Cybersecurity & Behaviour
People\u2019s behaviour does not arise in a vacuum. If a security procedure is not followed, it may just as well be about difficult workflows, technology, competing demands or organisational constraints as about a lack of knowledge.
We therefore look at the interplay between people, technology and organisation, so that follow-up can be targeted at the factors that actually shape behaviour.

Cybersecurity depends not only on technology and controls, but also on the organisational conditions within which people work.
We examine which factors shape behaviour in practice, such as workflows, technology, leadership, culture, skills and wellbeing.
The goal is to understand why people act as they do, so that follow-up can be targeted at the factors that actually make a difference.
We can examine specific issues or create a broader picture of the human and organisational side of your security.
For example:
The method depends on the question. We combine qualitative methods with quantitative data and analyses.
A concrete picture of the factors that shape security behaviour in your organisation, and of the patterns and interconnections relevant to the issue we examine.
A data foundation that makes it possible to measure relevant factors and differences across the organisation and establish a baseline against which development can later be compared.
Concrete and prioritised recommendations based on the results of the analysis, not general assumptions about what employees should do differently.
Support in how you continuously follow up on whether implemented recommendations have the intended effect.

People are often described as the weakest link in cybersecurity. But if we want to change behaviour, it is not enough to tell employees what to do.
We need to understand why they act as they do.
With a better data foundation, follow-up can be targeted at the factors that actually shape behaviour, and the effect can subsequently be measured.
CONTACT
Would you like to hear more about how we can help you with cybersecurity and behaviour? We are happy to have an informal talk about your needs.