I enjoyed talking to students completing their Global MBA and MSc in Digital Transformation with the University of Hull Online about human-centered approaches to cyber security.
My lecture helped reinforce the idea that cyber security is a socio-technical challenge that has deep behavioural contingencies.
Cyber is a business risk and I’m glad it’s increasingly featured in business degree curriculums beyond computer science. My book, the Psychology of Information Security, helps bridge the gap between organisational and cyber strategy.
For about a decade, our industry has had a favourite phrase: people are the weakest link. I made the opposite case – that the people we’ve been blaming are the most capable security asset we have, and we’ve spent that decade building systems that fight them instead of fit them.
The talk covered why training and punishment don’t work, why every workaround is actually free user research, and how you design your way to secure behaviour by making the secure path the easy path. And of course, where AI fits into all of it.
A day of sessions on AI in the SOC, OT resilience, fragmenting regulation and machine-speed response.
We build systems that assume the human in the loop has steady attention and reliable judgement. Neither is true, and it is getting less true. Every alert, prompt, exception, and “are you sure?” draws from the same depleting account. By afternoon, the analyst approving a transfer, the engineer waving through a change and the executive clicking an MFA push are all running on the same low battery.
AI does not solve this. It compresses the timeline and raises the stakes of each remaining human decision. The questions we still hand to people – is this normal? do I trust this? should I escalate? – are exactly the ones tiredness destroys first.
You cannot train your way out of the fact that attention runs out. It is a design problem. That’s precisely what I discuss in The Psychology of Information Security.
One of the UK’s leading research-intensive universities has selected the second edition of The Psychology of Information Security to be included in their flagship Information Security programme as part of their ongoing collaboration with industry professionals.
“We incorporated The Psychology of Information Security into our MSc in Information Security, where it has become part of the essential reading for the Human Aspects of Security and Privacy module. Over time, it has proven to be a valuable anchor text within the curriculum, helping to frame discussions around the human dimensions of cybersecurity in a structured and coherent way.
Students consistently appreciate the perspectives it offers, particularly its ability to bridge academic research with real-world industry practice. It not only provides a clear roadmap through a complex and wide-ranging topic, but also encourages a broad understanding of the psychological principles underpinning everyday security challenges.”
Dr Konstantinos Mersinas, PhD, CISSP
Associate Professor, Information Security Group, Royal Holloway, University of London
Visiting Professor, Keio University Tokyo, Japan 特別 招聘 准教授 慶応 大学 東京 日本
Director of Distance Learning MSc Programme in Information Security
Vice Chair, INCS-CoE (International Cyber Security Center of Excellence)
Excited that my book just hit #1 on Amazon’s bestseller list. Thank you to everyone who read, recommended, reviewed and supported this project – I couldn’t have done it without you. If you’ve read it, I’d love to hear what resonated most.
If you haven’t read it – it’s currently on offer in some Amazon stores, so get your 23% discount while you can!
And yes – it’s technically #1 in the very specific category, which is slightly amusing… I suspect it’s a hit with late-night cyber security enthusiasts rather than beach readers!
Security failures are rarely a technology problem alone. They’re socio-technical failures: mismatches between how controls are designed and how people actually work under pressure. If you want resilient organisations, start by redesigning security so it fits human cognition, incentives and workflows. Then measure and improve it.
Think like a behavioural engineer
Apply simple behavioural-science tools to reduce errors and increase adoption:
Defaults beat persuasion. Make the secure choice the path of least resistance: automatic updates, default multi-factor authentication, managed device profiles, single sign-on with conditional access. Defaults change behaviour at scale without relying on willpower.
Reduce friction where it matters. Map high-risk workflows (sales demos, incident response, customer support) and remove unnecessary steps that push people toward risky workarounds (like using unapproved software). Where friction is unavoidable, provide fast, well-documented alternatives.
Nudge, don’t nag. Use contextual micro-prompts (like in-app reminders) at the moment of decision rather than one-off training. Framing matters: emphasise how a control helps the person do their job, not just what it prevents.
Commitment and incentives. Encourage teams to publicly adopt small security commitments (e.g. “we report suspicious emails”) and recognise them. Social proof is powerful – people emulate peers more than policies.
Build trust, not fear
A reporting culture requires psychological safety.
Adopt blameless post-incident reviews for honest mistakes; separate malice investigations from learning reviews.
Be transparent: explain why rules exist, how they are enforced and what happens after a report.
Lead by example: executives and managers must follow the rules visibly. Norms are set from the top.
Practical programme components
Security champion network. One trained representative per team. Responsibilities: localising guidance, triaging near-misses and feeding back usability problems to the security team.
Lightweight feedback loops. Short surveys, near-miss logs and regular champion roundtables to capture usability issues and unearth workarounds.
Measure what matters. Track metrics tied to risk and behaviour.
Metrics that inform action (not vanity)
Stop counting clicks and start tracking signals that show cultural change and risk reduction:
Reporting latency: median time from detection to report. Increasing latency can indicate reduced psychological safety (fear of blame), friction in the reporting path (hard-to-find button) or gaps in frontline detection capability. A drop in latency after a campaign usually signals improved awareness or lowered friction.
Always interpret in context: rising near-miss reports with falling latency can be positive (visibility improving). Review volume and type alongside latency before deciding.
Inquiries rate: median number of proactive security inquiries (help requests, pre-deployment checks, risk questions). An increase usually signals growing trust and willingness to engage with security; a sustained fall may indicate rising friction, unresponsiveness or fear.
If rate rises sharply with no matching incident reduction, validate whether confusion is driving questions (update docs) or whether new features need security approvals (streamline process).
Confidence and impact: employees’ reported confidence to perform required security tasks (backups, secure file sharing, suspicious email reporting) and their belief that those actions produce practical organisational outcomes (risk reduction, follow-up action, leadership support).
An increase may signal stronger capability and perceived efficacy of security actions. While a decrease indicates skills gaps, tooling or access friction or perception that actions don’t lead to change.
Metrics should prompt decisions (e.g., simplify guidance if dwell time on key security pages is low, fund an automated patching project if mean time to remediate is unacceptable), not decorate slide decks.
Experiment, measure, repeat
Treat culture change like product development: hypothesis → experiment → measure → adjust. Run small pilots (one business unit, one workflow), measure impact on behaviour and operational outcomes, then scale the successful patterns.
Things you can try this month
Map 3 high-risk workflows and design safer fast paths.
Stand up a security champion pilot in two teams.
Change one reporting process to be blameless and measure reporting latency.
Implement or verify secure defaults for identity and patching.
Define 3 meaningful metrics and publish baseline values.
When security becomes the way people naturally work, supported by defaults, fast safe paths and a culture that rewards reporting and improvement, it stops being an obstacle and becomes an enabler. That’s the real return on investment: fewer crises, faster recovery and the confidence to innovate securely.
If you’d like to learn more, check out the second edition of The Psychology of Information Security for more practical guidance on building a positive security culture.
I’m thrilled to share that I’ve recently earned the GIAC Strategic Planning, Policy, and Leadership (GSTRT) certification- a milestone that validates my ability to architect and sustain cybersecurity programs with a sharp focus on business value and executive alignment.
The festive period can bring joy, but it can also be a time of loneliness and stress, which is why it’s so important to check in with ourselves and others.
One way I’ve had the chance to contribute is through volunteering as a telephone crisis supporter with Lifeline Australia. I’ve been answering calls from people who may be facing one of the toughest moments of their lives. Every conversation reinforces the power of simply being there for someone when they need it most.
One of the most moving parts of this role is hearing the shift in a caller’s voice – from distress to a sense of calm – because they feel heard, supported and not alone. It’s a small moment that can make a big difference.
As we head into the holidays, remember that you’re not alone either. If you’re struggling, reach out – whether to a friend, family member or a service like Lifeline. And if you’re looking for a meaningful way to give back, I can’t recommend volunteering with Lifeline enough. It’s been one of the most rewarding experiences of my life.
Take care of yourself and those around you this holiday season. Let’s make kindness, connection and understanding the greatest gifts we give.