For thirty years the industry has bought engineering for its machines and posters for its people. CyBehave exists because the science says we can do far better. Behavioural science, psychology and anthropology hold real, tested answers to why people behave the way they do around security, and our job is to turn that research, and our own, into things practitioners can actually use.
Most successful attacks do not break the technology. They borrow a person's trust, attention or haste, and walk in through the front door. Social engineeringAny attack that manipulates a person rather than a machine: a fake invoice, an urgent call pretending to be the IT desk, an email that looks exactly like it came from your boss. works because attackers have spent decades studying how people actually make decisions: quickly, under pressure, using mental shortcuts that serve us well almost everywhere else[2,3].
Psychologists describe two modes of thinking: a fast, automatic mode that runs most of our day, and a slow, deliberate mode we reserve for hard problems[3]. Phishing, payment fraud and pretexting are engineered to catch people in the fast mode: urgency, authority, familiarity, a deadline. The attacker's real target is not the inbox. It is the split second before a decision.
This is why security is a human science as much as a technical one. If attackers exploit psychology with rigour, defenders cannot answer with intuition and a poster. The good news is that the research exists, it is deep, and it is improving all the time.
Walk into almost any security conference and you will hear that humans are the weakest link, or that staff must become a human firewall. Both phrases feel intuitive, and both point the finger in the wrong direction. The research pushing back on this is not new: in 1999, one of the founding papers of the field argued that users behave insecurely largely because security is designed without them in mind, and that treating them as the enemy makes things worse[4]. Follow-up work showed the so-called weakest link could be transformed by fixing the design rather than blaming the person[5].
The most striking finding in this literature is that ignoring security advice is often rational. When researchers added up the daily cost of following every rule against the harm those rules actually prevent, the ledger frequently favoured the person who cut corners[7]. People are not careless. They are economists of their own time, and badly designed security asks them to pay constantly for benefits they never see.
Employees hold a finite reserve of time and effort for security: the compliance budgetThe limited amount of effort people will spend on security before they start cutting corners. Every rule, prompt and training module draws it down, and asking harder does not refill it.. Every extra rule spends it. When it runs out, corners get cut, however motivated the person[8].
Security fatigueA measurable state of weariness from constant security demands: too many passwords, warnings and decisions. Fatigued people make worse security choices, not because they care less but because they are exhausted. is a documented state, not an excuse. People bombarded with warnings and demands eventually disengage, and their decision quality drops with them[9].
Where official security blocks the job, people invent shadow securityThe unofficial workarounds people create when official security gets in the way of their work: shared logins, files emailed home, sticky notes. Invisible to compliance reports, but it shows how work really gets done.. Those workarounds are not disobedience. They are the most honest data an organisation has about where its security does not fit the work[10].
The modern research consensus reframes the question entirely: from human-as-problem to human-as-solution.
The direction of travel in the field, set out in Zimmermann and Renaud's 2019 review[6]The awareness era rested on a simple assumption: tell people about the risk and behaviour will follow. Psychology has tested that assumption to destruction. The gap between what people intend to do and what they actually do is one of the most reliable findings in behavioural science: across hundreds of studies, intentions explain only a modest fraction of behaviour[12]. Researchers call it the intention–behaviour gapThe well-documented distance between meaning to do something and doing it. Most people intend to eat well, save money and use unique passwords. Intention alone rarely survives contact with a busy day., and everyone who has ever owned an unused gym membership already understands it.
Security awareness campaigns run straight into this gap. Reviews of why they fail keep finding the same pattern: information transfers, behaviour does not, because the campaign never touched the environment, the habits or the social pressures that actually govern what people do at the moment of decision[11].
None of this means awareness is worthless. It means awareness is an ingredient, not a recipe. People do need to know what a payment diversion attempt looks like. But knowledge only becomes protection when the environment makes the secure action easy, the team around you treats it as normal, and doing it is quicker than not doing it. That is the territory of behavioural science, and it is where the awareness era ends and something better begins.
Here is the uncomfortable part, and the part most vendors skip. The best behavioural change frameworks were not built for cybersecurity. The COM-B model and Behaviour Change Wheel, the most rigorous tools the field has, were developed for health: helping people stop smoking, take medication, exercise[13]. They are superb instruments. But lifting them into security like for like quietly imports assumptions that do not hold, and a science-led approach has to be honest about that.
In health, the behaviour serves the person's own goal: their body, their life. In organisations, security is a secondary taskSomething you must do on the way to your real goal. Nobody opens their laptop to do security; they open it to close a deal or treat a patient. Security competes for attention with the actual job. that competes with the actual work, drawing on the same limited budget of effort[8]. A framework built for primary goals needs rethinking when the goal is secondary.
Stop smoking and you feel better, save money, watch the evidence accumulate. Do security well and nothing happens. The breach that never occurred provides no feedback, no reward, no visible proof the effort was worth it. Behaviour without feedback is behaviour that fades, so the feedback must be engineered in deliberately.
Health promotion can sell a positive future. Security asks people to work continuously to prevent rare, abstract harms that may never happen to them, and its natural register is fear. Fear-based messaging is one of the best-studied ways to get behaviour change wrong, which is why it needs careful, evidence-led handling rather than louder warnings.
A virus does not read your public health campaign and redesign itself. Attackers do. Every improvement in defensive behaviour is studied and countered by an intelligent adversary, which means security behaviour change is never finished, only maintained against a moving opponent.
This is why CyBehave translates and tests rather than transplants. We start from the established frameworks because they are the best science available, then adapt them for a domain where the task is secondary, the payoff is invisible, the framing is negative and the adversary fights back. That adaptation work, including our own research and our own technique taxonomy built specifically for security contexts, is the substance of what we do.
Psychology explains the individual decision. Anthropology explains everything around it. Decades of anthropological work on risk shows that what a community treats as dangerous is not a neutral calculation but a cultural choice: different groups, with the same facts available, genuinely fear different things[14]. Organisations are no different. Every company is a set of tribes with their own rituals, folklore and unwritten rules, and those rules, not the policy document, decide what people actually do[15].
Look at any team through an anthropologist's eyes and the real security culture appears quickly. Whether anyone locks their screen when leaving a desk. What happens, socially, to the person who reports a mistake. Whether verifying a request from a senior leader is treated as diligence or insubordination. Researchers who study organisations this way, through ethnographyThe anthropologist's method: observing what people actually do in their natural setting, rather than what they say they do in a survey. The gap between the two is usually where the interesting findings live. rather than surveys alone, consistently find that observed practice and official policy are two different worlds[10,15].
Culture also cannot be installed. The research is blunt on this: an organisation's security culture is the accumulated output of what it repeatedly does, rewards and tolerates, which means it is earned through practice, never declared in a memo[16]. This is precisely why Security Champions matter. A champion is not a messenger for the security team; they are a trusted insider of the tribe, able to shift what feels normal from within in a way no central function ever can. It is applied anthropology, and it is the most culturally literate tool a security programme has.
We will not pretend this field is finished, because it is not. Behavioural cybersecurity is a young discipline. Some findings are robust and replicated; others rest on small studies that have not yet survived contact with real organisations. Measuring behaviour honestly is hard, measuring culture harder still, and anyone promising a solved formula is selling certainty the science does not yet support. There is a long way to go, and saying so out loud is part of being science-led.
CyBehave's role in that journey is translation. We read the research so practitioners do not have to, run our own studies where the literature is thin, and publish what we learn through our articles and guidance. Then we build the findings into tools that working security teams can pick up on a busy Tuesday: practical, plain-language, and honest about their evidence base. Science that stays in the journal changes nothing.
And the frontier is moving again. As organisations hand real tasks to agentic AIAI systems that do not just answer questions but take actions: sending emails, running processes, making decisions with limited human oversight. Their behaviour, like human behaviour, can drift from what was intended., behavioural risk stops being an exclusively human question. The analytical discipline transfers: just as we ask what drives a person's behaviour, we now must ask what drives an AI agent's, and how to govern both together.
Driven by intentions, motivations, mental shortcuts, social pressures and capability gaps. Understood through behavioural science and anthropology, and shaped through culture, environment and design.
Driven by objectives, reward signals, training data and emergent behaviour. An evolving area CyBehave is actively researching, applying the same analytical discipline used for human risk.
Everything above is grounded in published work. Read the originals; they are worth your time.
Six stages, every one grounded in the research above, built to make behavioural change practical for working security teams. Specify, Hypothesise, Intervene, Embed, Learn, Diffuse.