Cybersecurity Requires Technology and Behaviour Change

Auteur zonder afbeelding icoon
Behaav
17 August 2026
4 min

Cybersecurity Requires Technology and Behaviour Change

Cybersecurity requires technology and behaviour change

Cybersecurity has evolved far beyond a purely technical challenge. For many organisations, information security has become an essential part of strategic risk management. Digital resilience directly affects business continuity, reputation and compliance. As organisations become more dependent on digital processes, supply chains and data, cyber risk increasingly becomes a boardroom issue.

The role of the CISO reflects that shift. Where cybersecurity was once primarily associated with technical measures, security leaders are now expected to understand how cyber risks affect business objectives and advise management accordingly.

“Organisations are looking much more closely at how cyber risks affect their business objectives,” says Rudy Spinola, co-founder of Behaav. “If a company enters a new market or introduces new digital processes, cybersecurity becomes part of that strategic discussion. Which new risks does that create, and how do we manage them?”

Technology is changing human risk

This shift also changes the way organisations should think about employees. People are not simply users of systems. Every day, their decisions can either reduce or increase cyber risk. Technical controls remain essential, but they cannot remove the human factor. Employees need access to systems and information to do their jobs. Attackers know this and increasingly try to influence people’s decisions instead of relying solely on technical vulnerabilities.

Artificial intelligence is accelerating that development. Generative AI makes it easier to create convincing phishing emails, personalise attacks and imitate trusted colleagues or executives. Microsoft Threat Intelligence has already reported campaigns in which AI was used to create highly personalised phishing messages based on a victim’s role and working environment. At the same time, Verizon’s Data Breach Investigations Report continues to show that the human element plays a significant role in cyber incidents.

The combination is important. Human behaviour is already a major source of cyber risk, while AI is making attacks on people more convincing and scalable. The challenge is therefore no longer simply whether employees can recognise an obvious phishing email. It is whether they make the right decision when a request looks legitimate, feels urgent and appears to come from someone they trust.

From awareness to behaviour change

This development requires organisations to look differently at security awareness. Traditional awareness programmes often focus on transferring knowledge through training, phishing simulations and communication campaigns. These activities remain useful, but knowledge does not automatically lead to secure behaviour.

An employee may know that an unusual payment request should be verified and still act differently when the request appears to come from a senior executive shortly before an important deadline. Effective security awareness should therefore start with risk. Not every employee has the same responsibilities, access or exposure. An HR department faces different risks from finance or sales and should not automatically receive the same interventions.

The objective is not simply to make employees more knowledgeable. It is to help them act securely at the moments where risk occurs. This requires targeted interventions that fit within daily work. Timing and context matter. A short prompt delivered when someone is about to perform a risky action can be more effective than generic information delivered months earlier.

“It is about meeting people where they work,” says Spinola. “Security should become part of everyday processes rather than a separate obligation.”

Making human cyber risk manageable

A more mature approach therefore goes beyond individual awareness campaigns. Organisations need to understand which behaviours create risk, identify where improvement is needed, introduce relevant interventions and measure whether behaviour actually changes. At Behaav, this is approached as a continuous process combining assessment, education, behavioural interventions, communication and measurement. Activities are linked to specific risks, target groups and organisational objectives rather than applying the same programme everywhere.

This also changes how security awareness can be discussed at management level. Instead of reporting mainly on training completion, phishing click rates or campaign reach, security teams can work towards measurable behavioural objectives. These might include reducing specific incidents, improving the reporting of suspicious situations or changing behaviour within high-risk processes. Data can then be used to determine where progress is being made and where additional intervention is required.

Ultimately, management needs to be able to answer a simple question: are we actually reducing human cyber risk? If human behaviour is considered an important part of cybersecurity, organisations should also be able to demonstrate how that behaviour develops over time.

Why Cybersec Netherlands matters

Cybersecurity challenges are becoming increasingly interconnected. AI affects attack methods, regulation influences governance, technology creates new opportunities and risks, and human behaviour remains an important factor throughout.

That is what makes events such as Cybersec Netherlands valuable. They bring together security professionals, technology providers, policymakers and specialists with different perspectives on digital resilience.

Cybersecurity cannot be solved from a single discipline. Technical controls will remain fundamental, but organisations also need to understand how people behave when they receive an urgent request, share sensitive information or are approached by someone pretending to be a trusted colleague.

Building digital resilience therefore requires both strong technology and an organisation in which secure behaviour becomes part of everyday work.

Behaviour change. Assured.

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!