Resources

Tools, frameworks and knowledge

Everything you need to understand, measure, and improve the human dimensions of your organisation's security posture.

Tools & Assessments

Interactive tools

Practical tools you can use right now to assess, plan, and improve.

Downloads

Free resources & guides

Guides, whitepapers, templates, and practical tools grounded in behavioural science and real-world security practice.

Showing 1–12 of 23 resources

Template Popular

Cybersecurity Psychological Safety Policy Template

11 Nov 2025

A cybersecurity psychological safety policy is designed to create an environment where employees feel safe to report incidents, raise...

Whitepaper Popular

Beyond the Checkbox: Evolving from Awareness to a Resilient Security Culture

25 Apr 2025

This whitepaper explores the critical journey organisations must undertake to evolve from basic cybersecurity awareness programmes toward embedding secure behaviours and cultivating a mature security culture.

Guide Popular

A Guide to Embedding Psychological Safety in Cybersecurity Culture

17 Apr 2025

This guide explores why psychological safety matters in cybersecurity, how it supports human risk management, and provides a practical step-by-step approach for embedding it into organisational culture. Drawing on behavioural science and cultural change principles, it offers actionable insights for leaders, managers, and security professionals seeking to reduce human cyber risk and create a more open, resilient, and secure workplace.

Toolkit Popular

Practitioner Toolkit Guide – Consolidated Framework for Implementation Research (CFIR)

11 Nov 2025

The Consolidated Framework for Implementation Research (CFIR) provides a robust and structured approach for embedding cybersecurity...

Checklist Popular

Security Champions - Programme Check List

11 Nov 2025

Editable template for Security Champions programme checklist.

Guide Popular

Human Risk Management Good Practice Guide

13 May 2025

Human behaviour has become both the most targeted vulnerability and the greatest potential defence in cybersecurity. The Human Risk Management Good Practice Guide provides a strategic, practical, and behaviourally grounded framework to help organisations identify, manage, and mitigate human cyber risk.

Whitepaper Popular

Leveraging Behavioural Science for Cybersecurity Strategy – Enhancing Cultural Maturity and Resilience

29 Apr 2024

In the rapidly evolving landscape of cybersecurity, technical defences alone are insufficient to protect organisations from threats. This...

Guide Popular

A Guide to Developing a Cybersecurity Strategy Using Behavioural Science

30 Apr 2025

Cybersecurity is not just about technology, it is also about the people who use it. Understanding and influencing human behaviour is essential to enhancing cybersecurity measures. The COM-B model, which stands for Capability, Opportunity, and Motivation, provides a robust framework for applying behavioural science to cybersecurity strategy development. This guide will walk you through the steps of using the COM-B model to craft a cybersecurity strategy that addresses both technological and huma

Toolkit Popular

Practitioner Toolkit Guide – Social Network Analysis (SNA)

11 Nov 2025

This guide introduces Social Network Analysis (SNA) as a practical tool for security professionals seeking to influence and embed secure...

Whitepaper Popular

Implementing the Behaviour Change Wheel for Enhanced Cybersecurity Strategies

20 May 2024

This white paper explores the application of the Behaviour Change Wheel (BCW), a systematic approach to understanding and influencing...

Whitepaper Popular

Enhancing Cybersecurity Culture through Dual Processing Theory (DPT) and Behavioural Interventions

24 Jun 2025

This white paper explores the application of Dual Processing Theory (DPT) in cybersecurity culture, emphasising the importance of transitioning employee responses to cyber threats from System 2 (deliberate and conscious) to System 1 (automatic and intuitive). It outlines how understanding DPT can enhance organisational defence mechanisms by creating behavioural interventions that simplify security processes, leverage nudges and prompts, and employ comprehensive training programs.

Toolkit Popular

Practitioner Toolkit Guide – Theoretical Domains Framework (TDF)

11 Nov 2025

This guide introduces cybersecurity professionals to the Theoretical Domains Framework (TDF), a comprehensive behavioural science model...

12 »
Books

Published works

Comprehensive guides on behavioural security and human cyber risk management. Each book offers practical, evidence-based strategies grounded in psychology, behavioural science, and real-world application.

Building a Cyber Security Culture
BCC
Strategic Guide
Building a Cyber Security Culture
A Strategic Guide to Protecting Your Business
Your comprehensive roadmap to creating a culture where every employee actively engages in security efforts - addressing the why and equipping you with the how to transform your weakest link into your strongest defence.
  • Global security landscape and challenges
  • Psychology driving security awareness
  • Culture, strategy, and security connection
  • Foundation for long-term resilience
Behaviour Change Playbook
BCP
Practical Guide
Behaviour Change Playbook
For Cyber Security
Your ultimate guide to transforming cybersecurity behaviours using proven behavioural science frameworks. Features the Behaviour Change Wheel with step-by-step implementation strategies.
  • BCW framework and behaviour change techniques
  • Real-world case studies included
  • Practical intervention design tools
  • Measurable outcomes and KPIs
DECEIVED
DCVd
Psychology Focus
DECEIVED
Why We Click, Trust, and Get Hacked
Explore the hidden psychological forces that make us vulnerable to cyberattacks. From phishing to AI-driven manipulation, learn how attackers exploit trust, fear, and urgency - and how to build psychological resilience.
  • Cognitive biases and cyber threats
  • Social engineering tactics exposed
  • AI and deepfake manipulation
  • Building psychological defences
The Rise of the Security Champion
RSC
People-First
The Rise of the Security Champion
From Awareness to Action
Unlock the untapped power of Security Champions - everyday employees transformed into security advocates. Your step-by-step guide to creating a Champions network that transforms your organisation's security posture.
  • Champion identification and recruitment
  • Practical frameworks and strategies
  • Measuring success and momentum
  • Human-first cybersecurity approach
SINGULARITY
SNGL
Future-Focused
SINGULARITY
Choosing Humanity's Future in the AI Age
A journey through the paradox of AI - from life-saving technology to sophisticated deception. Explore how Artificial Intelligence shapes our present and could redefine our future, with a roadmap for navigating this transformation wisely.
  • Current AI landscape and impact
  • Path to Artificial General Intelligence
  • Ethical AI and human responsibility
  • Preparing for technological singularity

Start with the Heroes platform

Put these tools and frameworks to work in your organisation.