Project NEXUS:
Behaviour is where every security domain connects

What people do decides whether controls work. It shapes the vulnerabilities that exist. And it's what every intervention is aiming at.

Yet most organisations have no systematic way to reason about behavioural risk.

Project NEXUS is building that foundation. It maps behaviour to threats, vulnerabilities, controls and risk outcomes, and gives the field a common language for how behaviour shapes security outcomes. Vendor neutral, openly licensed, and built in the open by a working group of senior practitioners and researchers.


Where we've got to

17 June. The first working group met in London. Practitioners spent the morning reflecting on the behavioural security ontology core to NEXUS, with a particular focus on its behavioural domain.

6 July. We published the readout. Every decision, every point still in dispute, out in the open.

16 July. The first online session opened the work to everyone else, and people who weren't in the room fed in. Watch it back >

What’s next

Next, the working group meets again on 1 October. The open session follows on 3 November.

1 October, London
Level39, One Canada Square, Canary Wharf.
9:30 to 13:30 BST.Four hours.

Do we all mean the same thing by asset, threat, and vulnerability? And do those words work for the people we're trying to reach?

How does a person's behaviour link to the threats we worry about? How does a threat connect to the behaviour that invites it, the weakness it exploits and the asset it targets? And, where those links go missing the community's thinking so far?

We open with a short recap of where we got to last time, then a grounding exercise against real situations from your own work. The rest is hands-on, working through the concepts and the connections between them, before we pull the threads together and agree what happens next.

You leave with clearer, shared definitions. A better picture of how a person's behaviour connects to the threats and the things you're protecting. And a marked-up model showing what the room would change, and why.

Take a seat
3 November, online
15:00 to 16:00 GMT.One hour.

In July we opened the first session up to everyone who wasn't in the room. We're doing it again.

The London working group will have worked through linking behaviour, threats, vulnerabilities and assets. Some definitions will have landed. Others will still be contested.

Whether or not you were in that room, this is where you react to the group's thinking and add your own, before the ontology evolves further.

We open with a short introduction to the ontology, so everyone starts on the same footing. Then what the group covered and where the thinking landed.

Save your place



Who's in the working group

CISOs, human risk managers and senior security culture practitioners, testing the framework against real applications and stress testing what's been drawn.




Between sessions

Everyone who signs up gets the readouts. Key decisions, the updated framework, and a way to feed in your own view. You don't have to attend anything to receive them.




Contribution and recognition

This is vendor neutral research with open source licensing. All contributors are offered the opportunity to be publicly recognised for their role in developing the ontology.



Express interest