The Science Behind Psyche-Cybersecurity — Human Systems Security
The science behind the practice

Your controls are hardened. The operator running them is not.

Psyche‑Cybersecurity is not a metaphor. It is a reading of the breach data and the cognitive science that explains it. The technical estate has been engineered, patched and monitored for two decades. The decision-making layer that authorises every action on top of it has not. This page sets out the evidence.

~60%
of confirmed breaches involve the human element — error, social engineering or misuse — a figure that has held steady year over year.
Verizon DBIR 2025
8% drive 80%
A small minority of people account for the overwhelming majority of incidents — risk is concentrated, not evenly distributed.
Verizon DBIR 2025
~0
measurable effect of additional awareness training on phishing click rates once a behavioural floor is reached.
DBIR phishing simulation analysis
The premise

Attackers stopped breaking the technology. They learned to operate the person.

Endpoint, identity and network controls have matured to the point where breaking them at scale is expensive. So the economically rational attacker moves up the stack — to the human who holds legitimate credentials and the authority to act.

The decisive moves in modern intrusions are not exploits. They are an urgent message that bypasses scrutiny, a convincing voice that borrows authority, a request that arrives at the moment attention is thinnest. Each one targets a predictable feature of human cognition, not a defect in code.

Security awareness programmes treat this as an information problem — if people simply knew better, they would act better. The data says otherwise. Knowing is a conscious-layer intervention. The behaviour being exploited sits underneath it.

A control failure is visible in a log. A judgement failure under pressure leaves no trace — which is exactly why it is the preferred attack surface.

The human stack

The same layered model you apply to infrastructure — applied to the operator.

Security architecture already thinks in layers: each one defended, each one able to fail independently. The person is no different. Below technology and process sit cognitive and physiological layers that are real, measurable, and almost entirely undefended. As you descend, defences thin and exploitability rises.

Surface · engineered & monitored Core · unguarded & exploitable
Layer 0–1
Technology & process
Hardened · the existing estate

Controls, configurations, policy. Two decades of investment. Genuinely difficult to defeat head-on — which is precisely why attackers route around it.

Layer 2
The conscious mind
System 2 · deliberate reasoning

Slow, effortful, analytical thought — where training lands. Powerful but metabolically expensive and easily crowded out. It is the layer we assume is in control, and rarely is.

Layer 3
Automatic processing
System 1 · heuristics & habit

Fast, intuitive, default-on. It handles the vast majority of daily decisions, including most clicks and approvals. Attackers craft lures so System 1 resolves them before System 2 is ever engaged.

Layer 4
Belief & influence
Compliance & trust heuristics

The mental shortcuts that decide who we trust and obey — authority, reciprocity, social proof, scarcity. Documented, reliable, and the explicit toolkit of social engineering.

Layer 5
The nervous system
Autonomic arousal & stress load

Acute stress floods the system and narrows attention. Under load, the prefrontal cortex — the seat of deliberate reasoning — measurably loses ground to faster, threat-driven circuits.

Layer 6
Survival response
Threat physiology under pressure

When something is framed as urgent and threatening, decision-making shifts toward immediate self-protection. Manufactured urgency is not a trick of wording; it is a deliberate move on this layer.

As depth increases, conscious oversight decreases — and attacker reliability increases.
Attack → mechanism

Every familiar lure maps cleanly onto a known mechanism.

This is the diagnostic value of the model. Once the layers are named, the attacker's playbook stops looking like a list of tricks and starts looking like a systematic exploitation of predictable human machinery.

The lure · urgency

"Action required in the next 30 minutes."

Manufactured time pressure triggers acute stress, narrows the window for deliberate reasoning and pushes the decision toward fast, threat-driven processing.

→ Layers 5–6 · stress & survival response
The lure · authority

An instruction that appears to come from the CEO.

The authority heuristic is a reliable compliance shortcut. Borrowed authority suspends the scrutiny a peer request would receive — no exploit required.

→ Layer 4 · compliance heuristics
The lure · familiarity

A routine-looking notification at a busy moment.

Routine requests are resolved by automatic processing. The more a message resembles the everyday, the less likely deliberate analysis is ever invoked.

→ Layer 3 · System 1 default response
The lure · cognitive load

The request that arrives mid-context-switch.

Attention is finite. When working memory is already saturated, the deliberate layer has no spare capacity to challenge what arrives — vigilance drops measurably.

→ Layer 2 · System 2 capacity limits
Why training plateaus

Awareness operates on the one layer the attacker is no longer targeting.

The DBIR's phishing-simulation analysis found that click rates were essentially unaffected by additional training once a behavioural floor was reached. This is not a failure of any single programme — it is what the layered model predicts. Awareness is a conscious-layer (System 2) intervention. The behaviour being exploited lives in automatic processing, stress physiology and compliance heuristics — layers that knowledge alone does not reach. You can raise reporting rates and you should; but you cannot train your way past human architecture. The work has to move down the stack.

From diagnosis to intervention

What changes when you defend the lower layers.

The point of the model is not insight for its own sake — it is a different set of controls. Applied behavioural-change methods, deployed with the same rigour as any other security control, target the layers awareness cannot reach.

01

Friction by design

Insert a deliberate pause into high-consequence, high-pressure decisions — re-engaging System 2 at precisely the moment an attacker is engineering to bypass it. An architectural control, not a poster.

02

Load-aware process

Map where critical approvals collide with peak cognitive load and redesign the workflow so the riskiest judgements are not made when capacity is lowest.

03

Concentrated risk focus

If a small fraction of people account for most incidents, blanket training is the wrong instrument. Effort concentrates where the data says exposure actually sits.

Evidence base

  1. 1Verizon. 2025 Data Breach Investigations Report (DBIR). Human element in ~60% of breaches; concentration of risk; phishing click rate unaffected by training. 18th annual report, >22,000 incidents analysed.
  2. 2Kahneman, D. (2011). Thinking, Fast and Slow. Dual-process theory — System 1 (automatic) and System 2 (deliberate) reasoning.
  3. 3Cialdini, R. B. (2021). Influence: The Psychology of Persuasion (rev. ed.). The principles of compliance — authority, reciprocity, social proof, scarcity and related heuristics.
  4. 4Arnsten, A. F. T. (2009). Stress signalling pathways that impair prefrontal cortex structure and function. Nature Reviews Neuroscience, 10(6).
  5. 5Starcke, K. & Brand, M. (2012). Decision making under stress: a selective review. Neuroscience & Biobehavioral Reviews, 36(4).
  6. 6Williams, E. J., Hinds, J. & Joinson, A. N. (2018). Exploring susceptibility to phishing in the workplace. International Journal of Human-Computer Studies, 120.

Bring the model to your own threat data.

A working session for CISOs and risk leaders: we map your real incident patterns onto the human stack and identify which layers your current controls do and don't reach.

Jakub
Enterprise Security Architect
Senior Cybersecurity Architect

Fifteen years across global banking, engineering, FMCG, e-learning and government. Psyche‑Cybersecurity applies that architectural discipline one layer further down — to the human system that operates everything above it.