DeReact, DeFatigue and Deceive: Psychology for Better Cybersecurity Design
Cybercrimeology1 Huhti 2025

DeReact, DeFatigue and Deceive: Psychology for Better Cybersecurity Design

Episode Notes:

  • Dr. Reeves’ Background – Trained as a psychologist, his interest in cybersecurity emerged from a talk connecting human error to security breaches.
  • Cybersecurity Fatigue Defined – A form of disengagement where employees lose motivation to follow security practices due to overload and conflicting advice.
  • Not Just Apathy – Fatigue often affects people who initially cared about cybersecurity but were worn down by excessive or ineffective interventions.
  • Training Shortcomings – Lecture-style, one-way training is frequently perceived as boring, irrelevant, or contradictory to users' experiences.
  • Compliance vs. Effectiveness – Many organizations implement security training to meet legal requirements, even if it fails to change behavior.
  • Reactance in Security – Users may intentionally ignore advice or rules to assert control, especially when training feels micromanaging or patronizing.
  • Better Through Design – Reeves argues that secure systems should reduce the need for user decisions by simplifying or removing risky options altogether.
  • Remove Rather Than Train – Limiting administrative rights is often more effective than trying to educate users out of risky behaviors.
  • Mismatch With Reality – Generic training that conflicts with real policies or system restrictions can confuse or alienate users.
  • Cognitive Load and Decision-Making – Under stress or fatigue, users rely on mental shortcuts (heuristics), which attackers exploit.
  • Personal Example of Being Fooled – Reeves recounts nearly falling for a scam due to time pressure, illustrating how stress weakens judgment.
  • Cybersecurity Buddy System – Recommends encouraging users to consult peers when making sensitive decisions, especially under pressure.
  • Cyber Deception Strategies – Reeves now researches ways to mislead and trap attackers inside systems using decoys and tripwires.
  • Applying Psychology to Attackers – The same behavioral models used to study users can help predict and manipulate attacker behavior.
  • Empowering Defenders – Deception technologies can help security teams regain a sense of agency, shifting from reactive defense to proactive engagemen

About our guest:

Dr. Andrew Reeves

Papers or resources mentioned in this episode:

Reeves, A., Delfabbro, P., & Calic, D. (2021). Encouraging employee engagement with cybersecurity: How to tackle cyber fatigue. SAGE Open, 11(1).

https://doi.org/10.1177/21582440211000049

Reeves, A., Calic, D., & Delfabbro, P. (2023). Generic and unusable: Understanding employee perceptions of cybersecurity training and measuring advice fatigue. Computers & Security, 128, 103137.

https://doi.org/10.1016/j.cose.2023.103137

Reeves, A., & Ashenden, D. (2023). Understanding decision making in security operations centres: Building the case for cyber deception technology. Frontiers in Psychology, 14, 1165705.

https://doi.org/10.3389/fpsyg.2023.1165705

Other:

UNSW Institute for Cyber Security (IFCYBER)

https://www.unsw.edu.au/research/ifcyber

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(129)

Public Interest Technology: Making Sense of Security in an AI World

Public Interest Technology: Making Sense of Security in an AI World

Notes: The conversation begins with his path into teaching public policy, despite never having planned a conventional academic career, and why translating technical subjects for non-technical studen...

1 Touko 34min

Who You Gonna Call?: Cybercrime Types and Expectations of Police Response

Who You Gonna Call?: Cybercrime Types and Expectations of Police Response

Notes: Cybercrime is often treated as a distinct phenomenon, but there are strong continuities with offline crime that are frequently overlooked. Digital technologies change behaviour and scale, bu...

1 Huhti 30min

Disordered Sense-Making: Conflict Narratives in the Digital Era

Disordered Sense-Making: Conflict Narratives in the Digital Era

Notes: Dr Samuel Tanner began his doctoral research examining war crimes and armed militias involved in mass violence in the Balkans, conducting extensive fieldwork and interviews with participants ...

1 Maalis 36min

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Notes:Dr Bekkers describes his academic pathway from psychology to criminology and explains why his research focus has consistently been on offenders and their behaviour rather than on offences or tec...

1 Helmi 25min

Systematically Improving Cybersecurity Training

Systematically Improving Cybersecurity Training

Notes:Julia Prümmer describes her transition from legal psychology into cybersecurity research and how psychological methods shape her approach to cybersecurity training.The discussion explores the ro...

1 Tammi 49min

The Human beneath the Hoodie: Profiling pathways into cybercrime

The Human beneath the Hoodie: Profiling pathways into cybercrime

otes:Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.Her research focuses on understanding the human behind ...

1 Joulu 202533min

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Episode Notes:Dr Ho describes an empirical research agenda focused on how security actually operates in organisations. He explains his experience with getting this research off the ground to allow the...

1 Marras 20251h 4min

The many minds of MITRE: building multidisciplinary human insider-risk research

The many minds of MITRE: building multidisciplinary human insider-risk research

Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber. Episode NotesDr Caputo's path ...

1 Loka 202544min

Suosittua kategoriassa Koulutus

rss-murhan-anatomia
psykopodiaa-podcast
voi-hyvin-meditaatiot-2
kesken
rss-valo-minussa-2
rss-liian-kuuma-peruna
rss-narsisti
rss-niinku-asia-on
rss-rahamania
adhd-podi
psykologia
rss-vapaudu-voimaasi
aamukahvilla
rss-laadukasta-ensihoitoa
rss-mentalrace
rss-arkea-ja-aurinkoa-podcast-espanjasta
rss-hereilla
rahapuhetta
puhutaan-koiraa
ihminen-tavattavissa-tommy-hellsten-instituutti