Psychological Security

Security for the part of the system attackers actually target: people.

Psychological Security (PsySec) is the discipline of defending people against manipulation. It builds the beliefs, instincts, and habits that help people recognize and report social engineering, inside a culture that treats them as partners, not risks.

48peer-reviewed studies & foundational works
25security behaviors mapped to evidence
8PsySec principles
6manipulation tactics

The third era of security

Each era of security emerged when the one before it stopped being enough.

Era 1PhySec

Guards, gates, and locks. Protects against threats you can see.

Era 2InfoSec

Firewalls, endpoint, identity. Protects against threats software can detect.

Era 3PsySec

Beliefs, instincts, and habits. Protects against attacks on human judgment.

How behavior changes

PsySec works the whole chain. Most programs try to force behavior directly and skip the first two links.

Belief“Reporting protects my team, and they have my back.”
EmotionSpotting a scam feels like pride, not anxiety.
BehaviorPause, verify, report.
HabitThe response becomes automatic.

What recent evidence says

All 48 studies →

The database includes evidence for and against PsySec claims: 22 supporting, 10 mixed, 4 challenging, and 12 foundational works.

SupportsQualitative · 2025

Phishing reporting in organizations: What motivates employees to take action?

The main reason employees report suspicious emails is wanting to protect and help the organization and coworkers, followed by responsibility, awareness of consequences, and feelings of insecurity. Reporters were more likely to report convincing, well-impersonated emails, showing they judge potential impact.

ChallengesRandomized controlled trial · 2025

Understanding the Efficacy of Phishing Training in Practice

Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.

MixedField experiment · 2022

Phishing in Organizations: Findings from a Large-Scale and Long-Term Study

Embedded training shown after failing a simulation did not make employees more resilient and could even increase susceptibility, while email warnings helped. Employees reporting suspicious emails worked as a fast, sustainable crowd-sourced detection system, with reporters staying active over long periods.

An open research initiative

The PsySec Research Database is free to use and cite. It is maintained by Hook Security, which developed the PsySec approach; our methodology explains how studies are selected and how we avoid cherry-picking. Researchers can submit studies or corrections.