Human Factor
Security is not only about systems.
It is about people in the system.
Human Factor looks at how people perceive situations, make decisions, communicate, act under pressure and interact with procedures and technology.
In cybersecurity, that means moving beyond the idea that people are simply the “weakest link”. With the right awareness, skills, processes and culture, people can become an active part of the defence.
The principle
The goal is not to remove people from security.
It is to design security that works with people.
Technology, procedures and human behaviour influence one another. Effective cybersecurity comes from understanding the whole system rather than blaming one component when something goes wrong.
From aviation to cybersecurity
Learning from environments where reliability matters.
Human Factor has been developed extensively in aviation and other high-reliability environments, where safety depends on the interaction between people, procedures, communication, technology and organisational culture.
HFCybersec draws on that experience as a source of principles for cybersecurity. The transfer is deliberate rather than mechanical: not every aviation practice belongs in cyber, but the underlying way of thinking about risk, decisions and organisational learning is highly relevant.
Situation Awareness
Build an accurate understanding of what is happening, what matters and what may happen next.
Shared Situation Awareness
Turn individual awareness into a shared operational picture across teams and responsibilities.
Just Culture
Learn from mistakes and unsafe conditions without defaulting automatically to blame.
Near Miss & Reporting
Treat events that almost became incidents as valuable information for prevention and improvement.
Knowledge, Skills, Attitude
Competence is more than knowing a rule: it combines what people know, what they can do and how they approach the situation.
Multiple Barriers
Incidents rarely come from one isolated weakness. Risk increases when multiple barriers fail or align at the same time.
From weak link to active defence
People can strengthen the security system.
Phishing, unusual requests, access mistakes and unexpected events all involve judgement. Awareness gives people a better chance to recognise something abnormal; clear procedures help them act; reporting helps the organisation learn.
The objective is not perfect human behaviour. It is a system that helps people make better decisions and catches problems before one mistake becomes an incident.
Recognise
Notice signals, anomalies and unusual requests.
Respond
Know what action to take and when to escalate.
Report
Make useful information visible to the organisation.
Learn
Use incidents and near misses to improve the system.
Putting Human Factor into practice
Awareness becomes useful when it changes behaviour and decisions.
HFCybersec connects Human Factor principles with practical cybersecurity activities: contextualised training, realistic scenarios, simulations, clear procedures, assessment and measurable improvement.
01
Understand the context
Start from real roles, workflows, risks and decision points rather than generic awareness messages.
02
Build capability
Develop knowledge, practical skills and attitudes appropriate to management, teams and employees.
03
Simulate and test
Use scenarios and exercises to turn theory into observable decisions and behaviours.
04
Measure and improve
Use assessment, reporting, feedback and lessons learned to identify gaps and guide the next improvement cycle.
!
Security has to work with the business.
The most secure system would be one nobody can use. Real cybersecurity is about managing risk while allowing the organisation to operate. Human Factor helps make that balance visible.
Build security people can understand, use and strengthen.