Human Factor

Security is not only about systems.
It is about people in the system.

Human Factor looks at how people perceive situations, make decisions, communicate, act under pressure and interact with procedures and technology.

In cybersecurity, that means moving beyond the idea that people are simply the “weakest link”. With the right awareness, skills, processes and culture, people can become an active part of the defence.

CONTEXTTECHPROCESSPEOPLE

The principle

The goal is not to remove people from security.
It is to design security that works with people.

Technology, procedures and human behaviour influence one another. Effective cybersecurity comes from understanding the whole system rather than blaming one component when something goes wrong.

From aviation to cybersecurity

Learning from environments where reliability matters.

Human Factor has been developed extensively in aviation and other high-reliability environments, where safety depends on the interaction between people, procedures, communication, technology and organisational culture.

HFCybersec draws on that experience as a source of principles for cybersecurity. The transfer is deliberate rather than mechanical: not every aviation practice belongs in cyber, but the underlying way of thinking about risk, decisions and organisational learning is highly relevant.

Situation Awareness

Build an accurate understanding of what is happening, what matters and what may happen next.

Shared Situation Awareness

Turn individual awareness into a shared operational picture across teams and responsibilities.

Just Culture

Learn from mistakes and unsafe conditions without defaulting automatically to blame.

Near Miss & Reporting

Treat events that almost became incidents as valuable information for prevention and improvement.

KSA

Knowledge, Skills, Attitude

Competence is more than knowing a rule: it combines what people know, what they can do and how they approach the situation.

Multiple Barriers

Incidents rarely come from one isolated weakness. Risk increases when multiple barriers fail or align at the same time.

From weak link to active defence

People can strengthen the security system.

Phishing, unusual requests, access mistakes and unexpected events all involve judgement. Awareness gives people a better chance to recognise something abnormal; clear procedures help them act; reporting helps the organisation learn.

The objective is not perfect human behaviour. It is a system that helps people make better decisions and catches problems before one mistake becomes an incident.

Recognise
Notice signals, anomalies and unusual requests.

Respond
Know what action to take and when to escalate.

Report
Make useful information visible to the organisation.

Learn
Use incidents and near misses to improve the system.

Putting Human Factor into practice

Awareness becomes useful when it changes behaviour and decisions.

HFCybersec connects Human Factor principles with practical cybersecurity activities: contextualised training, realistic scenarios, simulations, clear procedures, assessment and measurable improvement.

01

Understand the context

Start from real roles, workflows, risks and decision points rather than generic awareness messages.

02

Build capability

Develop knowledge, practical skills and attitudes appropriate to management, teams and employees.

03

Simulate and test

Use scenarios and exercises to turn theory into observable decisions and behaviours.

04

Measure and improve

Use assessment, reporting, feedback and lessons learned to identify gaps and guide the next improvement cycle.

!

Security has to work with the business.

The most secure system would be one nobody can use. Real cybersecurity is about managing risk while allowing the organisation to operate. Human Factor helps make that balance visible.

Build security people can understand, use and strengthen.