Jakob Lange

03 Field · SEC

Security Behaviour

Security fails at the keyboard. Assess how people actually behave under pressure, then train and design for it.

The majority of successful attacks do not exploit a software vulnerability. They exploit a person who was busy, helpful, tired, or simply following a process that made the unsafe action the easiest one. Technical controls matter, but the deciding variable is behaviour — and behaviour can be observed, understood and changed.

Why this matters now

Generative AI has collapsed the cost of convincing deception. Spear-phishing emails in flawless German, voice clones of the CFO, fake vendor portals built in an afternoon: the “obvious tells” that awareness training relied on for a decade are gone. Meanwhile, the same AI tools inside your organisation create new surfaces — an engineer pasting credentials into an assistant, an agent acting on a manipulated document, a support bot that can be talked into revealing data.

Regulators have noticed. DORA, NIS2 and sector guidance now expect evidence that awareness measures are effective, not merely delivered.

How I approach it

My background is in interdisciplinary research on how humans interact with complex, security-critical systems. That shapes the method: before any training, I assess. Structured observation, interviews, workflow analysis and controlled simulations reveal why unsafe behaviour occurs — time pressure, ambiguous responsibility, tools that punish caution — and that diagnosis drives the intervention.

Training is then designed for the actual teams: engineers, operations, finance, leadership, each with their own attack surface and their own language, often across cultures. Sessions are interactive and measured, and results feed a culture dashboard that management can act on and regulators can read.

Where it typically starts

A four- to six-week behaviour assessment of one business unit or one critical process, including a simulation baseline. From there, a training programme, a redesign of the riskiest workflows, or both.

Questions I am usually asked

  • Our staff pass the annual e-learning. Why do they still click?
  • How do we measure security behaviour without turning the company into a surveillance state?
  • Deepfake voice calls and AI-written spear phishing — how exposed are we, realistically?
  • Our engineers use AI coding assistants. What new social-engineering surface does that create?
  • How do we build a security culture across three countries and four languages?

Typical deliverables

  • Behaviour assessment report with observed risk patterns and root causes
  • Simulation results and resilience baseline
  • Tailored training programme with measurable outcomes
  • Workflow and permission redesign recommendations
  • Security culture dashboard for management reporting

Contact

Start with a conversation.

No forms, no funnels. Write me a short note about your situation — I answer personally, usually within two working days.

Mon – Fri, 18:00 – 20:00 CET