DeReact, DeFatigue and Deceive: Psychology for Better Cybersecurity Design
Cybercrimeology1 Apr 2025

DeReact, DeFatigue and Deceive: Psychology for Better Cybersecurity Design

Episode Notes:

  • Dr. Reeves’ Background – Trained as a psychologist, his interest in cybersecurity emerged from a talk connecting human error to security breaches.
  • Cybersecurity Fatigue Defined – A form of disengagement where employees lose motivation to follow security practices due to overload and conflicting advice.
  • Not Just Apathy – Fatigue often affects people who initially cared about cybersecurity but were worn down by excessive or ineffective interventions.
  • Training Shortcomings – Lecture-style, one-way training is frequently perceived as boring, irrelevant, or contradictory to users' experiences.
  • Compliance vs. Effectiveness – Many organizations implement security training to meet legal requirements, even if it fails to change behavior.
  • Reactance in Security – Users may intentionally ignore advice or rules to assert control, especially when training feels micromanaging or patronizing.
  • Better Through Design – Reeves argues that secure systems should reduce the need for user decisions by simplifying or removing risky options altogether.
  • Remove Rather Than Train – Limiting administrative rights is often more effective than trying to educate users out of risky behaviors.
  • Mismatch With Reality – Generic training that conflicts with real policies or system restrictions can confuse or alienate users.
  • Cognitive Load and Decision-Making – Under stress or fatigue, users rely on mental shortcuts (heuristics), which attackers exploit.
  • Personal Example of Being Fooled – Reeves recounts nearly falling for a scam due to time pressure, illustrating how stress weakens judgment.
  • Cybersecurity Buddy System – Recommends encouraging users to consult peers when making sensitive decisions, especially under pressure.
  • Cyber Deception Strategies – Reeves now researches ways to mislead and trap attackers inside systems using decoys and tripwires.
  • Applying Psychology to Attackers – The same behavioral models used to study users can help predict and manipulate attacker behavior.
  • Empowering Defenders – Deception technologies can help security teams regain a sense of agency, shifting from reactive defense to proactive engagemen

About our guest:

Dr. Andrew Reeves

Papers or resources mentioned in this episode:

Reeves, A., Delfabbro, P., & Calic, D. (2021). Encouraging employee engagement with cybersecurity: How to tackle cyber fatigue. SAGE Open, 11(1).

https://doi.org/10.1177/21582440211000049

Reeves, A., Calic, D., & Delfabbro, P. (2023). Generic and unusable: Understanding employee perceptions of cybersecurity training and measuring advice fatigue. Computers & Security, 128, 103137.

https://doi.org/10.1016/j.cose.2023.103137

Reeves, A., & Ashenden, D. (2023). Understanding decision making in security operations centres: Building the case for cyber deception technology. Frontiers in Psychology, 14, 1165705.

https://doi.org/10.3389/fpsyg.2023.1165705

Other:

UNSW Institute for Cyber Security (IFCYBER)

https://www.unsw.edu.au/research/ifcyber

Avsnitt(127)

Disordered Sense-Making: Conflict Narratives in the Digital Era

Disordered Sense-Making: Conflict Narratives in the Digital Era

Notes: Dr Samuel Tanner began his doctoral research examining war crimes and armed militias involved in mass violence in the Balkans, conducting extensive fieldwork and interviews with participants ...

1 Mars 36min

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Notes:Dr Bekkers describes his academic pathway from psychology to criminology and explains why his research focus has consistently been on offenders and their behaviour rather than on offences or tec...

1 Feb 25min

Systematically Improving Cybersecurity Training

Systematically Improving Cybersecurity Training

Notes:Julia Prümmer describes her transition from legal psychology into cybersecurity research and how psychological methods shape her approach to cybersecurity training.The discussion explores the ro...

1 Jan 49min

The Human beneath the Hoodie: Profiling pathways into cybercrime

The Human beneath the Hoodie: Profiling pathways into cybercrime

otes:Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.Her research focuses on understanding the human behind ...

1 Dec 202533min

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Episode Notes:Dr Ho describes an empirical research agenda focused on how security actually operates in organisations. He explains his experience with getting this research off the ground to allow the...

1 Nov 20251h 4min

The many minds of MITRE: building multidisciplinary human insider-risk research

The many minds of MITRE: building multidisciplinary human insider-risk research

Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber. Episode NotesDr Caputo's path ...

1 Okt 202544min

Follow the Honey: Experiments in Cybercriminal Decision-Making

Follow the Honey: Experiments in Cybercriminal Decision-Making

Show Notes:Daniëlle began her academic path in psychology, later moving into criminology through her interest in decision making and online behaviour.Her PhD research at NSCR focuses on cybercriminal ...

1 Sep 202530min

Crime Online: Hashtag Like and Subscribe, or don't

Crime Online: Hashtag Like and Subscribe, or don't

Episode NotesAbout our guest:Dr. Francesco Carlo CampisiPhD in Criminology, Université de MontréalResearcher, International Centre for Comparative Criminology🔗 https://www.cicc-iccc.org/fr/personnes/...

1 Aug 202529min

Populärt inom Utbildning

historiepodden-se
rss-bara-en-till-om-missbruk-medberoende-2
det-skaver
harrisons-dramatiska-historia
nu-blir-det-historia
roda-vita-rosen
not-fanny-anymore
alska-oss
johannes-hansen-podcast
sektledare
sa-in-i-sjalen
rss-max-tant-med-max-villman
allt-du-velat-veta
rss-viktmedicinpodden
rikatillsammans-om-privatekonomi-rikedom-i-livet
rss-foraldramotet-bring-lagercrantz
i-vantan-pa-katastrofen
rss-sjalsligt-avkladd
rss-basta-livet
sex-pa-riktigt-med-marika-smith