Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

10 cognitive biases that can derail cybersecurity programs

By Steve Durbin
cognitive-bias-freepik1170x658.jpg
January 17, 2022

Cybercrime will cost the global economy $10 trillion annually by 2025. Even though security spending is at an all-time high, the majority of security leaders still lack confidence in cybersecurity investments. This is because most security breaches aren’t a consequence of inadequate security controls but are a direct result of human failure.  


So why do humans make mistakes? What triggers our behavior, and why are we so susceptible to manipulation? Understanding these triggers will greatly help organizations change their approach to information security.


Heuristics and Biases Result in Cybersecurity Lapses


Security decisions are often clouded by intrinsic weaknesses of our subconscious mind, and this can result in risky behavior, poor judgment and gaping holes in security posture. We often look for cognitive shortcuts (heuristics) that help us digest or break down information as quickly as possible. Ordinarily, this helps security teams process vast amounts of security data rationally; however, once in a while, they will make a snap decision that could put the entire organization at serious risk. 


Similarly, biases are a systemic error in reasoning that leads to failures in producing correct security decisions. For example, mosquitoes kill more people in a day than sharks kill in 100 years, yet human instinct always makes us more fearful of sharks.  


Top Cognitive Biases in Cybersecurity


Cognitive biases have been studied at length by psychologists and used in advertising, sales, marketing and other sectors. But the impact of cognitive biases in cybersecurity is often neglected or isn’t studied in great detail. Let’s explore the top ten biases along with their implications on information security:


1. Affect Heuristic: Affect heuristic is a mental shortcut that is heavily influenced by the current state of emotion. For example, if security staff have a good feeling about a certain situation, they may perceive it as low risk and not dig deeper. 


2. Anchoring: Anchoring is a pervasive bias where humans accept the first piece of information as the gospel truth while arriving at a decision. For example, if a chief information security officer (CISO) or a C-level executive places a particular cyber threat on higher priority, lower-level employees find themselves anchored to that specific threat instead of assessing the entire threat landscape.


3. Availability Heuristic: The more frequently one encounters a type of situation, the more readily it is accessible in their memory. When evaluating a security threat or situation, security teams will often rely on their memory, experience or industry trend instead of taking a methodical approach that evaluates all possible risks.


4. Bounded Rationality: Bounded rationality is a process where people attempt to satisfy instead of optimize. When tensions are running high during a cyberattack, security teams make “good enough” decisions based on the availability of information and types of security tools available at their disposal.


5. Choice Overload: Security teams often experience choice overload. Thousands of security solutions are available on the market — many claiming to be a silver bullet for cyber threats. Marketing messages and vendor-led narratives can confuse security teams in deploying the wrong solution for the wrong problem.


6. Decision Fatigue: Repetitive decision-making drains mental resources, and this can lead to decision fatigue. Security tools generate an average of 1000+ alerts per day, with many security staff admitting to ignoring security alerts when their plates get too full.


7. Herd Behavior: Humans subconsciously mimic the actions of a wider group. So if you’ve got a group of individuals writing passwords on post-it notes, the behavior can quickly spread and manifest across the entire organization. 


8. Licensing Effect: This is a phenomenon where people allow themselves to do something either negative or positive, depending on achieving an emotional reward for the action. Security teams and employees, too, are prone to becoming complacent. For example, if an employee shreds sensitive documents and feels they have done a good deed for the day, they might end up clicking on a phishing email. 


9. Optimism Bias: 80% of people are known to exhibit optimism bias, and this also applies to cybersecurity. Management, security teams and employees often carry a false, optimistic notion that because they have structured security processes and tools in place, they are immune to cyberattacks. The misbelief behind “This won’t happen to me” prevails.


10. Ego Depletion: Humans have a limited supply of willpower that diminishes over time. For example, employees will follow best practices post a security training session; however, in the absence of ongoing scheduled security awareness training and reminders, this behavior will eventually start to diminish. 


Cybersecurity Best Practices That Help Overcome Biases


Humans are the weakest link in cybersecurity, and opportunistic cybercriminals can easily leverage these biases and manipulate them to their advantage. Below are some recommendations to help you get started:


Emphasize Psychology over Technology: Human behavior must always be the core focus, and cybersecurity controls must be designed around them, not the other way around. 


Use Defense-in-depth: Focus on a layered security approach that is a combination of technological controls, training and procedures. 


Strengthen security culture through regular communications and training: Ongoing education via security awareness training programs complete with simulated phishing exercises can greatly help boost security culture. 


Cybersecurity, at its core, is primarily a human problem. It’s important that security teams recognize this and change their approach accordingly.

KEYWORDS: cyber security data breach human error information security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Steve durbin ceo isf
Steve Durbin is CEO at the Information Security Forum (ISF). His main areas of focus include strategy, information technology, cybersecurity and the emerging security threat landscape across both the corporate and personal environments. Previously, he was senior vice president at Gartner.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Man walking with briefcase

The Rising Tide of Executive Protection: Corporations Ramp Up Security in an Era of Heightened Threats

Executive Protection

Beyond the Bodyguard: Why Executive Protection Requires a New Playbook

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Stadium

Physical Security in Global Arenas: How AI Improves Security at Scale

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 30, 2026

Building a Campus-Wide Culture of Security and Shared Responsibility

In today’s higher education environment, where institutions face evolving and multifaceted incidents, safety must be embedded into the fabric of campus culture. Learn strategies for generating collective buy-in from faculty, staff, students and senior leadership. 

May 7, 2026

Beyond Cameras: Revolutionizing Perimeter Security with LiDAR, AI and Digital Twins

In this webinar, we will explore how LiDAR‑based detection, AI‑powered analytics and digital twins are transforming the future of perimeter protection with 3D detection, real-time situational awareness and unified operational views.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • artificial intelligence

    3 myths that can derail your machine learning program

    See More
  • cyber-data-freepik1170x658x82.jpg

    7 steps to combat cybersecurity threats in times of instability

    See More
  • Cognitive biases most targeted by cybersecurity attackers

    Cybercriminals exploit these cognitive biases the most

    See More

Related Products

See More Products
  • The Complete Guide to Physical Security

See More Products

Events

View AllSubmit An Event
  • November 19, 2025

    From Chaos to Clarity: How Real-Time, Location-Aware Intelligence Strengthens Security Programs

    ON DEMAND: When disruptive events hit, security teams must move fast to protect people, executives, and assets. Learn how integrating verified, real-time alerts into ArcGIS empowers security leaders with the situational awareness and geospatial advantage needed to respond quickly.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing