Service

Human Factors in Cybersecurity

Most breaches begin with a person doing something reasonable under pressure. Treating that as a training failure misses the point. It is usually a design failure, and it is fixable.

Three colleagues talking through a document together

The people side is not the soft side

Organisations invest heavily in technical controls and then rely on annual training to cover everything those controls cannot. The result is predictable. The control set is strong and the behaviour around it is weak.

The framing matters here. Staff who click a link, reuse a password or route around a control are almost never being careless. They are resolving a conflict between the secure path and the path that lets them do their job today. Whichever is easier will win, reliably, and no amount of reminding changes that.

What Kairos actually does

Work in this area starts with where the secure path and the practical path diverge, because that gap is where incidents come from. Finding it means asking people what they actually do rather than what policy says they should.

From there it moves to the conditions that produce good decisions: whether reporting a mistake is safe enough that people do it early, whether security is reachable when someone is unsure, whether the secure route is genuinely the easiest one, and whether leadership behaviour matches the policy.

Awareness programmes are part of this but they are the smallest part. A programme that raises anxiety without changing what is easy will not change outcomes.

Culture, measured honestly

Phishing click rates are easy to measure and easy to game, and on their own they tell you very little. More telling is how quickly people report, whether they report at all when they think they made a mistake, and whether anyone routes around a control because it is unworkable.

Those signals are harder to collect and considerably more useful, because they describe the organisation as it actually operates.

Who this is for

  • Security leaders whose technical controls outpace their culture
  • Organisations that keep seeing the same class of incident
  • Companies where near misses are found late or not reported
  • Leadership teams who want an honest read on security behaviour

How an engagement starts

Start with a conversation about the incidents and near misses you keep seeing. Patterns usually point at a specific gap between policy and practice. Where a specialist in the Collective is better suited, we will introduce them rather than take the work.

Advisory on the people side of security — awareness, culture and behaviour — because most breaches start with a person, not just a system.

FAQ

Questions about Human Factors in Cybersecurity

What are human factors in cybersecurity?

The people side of security: awareness, culture and behaviour. It covers why people make the decisions they do under real working conditions, and treats the gap between the secure path and the practical path as a design problem rather than a training failure.

Is this the same as security awareness training?

No. Awareness training is one part of it and the smallest part. A programme that raises anxiety without changing what is easy will not change outcomes. The work focuses on making the secure route the easiest route and on the conditions that produce good decisions.

How should security culture be measured?

Phishing click rates are easy to measure and easy to game. More telling is how quickly people report, whether they report at all when they believe they made a mistake, and whether anyone routes around a control because it is unworkable in practice.

Not sure this is the one you need?

Sometimes all a business needs is one good introduction. Tell us what you are working on and we will point you at the right part of the Collective.

Make an introduction (opens WhatsApp)