Publication
Developing a behavioural cybersecurity strategy: A five-step approach for organisations
In this article, Tommy van Steen presents a five-step framework for building an effective behavioural cybersecurity strategy, designed to mitigate the impact of human-related risks on the cybersecurity of organisations.
- Author
- Tommy van Steen
- Date
- 22 October 2024
- Links
- Read the full article here
The field of cybersecurity is traditionally seen as technical; however, recent reports show that most data breaches stem from human error. This underscores the need for organisations to consider employee behaviour when designing cybersecurity strategies. Off-the-shelf solutions and one-time training initiatives are unlikely to succeed in addressing this issue, and evidence-based approaches are essential to foster meaningful behavioural change.
To improve cybersecurity, van Steen advocates for a strategy based on behavioural cybersecurity, which focuses on applying behavioural sciences to enhance cybersecurity for end-users, organisations, and society. The paper presents a five-step plan that goes beyond traditional awareness campaigns, emphasising technical solutions, nudges, targeted training, behaviour-change campaigns, and feedback loops to strengthen organisational cybersecurity.