top of page

Cognitive Bias in Cybersecurity: How Our Minds Help (or Hinder) Security Decisions.

Writer: Rachael Tubbs, Ph.D
Rachael Tubbs, Ph.D
4 hours ago
12 min read

Over 68% of data breaches involve a human element. Yet while we invest heavily in technical resources to protect our personal and professional assets, our cognitive shortcuts can still leave the proverbial digital back door unlocked. These mental shortcuts are evolutionary adaptations designed to save us time and energy. They are not examples of flawed thinking; instead, they free up brain space for more demanding tasks. The problem is that, in complex digital environments, the same shortcuts that normally help us can turn into cognitive biases that work against us.

Human psychology, then, is not merely a vulnerability we can patch. By understanding how cognitive biases can both help and hinder security decisions, organizations can build systems around real human behavior rather than idealized expectations. In this article, we will examine how our minds can undermine sound security decisions, where those same mental processes can strengthen them, and how to design security practices with human psychology in mind. Let’s begin with a few common biases that can keep us from reaching our security goals.


How Our Minds Hinder Security Decisions


Optimism Bias

Have you ever seen something happen on the news and thought, “It won’t happen to me”? That is optimism bias in full effect. Optimism bias is the tendency to overestimate the likelihood of positive events and underestimate the likelihood of negative ones, especially when comparing ourselves with others. In cybersecurity, this has real-world consequences because attackers can exploit the gap between knowing a threat exists and believing it applies to you. You might understand how social engineering works, stay current on phishing trends, and even consider yourself relatively security-conscious. At the same time, you may believe you are unlikely to fall victim to a social engineering or phishing attempt because you are more knowledgeable, more cautious, or simply not important enough to be targeted. That is precisely the mindset attackers can exploit.


Consider a phishing attempt. If you received an email at your work address saying you had won a free tropical vacation, you probably would not click the link to claim your prize (unless, of course, you had recently entered a contest using that address. In that case, congratulations!) But if you received an invoice from a regular vendor, you might click the payment link or download the file to review it. The more believable the situation, the easier it becomes to dismiss initial concerns and overlook unusual spacing, typos, or other errors. Optimism bias makes that process even easier for the threat actor. Someone who believes they already know what phishing looks like may become less suspicious when presented with a sophisticated attack. In that moment, confidence becomes part of the attack surface.


This dynamic is especially relevant to social engineering. Attackers are not always trying to convince a target that something impossible is true. More often, they create a situation in which the victim’s existing assumptions work in the attacker’s favor. If you believe your company is too small to be targeted by phishing, an attacker can, and will, exploit that assumption. This is where optimism bias becomes especially dangerous. Delaying critical software updates, setting weak passwords, or ignoring multi-factor authentication (MFA) prompts because you have decided that your small business or team is not a target could result in a serious breach. These choices may seem harmless in isolation, but together they reveal how attackers benefit from decisions shaped by our perception of an asset’s value.


Threat actors are not necessarily looking for the organization with the most valuable data; they are looking for an exploitable weakness. Regardless of the size of your brand, outdated software, inadequate MFA and user policies, and poor security training can make your company a far easier target than a heavily defended organization with more valuable assets. In other words, attackers often rely on human assumptions as much as technical vulnerabilities. A software flaw may provide an entry point, but an employee’s lapse in attention can do the same. The consequences can also extend well beyond a single mistake. Optimism bias can create a cycle of delayed security improvements, testing, and threat modeling. Over time, a company may discover that the absence of previous incidents was never proof of security; it only meant the consequences had not yet materialized.


That said, optimism bias does not make someone careless. It is simply the brain making certain risks feel less personally relevant, and that is exactly what makes the bias useful to an attacker. I am not suggesting that you live in constant fear of being hacked or assume every email is malicious. Instead, shift your mindset: “unlikely” does not mean “impossible,” and knowledge and confidence do not make anyone immune. Reinforce that perspective with regular security awareness training tailored to your organization. After all, your optimism must be right every time; the attacker only has to be right once. With that in mind, let’s turn to another bias that shapes security decisions: confirmation bias.


Confirmation Bias and Alert Fatigue in the SOC

Confirmation bias is our subconscious tendency to seek out and recall information that aligns with preexisting beliefs while overlooking contradictory evidence. In cybersecurity, it emerges when professionals interpret incoming threat data through the lens of their existing assumptions and dismiss anomalies that do not fit expected patterns. Instead of asking what might explain the activity, an analyst may unconsciously search for evidence that supports the first explanation that comes to mind.


Imagine, for example, that a SOC analyst receives an alert showing unusual login activity from an employee’s account. The analyst may assume the employee is traveling, has moved, or was issued a new device. Once they find one detail that supports that theory, they may stop investigating, even when other evidence points elsewhere, such as an unusual login time, attempts to access restricted information, or an unfamiliar IP address. This is dangerous because attackers rarely behave exactly as defenders expect. They may use legitimate credentials, mimic normal activity, or move slowly between systems in ways that initially appear harmless. If we look only for evidence that matches a familiar attack pattern, we may miss the subtle signs that something unusual is happening.


Alert fatigue can compound the problem. Modern security environments can produce what feels like an endless stream of notifications from SIEM platforms, cloud environments, endpoint detection and response tools, identity systems, vulnerability scanners, and more. When employees repeatedly encounter low-priority or false alerts, they become desensitized to the volume. Over time, the brain begins to treat certain alerts as routine rather than worthy of investigation. An analyst overwhelmed by constant notifications may then rely more heavily on assumptions and familiar patterns to decide what deserves attention. Attackers exploit this limitation by blending malicious actions into legitimate behavior, generating background noise, or using techniques that resemble ordinary administrative activity. As a result, defenders face an even harder task when separating genuine threats from routine events.


So how do confirmation bias and alert fatigue reinforce each other? Alert fatigue reduces the attention an employee can devote to each event, while confirmation bias shapes how that employee interprets the limited information they do review. A mature SOC therefore needs processes that deliberately challenge assumptions rather than merely confirm them. Adopting a hacker mindset is especially valuable here, as it channels a person’s natural curiosity into more rigorous analysis. Teams can ask questions such as:


·      What evidence would prove our current assumption wrong?

·      What activity doesn’t fit the current explanation?

·      Are there other systems or accounts connected to this event?

·      If this were a cyber-attack, what could we expect to see next?


The hacker mindset is especially important during incident response because it encourages teams to treat an initial hypothesis as exactly that: a hypothesis, not a conclusion. Technology can reduce the burden, but it cannot eliminate the human element. Another way that human judgment shapes security decisions is through the Dunning-Kruger effect, which we will examine next.


The Dunning-Kruger Effect and Security Overconfidence

Overconfidence in cybersecurity is widespread and can be driven, in part, by the Dunning-Kruger effect: a cognitive bias in which people with limited skill or knowledge in a subject overestimate their competence. Consider someone with little security experience who is nevertheless highly confident in their ability to spot malicious activity. They may look for obvious warning signs they heard about in a news report, but in the age of AI, malicious attacks do not always look obvious. Attackers can create convincing messages, impersonate trusted individuals, and use information gathered from social media or the internet to make an attack appear credible. In that situation, confidence in one’s ability to identify a threat can become a threat of its own.


The goal is not to eliminate confidence. Nor do we want to create an environment where security professionals feel that questioning a potential threat amounts to admitting incompetence. One of the worst outcomes would be an employee who hesitates to question or report a suspicious email because they are afraid of being wrong or appearing uninformed. Confidence is valuable in many areas of life, especially when it is grounded in knowledge and experience. The real goal is to develop the skill to understand what you know, recognize what you do not, and respond appropriately when something falls outside your expertise. Knowing when to pause and verify is not a sign of weakness; it is one of the strongest security behaviors a person can develop.


How Our Minds Help Security Decisions

So far, we have focused on the ways our minds can hinder us. Now let’s flip the perspective and look at how human psychology can strengthen security. Qualities that have little to do with technology, such as intuition, pattern recognition, and social proof, shape our decisions every day, often without our realizing it. We’ll begin with pattern recognition and intuition.


Pattern Recognition and Intuition

The human brain is a highly advanced detection system. Every day, we unconsciously process enormous amounts of contextual information, compare it with prior experiences, and recognize patterns that may not be immediately obvious. This ability allows us to catch subtle contextual errors that technology currently cannot, adding an important layer of defense in cybersecurity. But if the process is subtle and unconscious, what does it look like in practice?

Consider an employee who receives a text message that appears to come from their CEO. Below is an example of a message I recently received claiming to be from the CEO of my company, Independent Security Evaluators.

Dr. Rachael Tubbs, The Exploit Society, on cognitive bias in security decisions.

His name and my name were spelled correctly, and there were no strange spacing issues or obvious typos. Even so, the request was unusual: he was asking to meet on a Saturday, which he would never do. Curious, an analyst from our team decided to respond, to see what the request from the phishing attempt would be.  An automated security tool might have struggled to identify anything malicious in the message, but I recognized the problem immediately. I knew he was aware that I was attending a work conference and traveling all weekend. He also does not text employees with random meeting requests; our communication goes through a work app, and meeting invitations are sent by his executive administrator.


My reaction was pattern recognition at work.


People develop mental models of the people, places, and processes they interact with regularly. We become familiar with a coworker’s communication style and tone, the way managers phrase requests, the information a vendor usually needs, and the normal sequence of events within a business process. When something breaks that pattern, we may recognize the inconsistency before we can consciously explain why it feels wrong. This is one of many reasons cybersecurity cannot rely exclusively on automated detection. Security tools are effective at identifying known indicators, correlating large volumes of data, detecting anomalies, and enforcing policies at scale, but they still lack the full context people bring to a situation.


I am not suggesting that organizations cancel security awareness training and tell employees to simply “trust their gut.” Instead, teach teams to treat an uneasy feeling as a cue to stop and verify. Confirm the request through a separate communication channel and ask whether the behavior is consistent with the person involved. Always look for additional evidence before taking action. That brief pause can turn intuition into a practical security control.


Social Proof

Humans naturally mirror the behaviors and norms of the people around them. This psychological phenomenon is known as social proof. When we are unsure what to do or how to act, we observe others and use their behavior as evidence of what is appropriate. That tendency can be a powerful tool for building a security culture. When leadership visibly practices security-minded behaviors, peers and direct reports are more likely to follow. Safe practices then become part of the collective culture rather than a matter of enforced compliance.


The opposite is also true. When employees see coworkers leave computers unlocked, share passwords, ignore software updates, or complain about security controls, those behaviors can become normalized. A new employee entering that environment may quickly learn that security policies are treated as guidelines rather than rules and that working around them is acceptable. Even when a company has strict written policies, the behavior employees observe from their peers often has greater influence on what they actually do.


Social proof also shapes how employees respond to suspicious activity. Imagine a new employee receives a phishing email and is unsure whether it is legitimate. If the prevailing culture is to ignore suspicious messages and assume IT will handle them, the employee is unlikely to act. If employees are encouraged or even praised for reporting questionable emails and security concerns are discussed openly, reporting becomes the normal and expected response.


I am not suggesting that policies are unnecessary. Policies, training, and technical controls are essential for businesses of any size. However, using social proof as another tool can move an organization beyond the idea that security is merely a long list of rules. To begin that shift, recognize employees who demonstrate strong security behaviors and encourage leaders to model those behaviors publicly. Make it easy and socially acceptable to report mistakes and suspicious activity. Leaders can also share examples of times when they misjudged a potential threat. Over time, these practices become self-reinforcing and part of the group’s expectations. New team members are then more likely to adopt the same strong security culture. For a formal 90-day plan, see this article I wrote earlier this year.


Designing for Human Psychology


These examples point to a broader principle: security works best when it is designed around the people who use it. That is simpler than it may sound and can often be rolled out within a few months. The key is to stop treating human behavior as a problem to correct and start treating it as a factor to account for when designing security controls. Let’s look at a few practical ways to put that idea into practice.


The first priority is reducing cognitive burden. Employees make decisions constantly throughout the workday, and cybersecurity is only one of many demands competing for their attention. If secure behavior requires people to remember numerous rules, navigate multiple systems, or make difficult judgments every time they encounter a potential threat, fatigue will eventually set in and behavior will become inconsistent. The most effective response is to make the secure path the easiest path.


Password management is one effective way to ease that burden. Asking employees to create unique, complex passwords for every account places significant demands on memory. Providing an organization-approved password manager, enabling single sign-on where appropriate, and implementing phishing-resistant authentication can remove much of that burden while improving security. Employees no longer have to remember dozens of passwords, which also reduces the likelihood that credentials will be written down or stored in an insecure location.


The same principle applies to reporting suspicious activity. If an employee must locate the security team’s email address, compose a message, explain why the content seems suspicious, and manually attach evidence, friction builds between noticing a threat and reporting it. Each step pulls the employee away from their normal workflow. A simple “report phishing” button built into email can dramatically reduce that friction. Allowing employees to forward a message to a dedicated inbox monitored by the security team is another option. The fewer steps required, the more likely employees are to take the desired action.


Timing matters as well. Security controls should fit naturally into team workflows rather than constantly interrupting them. When training, MFA prompts, vulnerability notifications, and other controls are poorly timed or highly disruptive, employees begin to view security as an obstacle to productivity. Once security becomes synonymous with inconvenience, users are more likely to look for ways around it. Before implementing a new control, ask: “What behavior are we asking users to perform, and how much time and effort does it require?” That question can reveal opportunities to make the experience more human-friendly.


For example, rather than simply reminding employees not to click suspicious links, pair that guidance with technical controls that block known malicious destinations and make it easy to report messages that slip through. Likewise, instead of relying entirely on a single annual security training, provide short, relevant guidance when employees need it through micro-learning and immediate contextual feedback. External teams can reinforce these efforts by testing assumptions and offering an independent perspective, which helps reduce confirmation bias in risk modeling.


Ultimately, cognitive biases are standard features of being human. They are not bugs or vulnerabilities to be patched, and strict policies alone will never eliminate them. The goal of modern cybersecurity should not be to fix how people think, but to build human-centered security systems that adapt to how our minds actually work. When security aligns with human behavior, teams are far more likely to adopt a security-first mindset. If your organization would like guidance on putting these ideas into practice, please feel free to contact me at rtubbs@ise.io, and we can explore ways to set your team up for success.


Published by Exploit Security in The Exploit Society. Dr. Rachael Tubbs on why cognitive bias belongs in the attack surface, and how to design controls around the way people actually decide. What is The Exploit Society? The guest series on the Exploit Security blog.

"Writers do not work here. The topics are theirs."

Do cognitive biases cause breaches? They shape the decision an attacker is waiting on. The Verizon figure she opens with, a human element in over 68% of breaches, is the scale. The mechanism is optimism bias, confirmation bias and overconfidence. Can training fix optimism bias? Not alone. She argues the secure path has to be the easy path: a password manager, a report-phishing button, a prompt that arrives when the decision is being made. Who published this? Exploit Security, a CREST-approved offensive security practice in Sydney offering penetration testing services and offensive security consultancy. The author is Dr. Rachael Tubbs.



 

 

 

 

 

 

 

Recent Posts

See All

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page