Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementPhysicalSecurity NewswireCybersecurity News

New Information Security Forum research explores human-centered security

It's Time to Change Your Perception of the Cybersecurity Professional
November 24, 2020

The information security industry is playing catch-up when it comes to positively influencing behavior – the proliferation of remote working arrangements, exacerbated by the stress associated with the pandemic, has underlined the importance of strengthening the human elements of security. With this in mind, the benefits of a human-centered approach to security are clear. According to the Information Security Forum (ISF), with growing recognition that security awareness in isolation rarely leads to sustained behavior change, organizations need to proactively develop a robust human-centered security program to reduce the number of security incidents associated with poor security behavior.

To aid organizations to invest effort and resources in understanding the human mind and deploying the right techniques so they can influence behavior, the ISF is releasing Human-Centred Security: Positively Influencing Security Behavior. The organization’s latest digest helps enterprises to develop mature approaches to managing human risk by setting out several initiatives supported by established psychological theory. The digest will enable senior leaders to better understand the key drivers behind human behavior, how they can positively influence people and use the right techniques to empower employees to keep the organization secure.

“Errors and acts of negligence can cause significant financial and reputational damage to an organization, with many security incidents and data breaches originating from a human source,” said Daniel Norman, Senior Solutions Analyst at the ISF, and author of the digest. “A human-[centered]security program helps organizations to understand their people and carefully craft initiatives that are targeted at behavior change, reducing the number of security incidents related to human error and negligence.”

A human-centered security program uses psychology to address the fundamental strengths and weaknesses in the human mind and aims to enhance the working environment to enable employees to behave securely. A successful program leverages cross-departmental collaboration to fully grasp the current state of security behavior, which subsequently enables organizations to target investment to mitigate the identified risks.

Human-Centred Security: Positively Influencing Security Behavior provides organizations with guidance on:

  • Understanding the key factors that influence employees’ security choices
  • Delivering impactful security education, training, and awareness
  • Designing systems, applications, processes, and the physical environment to account for user behavior
  • Developing metrics to measure behavior change and demonstrate return on investment

“Technology and processes should complement behavior, not add friction and impede productivity,” said Steve Durbin, Managing Director, ISF. “A typical strategy should aim to reduce the number of security incidents and improve the accuracy of incident reporting – therefore human-[centered] security is an ideal mechanism for meeting these goals.”

Lisa Plaggemier, Chief Strategy Officer at MediaPro, a Seattle, Washington-based provider of cybersecurity and privacy education, explains, "If the “brand” of your security team isn’t to be approachable, helpful, and add value, you won’t be included in projects where you really do need a seat at the table.  Your training and awareness program is the most visible thing your security team does, so use it to show that you want to work with the business, not against it, and that you’re friendly and approachable.  This is the reason why I don’t advocate for training and awareness that relies on fear-mongering to get people’s attention. There are some simple initiatives organizations can engage in to design secure behavior into everyday activities. For developers, there are plenty of tools that don’t interrupt their workflow that help them to “design” security into their code.  Some of them also include “teachable moment” training when they scan their code and are ready to check it in.  I’m a huge fan of tools that don’t ask people to do things differently, but rather help them to be more secure in a way that is designed around their function." 

For more information, or any aspect of the ISF, please visit the ISF website.

KEYWORDS: cyber security information security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Colorful laptop

Organizations Think They Know Who’s Visiting Their Sites. They Don’t.

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

Sewer

Why Are People Entering NYC’s Sewers at Night?

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Security Worker

    New Information Security Forum Report Explores How to Build an Effective SOC

    See More
  • Revised NIST Cyber Security Framework - Security Magazine

    Information Security Forum explores the risks and challenges of open source software

    See More
  • cybersecurity-blog

    Information Security Forum Releases Updated Guide to Security Best Practices

    See More

Related Products

See More Products
  • Security of Information and Communication Networks

  • 9780815378068.jpg.jpg

    Biometrics, Crime and Security

See More Products

Events

View AllSubmit An Event
  • September 19, 2012

    Oil & Gas Critical Infrastructure & Asset Security Forum 2012

    The Forum will cover security issues related to both offshore and onshore oil and gas arising out of civil unrest, terrorist activities, and a competitive global market.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing