Everything you need to understand, measure, and improve the human dimensions of your organisation's security posture.
Practical tools you can use right now to assess, plan, and improve.
A structured assessment of your organisation's cyber resilience posture. Understand where you stand, identify gaps, and get a prioritised improvement roadmap grounded in behavioural risk principles.
Take the assessment →Map out your Security Champions programme timeline, milestones, and key actions. An interactive planning tool to help you structure your programme from launch to maturity - with progress tracking.
Plan your journey →The Behavioural Cyber Risk Management Skills Framework - 7 domains, 30 competencies, 8 professional roles. Select your role to see your recommended target competency levels.
Explore framework →CyBehave's emerging research body investigating whether established human behavioural science frameworks can be meaningfully extended to understand, predict, and govern AI agent behaviour in cybersecurity contexts.
Explore the research →Research summaries and practical perspectives on the intersection of behavioural science and cybersecurity from the CyBehave research programme.
Read insights →Practical advice, expert perspectives, and applied guides on building security culture, managing human risk, and running effective Champions programmes.
Read articles →Guides, whitepapers, templates, and practical tools grounded in behavioural science and real-world security practice.
Showing 1–12 of 23 resources
A cybersecurity psychological safety policy is designed to create an environment where employees feel safe to report incidents, raise...
This whitepaper explores the critical journey organisations must undertake to evolve from basic cybersecurity awareness programmes toward embedding secure behaviours and cultivating a mature security culture.
This guide explores why psychological safety matters in cybersecurity, how it supports human risk management, and provides a practical step-by-step approach for embedding it into organisational culture. Drawing on behavioural science and cultural change principles, it offers actionable insights for leaders, managers, and security professionals seeking to reduce human cyber risk and create a more open, resilient, and secure workplace.
The Consolidated Framework for Implementation Research (CFIR) provides a robust and structured approach for embedding cybersecurity...
Editable template for Security Champions programme checklist.
Human behaviour has become both the most targeted vulnerability and the greatest potential defence in cybersecurity. The Human Risk Management Good Practice Guide provides a strategic, practical, and behaviourally grounded framework to help organisations identify, manage, and mitigate human cyber risk.
In the rapidly evolving landscape of cybersecurity, technical defences alone are insufficient to protect organisations from threats. This...
Cybersecurity is not just about technology, it is also about the people who use it. Understanding and influencing human behaviour is essential to enhancing cybersecurity measures. The COM-B model, which stands for Capability, Opportunity, and Motivation, provides a robust framework for applying behavioural science to cybersecurity strategy development. This guide will walk you through the steps of using the COM-B model to craft a cybersecurity strategy that addresses both technological and huma
This guide introduces Social Network Analysis (SNA) as a practical tool for security professionals seeking to influence and embed secure...
This white paper explores the application of the Behaviour Change Wheel (BCW), a systematic approach to understanding and influencing...
This white paper explores the application of Dual Processing Theory (DPT) in cybersecurity culture, emphasising the importance of transitioning employee responses to cyber threats from System 2 (deliberate and conscious) to System 1 (automatic and intuitive). It outlines how understanding DPT can enhance organisational defence mechanisms by creating behavioural interventions that simplify security processes, leverage nudges and prompts, and employ comprehensive training programs.
This guide introduces cybersecurity professionals to the Theoretical Domains Framework (TDF), a comprehensive behavioural science model...
Comprehensive guides on behavioural security and human cyber risk management. Each book offers practical, evidence-based strategies grounded in psychology, behavioural science, and real-world application.
Put these tools and frameworks to work in your organisation.