Are we on autopilot?
For years, we’ve been told that humans are the weak link in keeping organisations cyber secure. Research shows that 68% of breaches involve a human element, and the response has typically been to try and improve training, provide more reminders and make more information about cyber threats readily available.
But increasingly, this approach is based on a flawed assumption that doesn’t take in the context in which people work. The challenge isn't that employees don't know the rules. The challenge is that cyber incidents rarely happen when people are calm, focused, and carefully evaluating their options. They happen in the middle of a busy working day, juggling meetings, emails, deadlines.
Under these pressured conditions, people rely less on considered thinking and more on automatic behaviours. Decisions are made quickly, simply to keep work moving… and that’s when mistakes can happen.
Understanding the wiring
Labelling security incidents "human error” can be misleading. They occur because humans are behaving the way people are designed to behave under pressure. Behavioural science tells us that when cognitive load is high, our brains conserve effort by relying on familiar patterns and mental shortcuts. Or as Nobel laureate psychologist Daniel Kahneman says "Thinking is to humans as swimming is to cats; they can do it, but they'd prefer not to."
So, under time pressure, cognitive load, and competing priorities at work, decision-making shifts from deliberate to automatic. We tend to rely on fast, pattern-based responses: processing emails, approving requests, and sharing information with minimal scrutiny. And in busy environments, security steps are frequently missed in favour of task completion.
Attackers design for exactly this mode of behaviour. Urgency, authority, and familiarity act as triggers that increase the likelihood of automatic response, bypassing reflective judgement.

Attacking behaviour, not tech
Many of the most successful cyber attacks are remarkably simple:
- A phishing email arrives disguised as a routine request.
- A message appears to come from a senior leader.
- An urgent deadline prompts someone to skip a verification step.
They succeed not because of sophisticated technology. They succeed because they exploit these predictable human tendencies:
Urgency encourages immediate action >>>>
>>>> Authority reduces questioning >>>>
>>>> Familiarity creates trust.
These behavioural triggers increase the likelihood that someone will click, approve, share, or respond before taking time to think critically.
Practice matters
If organisations want employees to reduce cyber risk in everyday work behaviours, they need to do more than just teach them what to look for. It requires retraining the automatic response itself.
As Dr. Charlotte Hills, BAD behavioural strategist says:
“Good cyber security is not about remembering every rule. It is about making the safer response habitual.
Traditional learning design may already consider knowledge and motivation. We use behavioural design to apply a sharper, psychologically robust understanding of how habits form, then build those insights into the intervention itself.
That is how we move beyond simply raising awareness and help safer responses stick.”
Interventions can start to build new habits through:
- Repeated exposure to realistic scenarios
- Decision-making under pressure
- Immediate feedback and consequences
- Opportunities for reflection
Over time, this repetition builds what behavioural science describes as interrupt habits: small, automatic pauses that break the default action (click, approve, send), long enough for reflection to occur. Or in other words…
The goal isn’t to slow people down. It’s to make “pause and check” part of their instinct.
When that pause becomes automatic, people become less susceptible to behavioural triggers such as urgency and authority. They begin to spot warning signs earlier and make better decisions without needing to consciously remember every rule they learned in training.

Building better interventions
The most effective cyber risk interventions will mirror the realities of modern work. It should attempt to place people in situations where attention is divided, time pressure exists, and security decisions must be made as part of everyday tasks.
Repeatedly exposing people to realistic challenges and consequences means they experience the costs of acting on autopilot and the benefits of taking a moment to verify before acting. They become better at recognising risk patterns, more aware of behavioural triggers, and more likely to pause before clicking, approving, or sharing.
That is what transfers safer behaviours into the workplace. Because when the next suspicious email lands in someone's inbox, success will depend less on their knowledge of cyber and more on what they do automatically in that moment.
That's where cyber risk is won or lost.
If you’d like to find out more about how we could help you use behavioural science to make a big difference to cyber security in your organisation, please do get in touch.


blog02.jpg)



