Related work
Organizations whose public research, standards, and data inform PsySec. Listing implies no partnership, endorsement, or affiliation.
Government
Peer-reviewed evidence and the Phish Scale
- Peer-reviewed, government-funded studies of real users and federal awareness programs
- Created the NIST Phish Scale for rating how hard a phishing email is to detect
- Named and documented 'security fatigue' through interview research
Cite
Government
Structuring an awareness and training program
- Lifecycle model for building and improving a learning program
- Explicitly frames the goal as behavior change and a security and privacy culture
- Includes guidance on measuring program effectiveness and maturity
Cite
Government
Simple public habits and free campaign materials
- Simple, repeatable behavior set used across U.S. public campaigns
- Free, public-domain toolkits and materials for organizations
- Joint technical phishing guidance with NSA, FBI, and MS-ISAC
Cite
Government
Government guidance on people-centred phishing defense
- Government guidance that favors layered defenses and easy, no-blame reporting over blaming users
- Layered phishing defense model that puts people in one layer, not the only one
- Board-level guidance on building a positive security culture
Cite
Government
Behavioral-science culture guidelines and toolkits
- Draws on behavioral economics, psychology, anthropology, and other human sciences
- Free awareness toolkit with KPI guidance and games (AR-in-a-Box)
- Compares national awareness strategies across EU Member States
Cite
Nonprofit
Cognitive attacks on humans and AI; practitioner community
- Treats social engineering as an attack on cognition, spanning humans, AI and human-AI teams
- Researcher-led board (Executive Director Dr. Matthew Canham; Board Chair Dr. Ben D. Sawyer)
- Runs SHIELD, a free practitioner community focused on human risk and behavioural security
Cite
Nonprofit
Yearly data on attitudes versus behavior
- Large multi-country survey of attitudes versus actual behavior, run annually since 2021
- Tracks the gap between completing training and changing behavior
- Uses humor and storytelling in public campaigns (e.g., the Kubikle web series)
Cite
Nonprofit
Phishing volume trends and the eCrime symposium
- Quarterly phishing volume and trend data from member and partner reports
- eCrime symposium (IEEE technically sponsored) explicitly covers social engineering and scam victim psychology
- Public-awareness work alongside data exchange
Cite
Research institute
Sociotechnical research linking academia and practice
- Long-running, government-funded home for sociotechnical and human-centred security research
- Practitioner-facing outputs, such as workshop materials released under Creative Commons
- Bridges academia, industry and policy through fellows, events and awards
Cite
Academic
Top-tier, open-access usable security research
- Top peer-reviewed venue for human-centred security research since 2005
- Free, permanent open-access proceedings on usenix.org (2014 onward)
- Regularly publishes field studies on phishing, scams and warnings
Cite
Academic
Peer-reviewed human-aspects research community
- Dedicated peer-reviewed venue for human-aspects security research since 2007
- Yearly Springer proceedings, indexed in Google Scholar and DBLP
- Global academic network led by researchers in security culture (Chair: Prof. Adele Da Veiga)
Cite
Academic
Reusable survey measures for behavior research
- Catalogs 799 constructs across 92 categories drawn from 699 publications
- Records each construct's origin, available survey items and validation status
- Links constructs back to the specific papers that used them
Cite
Industry research
Practitioner benchmarks and program maturity
- Longest-running practitioner benchmark on awareness teams (11th annual report in 2026)
- Maturity model widely used to describe program stages beyond compliance
- Large annual summit that gathers awareness, behavior, and culture practitioners
Cite
Industry research
Specific security behaviors mapped to risks and frameworks
- Breaks 'awareness' into specific, measurable behaviors ranked in four tiers by influence on risk
- Maps behaviors to MITRE ATT&CK tactics and NIST CSF 2.0 functions
- Free to use and inspect; described by CybSafe as open source
Cite