Evidence reveals the patterns behind human cyber risk.
More than 107,000 research observations, peer-reviewed analysis, and international scholarly exchange form an evidence base for understanding how psychology, behavior, and communication shape cybersecurity outcomes.
The evidence points to one consistent conclusion.
Attackers exploit human and organizational conditions as deliberately as they exploit technical weaknesses.
Materially influences cybersecurity outcomes.
Trust, authority, urgency, and communication shape cyber risk.
Remains essential—but cannot address the human dimension alone.
Shapes how exposure forms and how decisions are made.
Complements technical controls with behavioral understanding.
From observation to defensible insight.
Evidence becomes useful when observations survive measurement, review, publication, and scholarly exchange before they are translated into intelligence.
Research observations
Large-scale observations establish the empirical base.
Psychological patterns
Factors and attacker sophistication become measurable research problems.
Peer review
Findings are documented, challenged, and refined through scholarly review.
Research record
Peer-reviewed work makes the evidence inspectable.
Scholarly forums
Research is presented across international academic and security communities.
Defensive intelligence
Evidence becomes behavioral intelligence and organizational guidance.
A sustained investigation into the human mechanics of cyber risk.
The program began with doctoral research that reframed social engineering as a human decision problem, then matured through peer-reviewed scholarship, measurement, synthesis, and behavioral characterization.
Characterizing Internet-Based Social Engineering Attacks Through a Psychological Lens
This doctoral research established the psychological perspective that became the foundation for the subsequent IEEE, Springer, and international research contributions presented below.
Four published contributions extend the foundational investigation into an inspectable research record.
Internet-Based Social Engineering Psychology, Attacks, and Defenses: A Survey
A comprehensive synthesis connecting psychology, social engineering attacks, human vulnerability, and defensive strategy.
View publication record →Quantifying Psychological Sophistication of Malicious Emails
A measurement-oriented approach to identifying cognitive and behavioral manipulation patterns in malicious emails.
View publication record →Characterizing the Evolution of Psychological Factors Exploited by Malicious Emails
Evidence showing how recurring psychological factors become exploitable patterns in cyber attacks.
View publication record →Characterizing the Evolution of Psychological Tactics and Techniques Exploited by Malicious Emails
Analysis of attacker tactics and techniques as decision-shaping mechanisms rather than simple message content.
View publication record →A connected record of measurement, publication, and scholarly exchange.
The record progresses by strengthening the evidence—not by repeating the research journey already shown on the Research page.
Psychological factors identified
Focused analysis examines recurring psychological factors in malicious communication.
Sophistication quantified
Research advances from describing malicious emails toward measuring psychological sophistication.
Human-centered evidence consolidated
Large-scale analysis and the Proceedings of the IEEE survey establish a broader evidence base.
Tactics and factors characterized
Attacker tactics, techniques, and psychological factors are documented through Springer research.
Evidence tested across research and security communities.
International presentation places the work in scholarly conversation and connects research quality with practitioner relevance.
Copenhagen
SciSec 2024Two research presentations on psychological factors, tactics, and techniques.
Melbourne
SciSec 2023Psychological sophistication research presented internationally.
Colorado
N3SP · USAFAResearch presented to a national security and cyber audience.
UCCS / UW Tacoma
CWSSPResearch shared across academic and practitioner communities.
Research becomes valuable when findings change what defenders can see.
Cognitive Cyber Defense translates human-centered research into intelligence that helps organizations understand exposure before treating every human risk problem as an awareness problem.
Evidence should inform strategy.
Explore how human-centered research can strengthen the way your organization understands exposure, prioritizes intervention, and makes security decisions.