Our Version of Behavioral Cybersecurity

B.F. Skinner at Harvard circa 1950 (cropped)Pythia Cyber applies behavioral science to cybersecurity to make cybersecurity more effective. But our take is slightly different from the common definition of "behavioral cybersecurity." How are we different? Let's first review what Google's AI summary tells us about "behavioral cybersecurity" which is a decent summary of the common definition:

AI Overview

Behavioral cybersecurity focuses on human actions and system patterns to stop threats. It covers two main areas: behavioral analytics for threat detection and behavior-oriented training for human habits.

Behavioral Analytics (Systems and Data)

  • Baseline creation: Software learns normal user or device actions.
  • Anomaly detection: Flags strange login times or unusual data transfers.
  • Insider threats: Catches stolen accounts moving through a network.
  • Signature bypass: Finds new or unknown attacks that pass standard firewalls.

Behavioral Training (The Human Factor)

  • Habit focus: Replaces one-time compliance rules with real-world skill building.
  • Simulations: Uses frequent, safe phishing tests to practice safe clicks.
  • Positive reinforcement: Rewards good reporting instead of punishing mistakes.
  • Simplified actions: Makes reporting bad emails fast and easy.

How We Are Different

We are different in two big ways: we measure talent which allows us to address team dynamics. Behavioral training is a great way to get dogs to sit or people to avoid clicking on links in emails but this kind of conditioning is not going to get you to the top of the mountain: the right people in the right jobs doing the right things. How do you reach the mountaintop? With a highly developed Talent Acquisition & Upskilling program (TAU).

The Right People

You are probably doing a pretty good job at hiring people, although these days the input from HR and legal doesn't make that easy. You are probably using classic recruitment: trying to hire the best current candidate for the current role. This is good enough but it isn't great because the current candidate has to be judged on past experience of unknown applicability and the current role is likely to change over the course of the new hiree's tenure. How do you know if past performance was based on talent, which is adaptable, or if past performance was based on training and acquired skills, which are not very transferable? You know if you use our talent measuring instruments.

In The Right Jobs

Even if you do a great job hiring people you have not solved the performance / promotion problem that plagues so many workplaces. If you want to keep good people then you have to reward them. Salary bands mean that in order to reward high performers you must promote them. When you promote them you take them out of the role in which they excelled and put them into a different role. This does not tend to have the right people in the right jobs, it tends to turn the right people into the wrong people for their job. This is a form of The Peter Principle. Have you avoided this problem? How would you know? How about the people you didn't hire or promote? Our talent assessment will quickly and objectively tell you who should be doing what.

The Right Things

We are not a straight behavioral science team. We apply behavioral science to cybersecurity. We don't lose sight of the cybersecurity side of the equation. Cybersecurity is about measurable, provable success. The NIST CSF gives us a framework in which to gather evidence of effectiveness, detect failures and remedy the failures. You can't have TAU  for cybersecurity that isn't grounded in rigorous cybersecurity.

Conclusion

Classic cybersecurity will only get you so far. Conditioning people's behavior is an improvement but it always lags behind the state of the art. A Cybersecurity Program which includes a strong TAU component gives you the best chance of doing the best you can. Building such a TAU is hard. We can help. Ask us how.

Comments