Select Page

Security culture

Meaningful Metrics for Human Cyber Risk

Meaningful Metrics for Human Cyber Risk

Most organizations fail to measure their human cyber risk. Some measure security training uptake. Some go a little further and measure suspicious link-clicks or report-rates. But very few can answer key security questions such as “How has our human cyber risk changed over time?” and “Which security interventions reduce most risk?”

People Centric Cyber Security e-Book

People Centric Cyber Security e-Book

Is it time to reconsider traditional approaches to cyber security? For a long time now, people have largely been viewed as a cyber security “weakness”, and the viewpoint has shaped the majority of the cyber security strategies we see today.

In the absence of a secure culture, reducing cyber risk could be impossible

In the absence of a secure culture, reducing cyber risk could be impossible

To understand why it might be impossible to reduce human cyber risk without a secure culture, it’s worth considering a series of experiments from the world of behavioural science.The experiments weren’t designed to uncover security insights. Rather, they were designed to demonstrate quirks in human behaviour. Specifically, they were designed to reveal why people sometimes “cheat”.

Gains, losses and unconscious calculations

Gains, losses and unconscious calculations

Our attitudes to loss make us vulnerable online. Here’s how we can nullify the risks – starting with a question. Which of these two generous offers would you rather take up? The first is £1000 in cash with no strings attached. The second is the chance to win £2000 – but only if a coin toss lands on heads.