The next-generation CISO will be half hacker, half psychologist. Over the last three decades, I have watched security technology evolve in layers. From signature-based antivirus to EDR, from EDR to XDR, and now to AI-assisted detection systems that promise predictive intelligence. And yet, when I sit down and study most serious breaches, the root cause rarely begins with a sophisticated zero-day exploit. It usually begins with a human decision. (and attackers understand this very well.) They do not begin by writing code. They begin by studying behavior. They ask themselves quiet questions: Who inside this organisation is under pressure to deliver? Who has accumulated access over time that nobody reviewed? Who believes policy is flexible “just this once”? Who is tired? Who is overconfident? In one real scenario, an engineer bypassed three independent security controls because a deployment deadline was approaching and the system “had to go live.” There was no malicious intent. No insider conspiracy. Just urgency combined with authority and access. That is enough. When we look at such cases later, we often focus on the missing patch or the control gap. But the more important question is different: Why did someone feel comfortable overriding those controls in the first place? This is why I believe the CISO of the future must develop two parallel instincts. First, the technical instinct. They must still understand lateral movement, identity abuse, cloud misconfiguration, API exposure, privilege escalation, and the ways attackers chain small weaknesses into systemic compromise. But alongside that, they must develop a behavioural instinct. They must understand: • how incentives are structured inside teams • how deadlines distort judgment • how developers perceive security teams • how executives interpret “risk” versus “delay” • how culture silently encourages shortcuts Attackers exploit psychology with precision. They send emails that create urgency. They impersonate authority. They trigger fear. They trigger curiosity. They trigger ego. And sometimes, they do not even need to. Internal pressure does the work for them. So the next-generation CISO cannot rely only on dashboards. Cybersecurity is no longer just a contest of tools. It is a contest of human behaviour under pressure. The CISO who understands both, the code and the mind, will not only detect threats more effectively. They will reduce the conditions that create them. Seqrite #Cybersecurity #CISO #SecurityLeadership #CyberLeadership #InformationSecurity #CyberRisk #SecurityCulture #CyberDefense #SecurityStrategy #Leadership #HumanFactor #CyberResilience #Infosec #EnterpriseSecurity
Human-Centered Service Design
Explore top LinkedIn content from expert professionals.
-
-
In the U.S. alone, cybercrime caused $16 billion in damages in 2024 - a 33% increase from the year before. And most of these breaches weren’t due to complex hacks or advanced malware. They happened because of simple human errors: misconfigured systems, unsecured devices, careless behavior, or being tricked by a convincing phishing email. That’s why the human factor is often the weakest link in cybersecurity, but also where the biggest gains can be made. So how do we build a human-centered security culture? It’s about shaping behavior and habits. A proven approach is Neidert’s Core Motives Model, which helps leaders guide employees toward secure behavior through three stages: 🔹 Connect – Build trust and rapport. People follow leaders they like and feel connected to. Gamified training sessions, team bonding, and small acts of reciprocity go a long way. 🔹 Reduce Uncertainty – Show credibility and social proof. When senior leaders take part in security efforts, or when teams see peers taking security seriously, they’re more likely to follow suit. 🔹 Inspire Action – Reinforce commitments. Use nudges, timely reminders, and even friendly competitions to encourage continuous attention to cybersecurity practices. A collective mindset where everyone feels responsible for protecting company assets, and each other. Security doesn’t live in IT alone. It lives in everyone’s daily choices.
-
Icelandair recently paid someone to take bad photographs of Iceland. Not an award-winning travel photographer. Not a creator with perfectly edited landscapes. The airline searched for an ordinary traveller who openly admitted that photography was not their strength. More than 127,000 people applied. The idea worked because Icelandair was confident enough to make the destination, rather than the production quality, the hero of the campaign. It also gave people something many travel campaigns have polished away: 𝐢𝐦𝐩𝐞𝐫𝐟𝐞𝐜𝐭𝐢𝐨𝐧. Aviation marketing often shows us empty beaches, flawless cabins, perfect weather, and travellers who never look tired. The images are beautiful, but they can begin to feel interchangeable. People do not always connect with perfection. Sometimes they connect with an idea that feels playful, honest, and human. The campaign did not simply tell people that Iceland is photogenic. It invited someone to try to prove otherwise. That is a much better story. #AviationMarketing #AirlineMarketing #TravelAdvertising #BrandStorytelling #CreativeStrategy
-
This week, Booking.com released its annual sustainability report, and they’ve quietly dropped that broad (and somewhat meaningless) question: “𝗗𝗼 𝘆𝗼𝘂 𝘄𝗮𝗻𝘁 𝘁𝗼 𝘁𝗿𝗮𝘃𝗲𝗹 𝗺𝗼𝗿𝗲 𝘀𝘂𝘀𝘁𝗮𝗶𝗻𝗮𝗯𝗹𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗻𝗲𝘅𝘁 𝟭𝟮 𝗺𝗼𝗻𝘁𝗵𝘀?” Instead, the spotlight is on something much more tangible: 𝘁𝗼𝘂𝗿𝗶𝘀𝗺’𝘀 𝗶𝗺𝗽𝗮𝗰𝘁 𝗼𝗻 𝗹𝗼𝗰𝗮𝗹 𝗰𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝗶𝗲𝘀. The headline stat? 👉 For the first time, 𝗺𝗼𝗿𝗲 𝘁𝗵𝗮𝗻 𝗵𝗮𝗹𝗳 𝗼𝗳 𝘁𝗿𝗮𝘃𝗲𝗹𝗹𝗲𝗿𝘀 (𝟱𝟯%) 𝗮𝗿𝗲 𝗻𝗼𝘄 𝗰𝗼𝗻𝘀𝗰𝗶𝗼𝘂𝘀 𝗼𝗳 𝘁𝗼𝘂𝗿𝗶𝘀𝗺’𝘀 𝗶𝗺𝗽𝗮𝗰𝘁 𝗼𝗻 𝗽𝗲𝗼𝗽𝗹𝗲 𝗮𝘀 𝘄𝗲𝗹𝗹 𝗮𝘀 𝘁𝗵𝗲 𝗽𝗹𝗮𝗻𝗲𝘁. That’s a big leap toward a more holistic understanding of sustainability. For those of us in responsible tourism, this is the shift we’ve been waiting for: a move away from “green” checklists and towards 𝗽𝗲𝗼𝗽𝗹𝗲-𝗰𝗲𝗻𝘁𝗲𝗿𝗲𝗱 𝘁𝗿𝗮𝘃𝗲𝗹. Other key figures include: 🔍 77% seek ✨𝙖𝙪𝙩𝙝𝙚𝙣𝙩𝙞𝙘✨experiences that reflect local culture ❤️ 69% want to leave the places they visit better than when they arrived 🛍️ 73% want their spending to benefit the local community Travellers are now thinking beyond turning off the air con and reusing their towels. They’re asking: 💭 Who benefits when I visit? 💭 Am I supporting local livelihoods or global shareholders? 💭 Am I being a respectful guest? Not just to the land, but to the people who live there? This opens the door to deeper, more meaningful storytelling. Because travellers today don’t just want to tread lightly, they want to leave 𝗮 𝗽𝗼𝘀𝗶𝘁𝗶𝘃𝗲 𝘀𝗼𝗰𝗶𝗮𝗹 𝗳𝗼𝗼𝘁𝗽𝗿𝗶𝗻𝘁. So instead of leading with solar panels and water-saving toilets, 𝗹𝗲𝗮𝗱 𝘄𝗶𝘁𝗵 𝗽𝗲𝗼𝗽𝗹𝗲. Tell stories like: 🌿 How your community-led tours fund youth training or preserve indigenous heritage 🥗 How your menu supports a local organic farm 🤝 What your guests have learned from locals, and what locals have gained in return This is the kind of narrative shift that could 𝗿𝗲𝗱𝗲𝗳𝗶𝗻𝗲 𝘁𝗵𝗲 𝗳𝘂𝘁𝘂𝗿𝗲 𝗼𝗳 𝘁𝗼𝘂𝗿𝗶𝘀𝗺. Let’s not miss the moment. Read Booking.com’s 2025 Sustainable Travel report here: https://lnkd.in/eEZJEfp9 For more tips, 𝗱𝗼𝘄𝗻𝗹𝗼𝗮𝗱 𝗧𝗵𝗲 𝗚𝘂𝗶𝗱𝗲 𝘁𝗼 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗶𝗯𝗹𝗲 𝗧𝗼𝘂𝗿𝗶𝘀𝗺 𝗠𝗮𝗿𝗸𝗲𝘁𝗶𝗻𝗴 𝗵𝗲𝗿𝗲: https://lnkd.in/eEBjaCBv
-
Travel businesses that want to stand out must realise that travellers now value stories over destinations. The emotional resonance of a journey, how it feels, what is discovered, the connections made, has become the true currency of modern travel. Experiences need to be presented in a way that is not only visually striking, but also personal and genuine. The old marketing playbook of listing attractions and amenities no longer works; travellers are asking how a trip will change them, what memories they’ll gain, and how they’ll connect with others. For companies in both leisure and business travel, this shift is an opportunity: By crafting authentic narratives that showcase transformation, challenge, and adventure, brands build lasting loyalty. The business impact is clear, those who evoke emotion and foster connection attract repeat guests and generate organic growth through word-of-mouth. The most successful strategy is to invest in content that highlights real experiences and customer stories, not just polished brochures. How can your brand make every journey a memorable chapter in your client’s personal story? #Authenticity #Connection #Growth
-
The biggest cyber risk in your company isn’t AI. It’s your people. We’ve trained employees on security awareness. Yet phishing clicks, weak passwords, and shadow IT persist. Why? Because behaviour change doesn’t come from awareness. It comes from influence. Harvard Business Review nailed it: To build a security-conscious culture, CISOs must: ✅ Influence executive tone from the top ✅ Continuously measure behaviour (not just train it) ✅ Build trust and inspire change through shared values The frameworks we use—NIST, ISO, OWASP—guide systems and controls. But what about human behaviour? Frameworks like: ➡️ Neidert’s Core Motives (Connect, Reduce Uncertainty, Inspire Action) ➡️ Cialdini’s Principles of Influence (social proof, reciprocity, authority...) …should be in our security playbook — right next to NIST and ISO. Security that sticks is human-centred, trust-driven, and values-aligned. It’s about people, persuasion, and creating a culture where secure behaviour is the norm. #CyberLeadership #SecurityCulture #HumanCentredSecurity #CISO https://lnkd.in/eABd7pXq
-
One of the smartest travel campaigns I’ve seen recently didn’t come through sponsorship rights. It came through fan frustration. Air Transat has leaned into rising FIFA World Cup 2026™ - Canada, Mexico and the United States ticket prices by comparing the cost of attending a match with the cost of flying to the actual home nation fans support. A simple but sharp strategic pivot - for the price of one game ticket, you could instead experience the culture behind the team. That reframing matters, because the most effective travel marketing increasingly understands something many brands still miss - People don’t just travel for destinations anymore, they travel for identity, belonging and emotional proximity to the things they love. Sport is becoming one of the strongest accelerants of that behaviour. We’re already seeing it: > fans planning travel around tournaments rather than holidays, > sporting communities shaping destination preference, > airlines, tourism boards and hospitality brands moving from transactional messaging to cultural participation. What makes this campaign work isn’t just the data-driven execution. It’s the insight underneath it. The experience of football doesn’t only live inside a stadium. It lives in neighbourhoods, rituals, chants, language and collective emotion. That’s a far richer territory for travel brands to play in. With the FIFA World Cup kicking off in North America this month, I suspect we’ll see far more brands trying to tap into fan culture over the next 12 months. But I suspect few will do it this cleanly. #SportsMarketing #TravelMarketing #BrandStrategy #CustomerInsight #FIFAWorldCup
-
The JLR Cyberattack: A Wake-Up Call on Human Factors in Cybersecurity 🚨 The recent Jaguar Land Rover cyberattack that shut down global production for weeks offers a sobering lesson: **technology alone cannot protect us—people are both our greatest vulnerability and our strongest defense.** What Really Happened? 🔍 While headlines focus on the billions in losses and production shutdowns, the real story lies in the human elements: • **4-year-old stolen credentials** from a partner company employee infected by infostealer malware • **Social engineering campaigns** that made attacks more targeted and effective • **Legacy security practices** that left old credentials active and exploitable The attackers didn’t break through sophisticated firewalls—they walked through the front door using credentials harvested years earlier from an LG Electronics employee with Jira access. The Security Culture Challenge 💡 This incident highlights why we need to shift from a **compliance mindset** to a **security culture mindset**: Instead of asking:** “Did employees complete their security training?” 💡 Ask: “Do employees feel empowered to report suspicious activities without fear?” Instead of: “Are we using the latest security tools?” 💡 Ask: “Do our people understand their role as the first line of defense?” Building Human-Centered Security 🛡️ 1. Make Security Personal Help employees understand that cybersecurity isn’t just about protecting company data—it’s about protecting their jobs, their colleagues, and their customers. 2. Create Psychological Safety When someone clicks a suspicious link, do they feel safe reporting it immediately? Or do they hide it out of fear? The difference can determine whether an incident is contained in minutes or spreads for months. 3. Train for Reality, Not Compliance • Use real-world scenarios relevant to employees’ daily work • Focus on decision-making skills, not just rule memorization • Practice incident response through tabletop exercises 4. Extend Your Security Perimeter JLR was compromised through a third-party partner. Your security culture must include vendors, contractors, and anyone with system access. The Bottom Line 📈 The most sophisticated security stack in the world is worthless if an employee with 4-year-old compromised credentials can access critical systems. Cybersecurity is fundamentally a **people problem** that requires **people solutions.** Organizations that understand this—that invest in security awareness, create open communication channels, and treat every employee as a security stakeholder—will be the ones that survive and thrive. ----- 🤷♀️What’s your experience with building security culture? Have you seen human factors make or break cybersecurity efforts? Share your thoughts below. #Cybersecurity #SecurityCulture #HumanFactors #Leadership #RiskManagement #JLR #CyberAwareness JLR Anima People
-
The hardest part of security isn’t blocking attackers—it’s stopping our people from being recruited or overwhelmed. My final piece in “Selling Access: Insider Risk in Hard Times” is a practical playbook you can use this quarter. 🔰 IDF 2025—five layers: access, behavior, DLP, support/whistleblowing, fair response. 📣 Reporting confidence—unified channels, anonymity, close the loop. 🎓 Training that works—scenarios + recognition, not checkboxes. 🤝 Governance—Security × HR × Legal × Comms aligned with NIS2/GDPR/DORA. 📈 Metrics that matter—culture + detection KPIs boards use. 💙 New—empathy as a leadership control to surface risks earlier. This wraps our journey from phishing → bribery, through economic stress, to spotting human signals before data moves. If you lead security, HR, or teams, it’s a field guide to build trust and reduce loss. 💬 Tell me what’s working—or not—in your environment. I’ll compile the best practices in a follow-up. #cybersecurity #InsiderRisk #NIS2 #SecurityCulture #Leadership #CISO #CyberResilience