I don't mean a game in the trivial sense. I mean it in the formal sense that mathematicians and economists have used for eighty years: a situation where the outcome for each person depends not only on what they do, but on what everyone else does too. Once you see security behaviour through that lens, many stubborn problems suddenly make sense. And a few of the standard remedies start to look like they were never going to work.
The rational actor who never turns up
Game theory began in the 1940s with John von Neumann and Oskar Morgenstern as a branch of mathematics. It assumed perfectly rational players who calculate payoffs and choose the option that maximises their own return. On paper, this produces elegant predictions. In the laboratory, humans ignore them.
The best-known demonstration is the Ultimatum Game. One player is given a sum of money, say £100, and offers a split to a second player. If the second player accepts, both keep their shares. If they reject, both get nothing. Pure rationality says accept any offer above zero, because something beats nothing. Real people consistently reject offers below roughly 30 per cent across cultures. They will pay real money to punish what they perceive as unfairness.
That finding, and hundreds like it, gave rise to behavioural game theory. Researchers such as Colin Camerer, Ernst Fehr, and Simon Gächter showed that people bring fairness, reciprocity, and social comparison into every strategic decision. We are not rational maximisers. We are conditional cooperators. We contribute when we believe others are contributing, and we withdraw when we suspect we are being taken for a ride.
Hold that thought, because it describes your workforce precisely.
Security is a public goods problem
The public goods game works like this. Everyone in a group can contribute to a shared pot. The pot is multiplied and split equally among all members, whether or not they contributed. The group does best when everyone contributes. Each individual does best by contributing nothing and enjoying the multiplied returns of everyone else's effort.
Now replace the pot with organisational security. Every employee who reports a phishing email, challenges a tailgater, uses a password manager, or takes the extra thirty seconds to verify a payment request is contributing to a shared asset: the organisation's resilience. The benefit is collective. The cost is individual. Every one of those behaviours takes time, attention, or social discomfort from the person performing it, while the protection it generates is spread across thousands of colleagues who will never know it happened.
That is a textbook public goods structure, and the experimental literature tells us exactly what happens in these games over repeated rounds. Cooperation starts at a reasonably high level, then decays. People look around, conclude that others are free-riding, feel foolish for contributing, and stop. By the final rounds, contributions collapse towards zero.
Sound familiar? It should. It is the standard trajectory of a security awareness programme. Launch enthusiasm, gradual disengagement, eventual quiet cynicism. We tend to blame apathy or poor content. The game structure predicts the decay regardless of content quality, because the problem is not what people know. It is what they believe everyone else is doing.
Shadow IT is a defection strategy, not a knowledge gap
Look at shadow IT through the same lens. An employee who spins up an unsanctioned file-sharing tool is not confused about policy. They have run the payoff calculation. The sanctioned route costs them time and friction today. The risk they create is diffuse, delayed, and borne mostly by others. Defecting is individually rational even when it is collectively damaging.
This matters because it changes the intervention. If shadow IT were a knowledge gap, more training would fix it. It isn't, so it doesn't. Seventeen years of watching awareness programmes fail to move this needle convinced me of that long before I could name the mechanism. You do not talk someone out of a dominant strategy. You change the payoffs, or you change what they believe about how others are playing.
What champions actually do
This is where Security Champions Networks earn their place, and why I think most explanations of their success miss the real mechanism.
The conventional account says champions work because they translate security into local language and extend the security team's reach. Both true, both secondary. When I built a network of 550 champions at Capita over 18 months, the most powerful effect was not the transfer of information. It was that champions made cooperation visible.
The public goods experiments contain a striking result. Cooperation decays in standard play, but when researchers introduce ways for players to see that others are contributing, or to sanction free riders, contributions stabilise and often rise. Fehr and Gächter's punishment experiments showed groups sustaining near full cooperation over many rounds once defection carried a visible social cost. The decisive variable is not knowledge of the rules. It is evidence about other players.
A champion in a team of forty is exactly that evidence. Every time they report a phish and mention it, challenge a risky shortcut in a stand-up, or normalise asking the security question, they are broadcasting a signal: people here contribute. Conditional cooperators, which is most of us, respond to that signal by contributing too. The champion is not primarily a teacher. They are a payoff modifier and a proof of cooperation, embedded where the game is actually played.
That reframing also explains a pattern every network operator recognises: coverage matters more than expertise. A moderately knowledgeable champion within a team outperforms a brilliant one broadcasting from the centre because the signalling effect only works locally, within the group whose behaviour you want to shift.
Designing the game, not the message
If security behaviour is a repeated game, then culture programmes should be judged as game design rather than communication. A few practical tests fall out of this.
First, ask what your programme does to visible cooperation. Phishing reporting numbers locked inside a security dashboard change nothing. The same numbers shared back to teams, with recognition attached, are a cooperation signal. The data is identical. The game effect is completely different.
Second, audit the payoff matrix honestly. If reporting an incident triggers a bureaucratic ordeal, you have priced honesty out of the game, and no poster campaign will buy it back. If the secure path is slower than the insecure one, you have made defection the dominant strategy and then blamed players for finding it.
Third, treat punishment with care. The experiments show sanctions sustain cooperation, but they also show antisocial punishment and spite when sanctions feel arbitrary. Naming and shaming phishing simulation clickers is exactly the arbitrary variety. Peer-level social accountability- the raised eyebrow from a respected colleague-works far better than centrally administered humiliation, and champions supply it naturally.
Fourth, expect decay and design against it. Conditional cooperation needs continuous evidence. A champions network is not a launch activity. It is the standing infrastructure that keeps broadcasting the signal round after round.
The measurement implication
There is a measurement consequence, too, and it runs counter to most human risk scoring on the market. If behaviour is strategic and interdependent, then measuring individuals in isolation misses the mechanism entirely. The unit of analysis should be the group: contribution rates, the visibility of cooperation within teams, the local presence of champions, the speed at which cooperation recovers after an incident. An individual risk score treats each employee as a lone decision maker. The game theory says no such person exists.
None of this replaces the behavioural science we already use. COM-B still describes what any individual needs to act. Game theory adds the layer above it: why capable, motivated people with every opportunity still choose not to, and what changes their minds. The answer, in the end, is other people. It always was.