Psychological Security
Security for the part of the system attackers actually target: people.
Psychological Security (PsySec) is the discipline of defending people against manipulation. It builds the beliefs, instincts, and habits that help people recognize and report social engineering, inside a culture that treats them as partners, not risks.
48peer-reviewed studies & foundational works
25security behaviors mapped to evidence
8PsySec principles
6manipulation tactics
The third era of security
Each era of security emerged when the one before it stopped being enough.
Era 1PhySecGuards, gates, and locks. Protects against threats you can see.
→
Era 2InfoSecFirewalls, endpoint, identity. Protects against threats software can detect.
→
Era 3PsySecBeliefs, instincts, and habits. Protects against attacks on human judgment.
How behavior changes
PsySec works the whole chain. Most programs try to force behavior directly and skip the first two links.
Belief“Reporting protects my team, and they have my back.”
EmotionSpotting a scam feels like pride, not anxiety.
BehaviorPause, verify, report.
HabitThe response becomes automatic.
The database includes evidence for and against PsySec claims: 22 supporting, 10 mixed, 4 challenging, and 12 foundational works.
MixedField experiment · 2026
Yin et al. — MIS Quarterly
Embedded feedback shown only to people who fail has limited reach and weaker field effects than lab studies suggested. Sending delayed feedback to all employees after a simulation (non-embedded training) emerged as a more promising way to reduce vulnerability over time.
SupportsQualitative · 2025
Burda et al. — Information & Computer Security
The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.
ChallengesRandomized controlled trial · 2025
Ho et al. — 2025 IEEE Symposium on Security and Privacy (SP)
Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.
MixedField experiment · 2022
Lain et al. — 2022 IEEE Symposium on Security and Privacy (SP)
Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.
An open research initiative
The PsySec Research Database is free to use and cite. It is maintained by Hook Security, which developed the PsySec approach; our methodology explains how studies are selected and how we avoid cherry-picking. Researchers can submit studies or corrections.