What people do decides whether controls work. It shapes the vulnerabilities that exist. And it's what every intervention is aiming at.
Yet most organisations have no systematic way to reason about behavioural risk.
Project NEXUS is building that foundation. It maps behaviour to threats, vulnerabilities, controls and risk outcomes, and gives the field a common language for how behaviour shapes security outcomes. Vendor neutral, openly licensed, and built in the open by a working group of senior practitioners and researchers.
17 June. The first working group met in London. Practitioners spent the morning reflecting on the behavioural security ontology core to NEXUS, with a particular focus on its behavioural domain.
6 July. We published the readout. Every decision, every point still in dispute, out in the open.
16 July. The first online session opened the work to everyone else, and people who weren't in the room fed in. Watch it back >

Next, the working group meets again on 1 October. The open session follows on 3 November.

CISOs, human risk managers and senior security culture practitioners, testing the framework against real applications and stress testing what's been drawn.
Everyone who signs up gets the readouts. Key decisions, the updated framework, and a way to feed in your own view. You don't have to attend anything to receive them.


This is vendor neutral research with open source licensing. All contributors are offered the opportunity to be publicly recognised for their role in developing the ontology.