Module Overview

Behavioural insight, human-centred design, and cultural interventions for security

The module examined how human abilities, motivations, and constraints shape security outcomes — from the dominance of the human element in breach causation, through design choices that drive risky behaviour, to the integration of privacy, accessibility, and ethics into effective controls. Coursework focused on translating behavioural insight into interventions and metrics that improve outcomes within real organisational contexts, with a particular emphasis on the constraints faced by start-ups.

Module Learning Outcomes

The five outcomes assessed by this module

Behavioural Insight

Examine how human abilities, constraints, and motivations affect security actions and incident risk.

Human-Centred Design

Apply human-centred and usable-security principles to create safer defaults without hindering legitimate work.

Insider Risk Assessment

Assess insider-risk scenarios — malicious and unintentional — and propose proportionate detection, access, and cultural interventions.

Governance Integration

Integrate privacy-by-design and continuous improvement into governance processes and control selection.

Communicating Assurance

Clearly communicate risks and recommendations to both technical and non-technical audiences.

Key Artefacts

Summative submissions and tutor feedback

Individual Essay (individualessay.pdf)

UNIT 3

Critical analysis of three human factors for a local start-up: employee awareness, organisational culture and security mindset, and insider threats. The work connects start-up constraints to increased human-centred risk and argues for culture, training, and clear role definition.

Peer Review Submission (review.pdf)

UNIT 4

Reviewed two essays, identifying strengths and areas for improvement; applied concepts such as compliance budget and cognitive biases, and offered references to support suggestions.

Individual Presentation (final assignment.pdf)

UNIT 6

Proposed solutions addressing cognitive limitations and human error, insider threats, and design–behaviour mismatches for start-ups, supported by data and visuals.

Action Plan

Concrete next 6–8 week goals derived from tutor feedback

  1. Evidence base & currency. Add recent peer-reviewed studies and current insider statistics to the essay and slides, updating citations and figures as proof of completion. Week 2
  2. Concrete examples. Embed brief, relevant case studies alongside each factor and recommendation, evidenced by revised essay sections with example call-outs. Week 2
  3. Theoretical grounding. Map controls to a behavioural framework such as COM-B, linking actions to metrics and documenting the mapping in slides and narrative. Week 3
  4. Monitoring & improvement. Design a feedback loop covering KPIs, pulse surveys, A/B tests, and incident reviews, evidenced by an appended continuous-improvement plan. Week 4
  5. Peer-review rigour. Swap non-peer-reviewed sources for academic equivalents and annotate rationale, evidenced by an updated review with quality notes. Week 3
  6. Presentation polish. Add slide citations, a full references slide, and re-record audio with a script to tighten delivery, evidenced by new slide exports and transcripts. Week 3
  7. Accessibility & usable security. Introduce plain-language summaries, task-based guidance, readability checks, and alt text — evidenced by improved scores and annotated slides. Week 4

Professional Skills Matrix

Snapshot of competencies developed across the module

Skill Summary
Human-centred security & usability Operating at a proficient level by identifying cognitive limits, design–behaviour mismatches, and mitigations within the start-up context; next step is to align recommendations with COM-B and embed feedback loops.
Insider-risk analysis Proficient differentiation of malicious versus unintentional insiders with practical access and monitoring implications; improvement focuses on incorporating current prevalence data and threshold-based controls.
Evidence-based writing Progressing towards proficiency through appropriate sourcing and peer-review additions; next actions are increasing peer-reviewed material, refreshing statistics, and tightening citation placement.
Critical review & feedback Maintaining a proficient, balanced critique style with actionable recommendations, while adding source-quality flags and alternative peer-reviewed citations to elevate rigour.
Presentation & storytelling Delivering clear, data-backed narratives with strong visuals; focus is on enhancing audio, adding on-slide citations, and including a full references slide.
Academic practice & referencing Currently developing with correct structure but dated sources; improvement entails applying Cite-Them-Right consistently, alphabetising entries, and ensuring references appear both on slides and in full lists.

References

Sasse, M.A. and Flechais, I. (2005) 'Usable Security: Why Do We Need It? How Do We Get It?', in Cranor, L.F. and Garfinkel, S. (eds.) Security and Usability: Designing Secure Systems that People Can Use. Sebastopol: O'Reilly, pp. 13–30.

European Union Agency for Cybersecurity (2023) Awareness Raising in a Box (AR-in-a-Box). Heraklion: ENISA. Available at: https://www.enisa.europa.eu/topics/cybersecurity-education/awareness-campaigns

National Institute of Standards and Technology (2003) NIST SP 800-50 Building an Information Technology Security Awareness and Training Program. Gaithersburg: NIST.

Norman, D.A. (2013) The Design of Everyday Things. Revised and expanded edn. New York: Basic Books.

BCS, The Chartered Institute for IT (no date) BCS Code of Conduct. Swindon: BCS. Available at: https://www.bcs.org/membership-and-registrations/become-a-member/bcs-code-of-conduct/