Select Page

CybSafe book list: Books on the human aspect of cybersecurity, human risk management, security awareness, or security culture

CYBSAFE-SebDB Webinar-preblog-221011MS-36

12 March 2025

Below are a selection of books written by authors who specialise in the human aspect of cybersecurity. Some are progressive in their approach. Others, less so.

However, each book has some real gems and all provide incredible insights into the range of views, ideas and challenges in the field.

Recommended reading for anyone who wants to specialise in this field or deepen their expertise.

 

Social Engineering, the science of human hacking

Christopher Hadnagy

This book reveals the craftier side of the hacker’s repertoire―why hack into something when you could just ask for access? Undetectable by firewalls and antivirus software, social engineering relies on human fault to gain access to sensitive spaces.

You Can Stop Stupid – Stopping Losses from Accidental and Malicious Actions

Ira Wrinkler & Dr Tracy Celaya Brown

Using lessons from tested and proven disciplines like military kill-chain analysis, counterterrorism analysis, industrial safety programs, and more, Ira Winkler and Dr. Tracy Celaya’s You CAN Stop Stupid provides a methodology to analyze potential losses and determine appropriate countermeasures to implement.

Security Culture –  A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Hilary Walton

Hilary Walton combines her research and her unique work portfolio to provide proven security culture strategies with practical advice on their implementation. And she does so across the board: from management buy-in, employee development and motivation, right through to effective metrics for security culture activities.

People-Centric Security: Transforming Your Enterprise Security Culture 

Lance Hayden

This book addresses the urgent need for change at the intersection of people and security. Essentially a complete security culture toolkit, this comprehensive resource provides you with a blueprint for assessing, designing, building, and maintaining human firewalls.

Security Awareness Program Builder

Mark Majewski

This book defines a common framework for building a broad awareness program using the Train, Reinforce, Assess and Manage (TRAM) model. It includes specific advice and examples for activities across the TRAM functions. This book is filled with examples of deliverables an awareness professional can leverage in their program.

Building a Cybersecurity Culture: A Strategic Guide to Protecting Your Business

Andy Wood

This essential resource begins with a call to empowerment, encouraging you to embrace a security-first mindset that will permeate your organisation. Within these pages, you will explore the complex landscape of global security challenges and gain valuable insights into the psychology that drives security awareness and behaviour. This book addresses the ‘why’ and equips you with the ‘how’.

Security Awareness For Dummies

Ira Wrinkler

Written by one of the world’s most influential security professionals—and an Information Systems Security Association Hall of Famer—this pragmatic and easy-to-follow book provides a framework for creating new and highly effective awareness programs from scratch, as well as steps to take to improve on existing ones. It also covers how to measure and evaluate the success of your program and highlight its value to management.

The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer

Perry Carpenter & Kai Roer

The Security Culture Playbook, Perry Carpenter and Kai Roer, two veteran cybersecurity strategists deliver experience-driven, actionable insights into how to transform your organization’s security culture and reduce human risk at every level.

The Cybersecurity Playbook: How Every Leader and Employee Can Contribute to a Culture of Security

Allison Cerra

Drawing from her experience as CMO of one of the world’s largest cybersecurity companies, author Allison Cerra incorporates straightforward assessments, adaptable action plans, and many current examples to provide practical recommendations for cybersecurity policies.

The Weakest Link: How to Diagnose, Detect, and Defend Users from Phishing

Arun Vishwanath

Cybersecurity expert Arun Vishwanath offers a new, evidence-based approach for detecting and defending against phishing–an approach that doesn’t rely on continual training and retraining but provides a way to diagnose user vulnerability.

Vishwanath explains how organizations can build a culture of cyber safety. He presents a Cyber Risk Survey (CRS) to help managers understand which users are at risk and why.

Cybersecurity ABCs: Delivering awareness, behaviours and culture change

Jessica Barker, Adrian Davis, Bruce Hallas & Ciaran Mc Mahon

Cyber Security ABCs, by Dr. Jessica Barker, Adrian Davis, Bruce Hallas & Ciaran Mc Mahon presents a practical, engaging guide to fostering security-conscious behaviors across all levels of an organization. Through clear, accessible advice, it helps leaders deliver effective cybersecurity strategies focused on changing human behavior to enhance overall security resilience.

Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors

Perry Carpenter

Transformational Security Awareness, by Perry Carpenter, combines neuroscience and storytelling to revolutionize how organizations approach security awareness. This book offers a compelling framework for creating security programs that go beyond traditional methods, leveraging the power of human psychology to foster lasting behavior change and a deeper understanding of security risks.

The Psychology of Information Security

Leron Zinatullin

The Psychology of Information Security, by Leron Zinatullin, explores the human aspects of cybersecurity, offering strategies to align security measures with the way people think and behave. Drawing on psychological principles, the book provides actionable insights on how to design security programs that not only protect systems but also resonate with users, minimizing friction and maximizing adoption. Through a mix of theory and practical advice, it helps organizations foster a security-conscious culture.

Humans and Cyber Security: How Organisations Can Enhance Resilience Through Human Factors

Amanda Widdowson

Humans and Cyber Security: How Organisations Can Enhance Resilience Through Human Factors, by Amanda Widdowson, examines the role of human factors in cyber security, shifting the focus from individual errors to organizational root causes. The book explores why undesirable security behaviors occur and how to mitigate them by improving organizational practices rather than attempting to change individual behavior. It introduces behavioral models, discusses individual and organizational vulnerabilities, and provides practical strategies for reducing human-related cyber risks.

Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

“Humans are the weakest link.”“Security Awareness training = better behaviour”"If we can nail engagement, we’ll nail risk reduction.""Security Awareness is *actually* about so much more than awareness.”“Security culture is the golden ticket to risk reduction.”“Good communication, messaging,...

Can BS make SA&T stick? Hot takes from the experts…

Can BS make SA&T stick? Hot takes from the experts…

Using insights from “Oh, Behave!” to strengthen security training and drive lasting behavioral change Security training. It’s as commonplace in an organization as writing “see attached” and forgetting to attach anything. It can help to tackle cybersecurity risks—but only when done well. Simply...

Maximizing security awareness engagement: How the pros do it

Maximizing security awareness engagement: How the pros do it

Ditch mandatory training, starting riiiight…now!Want to boost security awareness? Talk about something else entirelyGet serious about funThe top mic-drop insights from our Cybersecurity Awareness Month engagement webinar We know people whose organizations make a big deal of CAM are much more...