CYBSAFE LABS

We don't just believe in evidence. We build with it

We invest in science, research and the evidence base because our mission goes beyond our product: to end the guesswork in human security.

Science and Research team
Every nudge, every workflow, every line of code at CybSafe is grounded in data, tested hypotheses and continuous learning. When human behaviour is the risk, guesswork isn't just ineffective, it's irresponsible.

Behind that is CybSafe's dedicated Science and Research team. Our researchers come from psychology, cybersecurity and computing, with more than two decades of designing and delivering behaviour change between them. They use behavioural science, cyberpsychology, data analytics and AI, including generative AI and large language models, to change how organisations approach human risk.

Hundreds of companies sell human risk and secure behaviour management tools. Few have a team of scientists advancing the field itself, and using AI responsibly to do it.
OUR PRINCIPLES

Our work

Understanding the science of human behaviour is key to reshaping how organisations approach the human aspect of cybersecurity. Our research and innovation rest on four principles:

Rooted in psychology
We apply proven insights from behavioural science to change how people act, not just what they know.
AI, used responsibly
We use AI and large language models to move the field forward, and we measure their accuracy as carefully as anything else we test.
Scientifically tested
We test what changes behaviour, and why, so nothing rests on assumption.
People-centric
We help people be productive and secure at work, never one at the expense of the other.
PARTNERSHIPS

Research collaborations

We build our product through research, and collaborations with academic partners at universities including Bath, Bristol, Cardiff, Kent and Northumbria. The aim is the best product we can make, and a real contribution to academic knowledge and government policy.

Cybersecurity is a wicked problem. Nobody solves it alone, so we work with universities, funders and government to keep people, businesses and nations safe online.

Selected projects

CRANE

CRANE is a new EPSRC-funded network to strengthen the UK’s cybersecurity research ecosystem. It will evaluate new technologies and threats, and opportunities for novel research to bring tangible security interventions. Read more about the project here.

REPHRAIN

Researchers in Computer Science, International Relations, Law, Psychology, Management, Design, Digital Humanities, Public Policy, Political Science, Criminology and Sociology at Bristol (lead), University College London, Bath, King’s College London  and Edinburgh have teamed up to lead an £8.6 million three-year UKRI Research Centre of Excellence focussed on the protection of citizens online. This activity is designed to build and lead the UK’s world-leading interdisciplinary community on this mission and provide a clear single front door to engage and build capacity with government, industry and citizens. Read more about the project here.

EPSRC CDT in Cyber Secure Everywhere: Resilience in a World of Disappearing System Boundaries

The Centre for Doctoral Training (CDT) 'Cyber Secure Everywhere: Resilience in a World of Disappearing System Boundaries' will train at least 50 new doctoral-level graduates to address national cybersecurity capability gaps. It will do this by educating PhD students in both the technical skills needed to study and analyse blended infrastructures, while simultaneously training them to understand the challenges as fundamentally human too. The training involves close involvement with industry and practitioners who have played a key role in co-creating the programme. Read more about the project here.

Cyber Security Quirks

Cyber Security Quirks is funded by the Home Office and part of the Research Institute in Sociotechnical Cyber Security. The project explores the role of personalisation in cybersecurity behaviour interventions by taking account of individual variability.

SPEC

Simulated Phishing and Employee Cyber security behaviour (SPEC) is led by CybSafe in conjunction with the University of Bath. Funded by the Centre for Research and Evidence on Security Threats the project explores the impact of simulated phishing emails on employee awareness and work-based outcomes such as productivity and trust. Read more about the project here.

PHISHTRAY

PHISHTRAY is a modifiable open source e-tray software for research and training applications related to social engineering for use in academia and industry. Funded by CPNI and developed by behavioural scientists from the University of Bath and University of Bristol in conjunction with CybSafe.

AP4L

AP4L is a 3-year programme of interdisciplinary research, centring on the online privacy & vulnerability challenges that people face when going through major life transitions. Our central goal is to develop privacy-by-design technologies to protect & empower people during these transitions.

CREST

CybSafe is an associate partner of the Centre for Research and Evidence on Security Threats a national hub delivering world-class, interdisciplinary portfolio of activity maximising the value of behavioural and social science research to understanding, mitigating and countering threats to national security.

PETRAS

The PETRAS Internet of Things Research Hub is a consortium of nine leading UK universities which explore critical issues in privacy, ethics, trust, reliability, acceptability, and security related to Internet of Things technology. We currently support the Consumer Security Index project, exploring labelling schemes for consumer products and the Cyber Hygiene project, exploring behaviour change interventions for cybersecurity behaviour.

University of Kent

Dr Jason Nurse, who leads our Science and Research team, also works as academic at the University of Kent. This collaboration between CybSafe and Kent has led to various joint projects on topics such as behavioural security, cybersecurity in the home, and human risk management.

Research Institute for Sociotechnical Cyber Security

The Research Institute for Sociotechnical Cyber Security is the UK’s first academic Research Institute to focus on understanding the overall security of organisations, including their constituent technology, people, and processes. It is now in its second phase.

SPRITE+ hub

The SPRITE+ hub brings together people involved in research, practice, and policy relevant with a focus on digital contexts. We are a project partner helping to identify the future challenges of security, privacy, identity & trust in the digital world.

Safe as Houses: TIPS in Home Office Environments

As a result of COVID-19, many workplaces had to suddenly transition to remote working, despite a lack of training, remote-working policies, or in some cases, work devices. Coupled with the pressures of working from home in this context (e.g. childcare, impaired work-life balance), this new way of working has changed the risks and challenges surrounding workplace Trust, Identity, Privacy and Security (TIPS). This is exacerbated even further with the increase in cyberattacks specifically targeting remote workers. This work will therefore aim to explore and identify these issues, taking a socio-technical approach and focusing on small and large organisations. Our goal is to provide key, novel insights into the new challenges and tensions in relation to TIPS in these environments, and thereby provide the much-needed foundation for approaches to address these issues.

Government and regulators


We work with government bodies and regulators to advance people-centred security and cyber resilience.

Financial Conduct Authority (FCA)

We're supporting the FCA on guidance for how firms should measure, address and report cyber awareness and culture risk.

National Cyber Security Centre (NCSC)

We work with the NCSC's Sociotechnical Security Group on people-centric security and its guidance on awareness and behaviour change.

Department for Science, Innovation and Technology (DSIT)

We're working with the Cyber Security and Data Protection Directorate to improve cyber resilience in UK organisations.

Research Advisory Group

We strive to make sure that we are doing the best work possible. As such, we have a Research Advisory Group, comprising of leading cybersecurity experts, who provide independent high-level strategic advice and input into the development of the Research and Analysis activities conducted at CybSafe.

Prof. Adam Joinson

Prof. Adam Joinson conducts inter-disciplinary research on the interaction between human behaviour and technology, he is programme lead for the national Centre for Research and Evidence on Security Threats, as well as, running funded projects on individual susceptibility to malevolent influence techniques (e.g., phishing), communication accommodation, and behaviour change and technology.

Prof. Lynne Coventry

Prof. Lynne Coventry is the Director of PaCT (Psychology and Communication Technology) at Northumbria University. She is an applied researcher who is keen to explore new ways of integrating psychology into design and technology development processes.

Prof. Shane Johnson

Prof. Shane Johnson is the Director of the Dawes Centre for Future Crime at UCL. He has worked within the fields of criminology and forensic psychology for two decades, and his research has explored how methods from other disciplines can inform understanding of crime and security issues.

Dr. Jason Nurse (Chair of Advisory Group)

Dr. Jason Nurse chairs the Advisory Group and is the Director of Science and Research at CybSafe. Dr Nurse is also a Reader in Cyber Security at the University of Kent. His research investigates the human and psychological aspects of cybersecurity, privacy and online trust.

Dr. Suzie Dobrontei, CPsychol

Dr. Suzie Dobrontei is a chartered social psychologist, former university lecturer, and Behavioural Scientist at CybSafe. She’s researched and taught social processes, group dynamics and human factors in cybersecurity for eight years.

NCSC Researcher

A senior researcher from NCSC’s team of sociotechnical researchers.

Resources & events

SebDB

SebDB is the world’s first AI-powered, open-source security behaviour database. It forms the foundation of a fast-evolving behavioural ontology for cybersecurity. Designed and maintained by CybSafe’s Science and Research team as an open-source research initiative, SebDB maps security behaviours to impacts, threat actor tactics, intervention strategies, and security frameworks like MITRE ATT&CK and NIST CSF. It brings structure, meaning, and actionability to human cyber risk, something long overlooked or misunderstood in security programmes. sebdb.com

The IMPACT conference

IMPACT is about facilitating discussion and collaboration between academia and industry. And it’s about the latest academic research on the human aspect of cybersecurity. World-leading academic experts will discuss the latest research implications for policy and practice. theimpactconference.com

Research library

The world’s first globally accessible archive of research into the human aspect of cybersecurity and behavioural science as applied to cybersecurity awareness and online behavioural change. cybsafe.com/research-library

Research publications

Nurse, J. R. C., Dobrontei, S., Webster, J., & Alashe, O. (2026). Toward a behavioral ontology for cybersecurity: Introducing SebDB. In International Conference on Human-Computer Interaction (pp. 492-512). Cham: Springer Nature Switzerland.
Nurse, J. R. C., Milward, J., & Alashe, O. (2025). From Security Awareness and Training to Human Risk Management in Cybersecurity. In International Conference on Human-Computer Interaction (pp. 86-104). Cham: Springer Nature Switzerland.
Nurse, J. R. C., Williams, N., Collins, E., Panteli, N., Blythe, J., & Koppelman, B. (2021). Remote working pre-and post-COVID-19: an analysis of new threats and risks to security and privacy. In International Conference on Human-Computer Interaction (pp. 583-590). Cham: Springer International Publishing.
Blythe, J. M., Gray, A., & Collins, E. (2020). Human cyber risk management by security awareness professionals: Carrots or sticks to drive behaviour change?. In International conference on human-computer interaction (pp. 76-91). Cham: Springer International Publishing.
Blythe, J. M., Sombatruang, N., & Johnson, S. D. (2019). What security features and crime prevention advice is communicated in consumer IoT device manuals and support pages?. Journal of Cybersecurity, 5(1).

Change the behaviours that cause breaches. Prove it.