviour observed by colleagues, gathered in waves across the year, gives a more honest read on security behaviour than self-report or click-rate.

In scope: how many waves a year is enough, how observer bias shows up and what dampens it, and whether a peer-observed score moves in ways that survive scrutiny from a sceptical board.

Networks
Security Champion network health
Active

What makes a champion network hold together rather than quietly decay: tenure effects, coverage, position in the informal structure, and which signals predict a programme running out of energy before the sponsor notices.

Closely tied to SCIM. The practical question is whether decline can be seen early enough to do something about it, rather than explained afterwards.

AI and behaviour
Behavioural Convergence Theory
Active

Systematically assessing how each established human cyber risk concept maps to AI agent behaviour, and classifying the strength of each analogy rather than asserting that the whole thing transfers.

The work is ongoing because the ground keeps moving. Agent capability changes faster than the literature about it, so the classifications are reviewed rather than fixed.

Assessment
Programme maturity and readiness
Published

A structured assessment of behavioural readiness, staged against recognised maturity thinking, giving security leaders a defensible starting position rather than a vendor score out of ten.

It reports where a programme is constrained rather than only how it scores, on the grounds that knowing your weakest stage is more useful than knowing your average.

Published work

The frameworks, in the open

Four bodies of published work. Each one is a standing output of the Lab, and each one feeds directly into the platforms. Open a row to read more.

Framework
SHIELD

Our six-stage behavioural change framework for cybersecurity: Specify, Hypothesise, Intervene, Embed, Learn, Diffuse. It gives a security team a repeatable way to move from a vague concern about behaviour to a tested intervention and an embedded change.

Built on COM-B and the Behaviour Change Wheel, but written for working practitioners rather than researchers. SHIELD is the backbone of how Heroes structures a programme, and it is free to use whether or not you ever buy anything from us.

Read the SHIELD framework →
Interactive model
The Behavioural Model

An adaptation of the Behaviour Change Wheel to security behaviour: 16 behavioural factors arranged across four concentric layers, from the individual outwards to the organisational conditions that shape what people actually do.

The model can be viewed through three lenses - human, AI agent, and convergent - which lets you ask whether a given factor behaves the same way for a person and for an autonomous system.

Explore the model →
Research programme
Behavioural Convergence Theory BCT

Our open question about whether human behavioural science can be meaningfully extended to understand, predict and govern AI agent behaviour - and whether the security industry is quietly solving the same problem twice under two different names.

Rather than asserting that the whole of behavioural science transfers, BCT assesses each established human cyber risk concept individually and classifies how strong the analogy actually is. Some hold well. Some do not hold at all.

Read the theory →
Capability
Skills Framework

The Behavioural Cyber Risk Skills Framework: 30 competencies across 7 domains and 5 proficiency levels, covering what a team needs to be able to do to manage human cyber risk properly.

Use it to assess where your team is now, to write a defensible job description, or to work out which capability gap is the one actually holding your programme back.

View the framework →
Evidence standard

What we will and will not claim

Behavioural science attracts confident claims. Most of them are unearned, and the security industry has been sold enough of them already. So the Lab holds itself to a rule: the strength of a claim has to match the strength of the evidence behind it, and both get stated.

In practice that means we will tell you when something is grounded in replicated research, when it is a reasonable inference we are testing, and when it is a hypothesis we happen to find persuasive. Those are three different things, and collapsing them into one confident sentence is how the field ends up back where it started.

It also means we will change our position when the evidence does. Anyone promising a solved formula for human cyber risk is selling certainty the science does not yet support.

01

Established

Replicated in peer-reviewed research across multiple studies and settings. We state it plainly and cite it.

02

Supported

Good evidence exists, but from a narrower base than we would like. We state it with the limits attached.

03

Testing

A reasonable inference we are actively running studies on. Described as a working position, never as a finding.

04

Exploratory

A question we are shaping. Published as thinking, flagged as such, and open to being wrong.

Applied

Research that leaves the Lab

Science that stays in the journal changes nothing. Every framework here is built into something a security team can pick up on a busy Tuesday.

Latest

Research Insight Articles & Papers

View all research →

Read the work, then judge the product

Every framework the Lab publishes is free to read and free to use. Start with SHIELD, or see how the research is applied in practice.