CYBR.Minded
CYBR.Minded is a cybersecurity podcast for leaders who know risk is not reduced by tools alone. Hosted through the lens of behavioral science, governance, culture, and executive risk, the show explores the human realities behind secure decision-making - from cognitive bias and trust to CISO burnout, board pressure, AI readiness, and the organizational dynamics that shape security outcomes. Built for CISOs, GRC leaders, cyber risk professionals, and board-facing security executives, CYBR.Minded helps listeners look beyond the controls and understand the human side of cybersecurity.
CYBR.Minded
The Human Factor with Dr. Calvin Nobles
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Organizations invest heavily in security awareness training - but risky behavior persists. In this episode of Cyber Minded, host Dr. Dustin Sachs sits down with Dr. Calvin Nobles, Portfolio Vice President and Dean of the School of Cybersecurity and Information Technology at the University of Maryland Global Campus, to explore why security awareness alone is insufficient when it comes to changing human behavior.
Things mentioned:
- Dr. Nobles Book, “Human Factors in Cybersecurity” – https://a.co/d/05zWEM6j
- Verizon data breach report - https://www.verizon.com/business/resources/reports/dbir/
Do you have a question for the hosts? Reach out to us at media@cscgroupllc.com
In this episode:
- Host: Dr. Dustin Sachs
- Guest: Dr. Calvin Nobles
- Production: Bill Brenner
- Editing: Lauren Andrus
Produced in partnership with Psybercog Labs
Keep up with our Conferences and Events:
Keep up with CYBR.SEC.Media:
Learn About CYBR.SEC.Careers Non-Profit Efforts
Subscribe to the podcast:
Listen to our other shows:
Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet. I'm Dr. Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cybersec Media, asks a simple question. What if the biggest risks in cybersecurity start with how we think, decide, and respond? Each episode is a chance to pause, reflect, and see security through a more human lens. Let's take some time and look beyond the controls to the human side of cybersecurity. Today, we're exploring a problem cybersecurity leaders have wrestled with for years. Why security awareness alone does not reliably change security behavior. Organizations invest in training, phishing simulations, policy reminders, and compliance modules, yet risky behavior still appears at the point of a decision. The issue is not about that people forgot the training. Often it's that security decisions happen inside real systems, real workflows, real pressures, and real human limitations. So today's question to think about at the start What does security awareness miss when it treats human behavior as a knowledge problem instead of a human factors problem? You know, the behavioral science answer is that knowing the right thing and doing the right thing aren't the same. People make security decisions under cognitive load, time pressure, fatigue, unclear incentives, confusing interfaces, competing priorities, and social influence, which we all know as peer pressure. Human factors help us examine the conditions around the behavior, not just the person performing it. That's the space that this podcast is built to explore. Cybersecurity depends on controls, tools, policies, and governance, but it also depends on attention, judgment, incentives, trust, communication, and behavior. Welcome to today's episode of Cyberminded. So, again, the real question that we're going to cover in this episode is what would cybersecurity look like if we stopped asking only whether people were aware and started asking whether our systems, controls, and workflows were designed for real human performance. I'm really excited today for our guest. My guest today is Dr. Calvin Nobles, portfolio vice president and dean of the School of Cybersecurity and Information Technology at the University of Maryland Global campus. Also a key contributor to my doctoral dissertation, whether he realized it or not. But Dr. Nobles is a cybersecurity leader, educator, human factors expert, and retired U.S. Navy officer whose work sits at the intersection of cybersecurity, human performance, workforce development, and systems design. His career spans military cyber operations, corporate security leadership, and academic program development. He's written and spoken extensively about human factors in cybersecurity, including stress, burnout, security fatigue, cognitive workload, and the limitations of simplistic human error narratives, all topics that anybody who knows me knows are my soapbox topics. He's also co-author with a very good friend of both of ours, Nikki Robinson, of the recently released book, Human Factors and Cybersecurity, a book focused on designing resilient, human-centered cybersecurity systems. I was fortunate to be a reviewer and read it, and it is phenomenal. Encourage everybody to pick it up. We'll have a link in the show notes. That makes him an ideal guest for today's conversation on what security awareness misses when it fails to account for human factors. Calvin, welcome to Cyberminded. Yeah, thank you for being here, please.
SPEAKER_00Yeah, it's always great to talk to you about this because I know how passionate you are about this topic. We probably could talk two or three days without any brace on this topic. So I'm happy to be on your show.
SPEAKER_01Yeah, it's always great to talk to the people who influence the work that I do, but also that I get to share a common passion with. But so before we get into the deeper parts of the conversation, I want to start with your perspective. And I ask everybody this question off the bat. When you hear the phrase the human side of cybersecurity, what does that mean to you? And where do you think the industry still misunderstands it? This is a fantastic question.
SPEAKER_00So when we when I hear that phrase, the human side of cybersecurity, to me, it's the most same point of cybersecurity. Because without the human aspect of cybersecurity, you can't advance cybersecurity at all. Because ultimately, in cybersecurity, the humans are responsible for everything about cybersecurity. And for me, when I see the advances that were made in cybersecurity, I see a lot of it around the technological aspect, and I see very little around really trying to understand the human behavior. And I make one critical point here, and that is if you look at most cybersecurity teams today and they look at most of their operations, very few, if any, have a dedicated staff expert who understands human behavior, human factors, cognitive psychology, or anything, neuroscience to help them understand human behavior and how people are going to perform within the ecosystem that they built. And so it's always a red flag for me. But at the same time, Dustin, I will say this the way cybersecurity has morphed into what it is today. One of the things that I say is that the problem that we face today with the human element in cybersecurity is not an industry problem alone. It's a government problem, it's an academia problem, and it's definitely an industry problem. And we need to work in that threesome there to fix and address the human element in cybersecurity.
SPEAKER_01Before we go further, this episode is supported by CyberCog Labs. At CyberCog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk. Because the issue is not that a control does not exist. It's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue. Visit us at cybercog.com. That's P-S Y R C O G dot com. Now, with that in mind, let's get into the problem beneath the problem. Yeah, that makes a lot of sense. Calvin, the topic for today is one I know you're very passionate about. It's what security awareness misses about human factors. I want to start with the distinction itself, because many organizations still treat the human side of cybersecurity as a training, communications, or compliance issue. So when cybersecurity leaders rely heavily on security awareness programs, what do they often miss about how people actually make security decisions?
SPEAKER_00That's a really good question. So I have this saying when I travel and I do keynotes and I do presentations across the globe, one of the things I always say is that everybody don't eat mayonnaise on their sandwich. And the reason I say that is because security awareness is applied, like it's applied in the form of a mayonnaise on a sandwich. You're gonna eat some of this mayonnaise today, whether you want it or not, right? But everybody don't eat mayonnaise, meaning that everybody doesn't learn the same, everybody don't take the information in the same, everybody don't process information the same. So one of the first things that I that I see right up front is that organizations don't offer different modalities for their employees to learn security awareness differently. So you're either going to get it through one modality, and that doesn't work for everybody. Some people like to be more hands-on, some people like to go home and just spend some time in the information, whether it's a computer-based training or whether it might be a PDF file or whatever it may be, people digest training differently. And so it's something that we miss a lot because we assume that once you get this training once a year, that it's that you're gonna remember everything you learn for the next 12 months. And that's not necessarily true where the literature tells us that if you don't reinforce the learning and the training that these people are going through, that in about four months, that understanding of what they just learned starts to taper off, and it's called the forgot theory.
SPEAKER_01Yeah. So how do you explain the difference between a security awareness problem and a human factors problem, though?
SPEAKER_00So when I talk about human factors, let me give a definition of that. As a human factors engineer, let me give the definition. When I say talk about human factors, is essentially, when we talk about it and apply it to cybersecurity, so essentially human factors is a way of building, designing systems, technologies, processing to account for human limitations and weaknesses within the environment in which they're going to work. In other words, how do we design, work, a system or even an ecosystem for people to have optimum performance and behavior? And so when you look at it from that aspect, when you look at security awareness, you say, how do I design security awareness to account for human limitations and weaknesses? And I'll be honest with you, we have not done that to this day. And we don't really account for the human element holistically. And that's why I say we apply the mandates to the sandwich. But one of the things that we can do is understand that training can be more realistic, training can be gamified, training can be a lot more productive. You know, I always tell the story of when I was in the Navy, I was a I was a shooter, kind of pumping a luncheon and arresting gear officer on the carrier. And one of the things on aircraft carrying, and one of the things I would tell you, we did training all the time. And the reason we did training all the time is so one, it would become second nature. And two, that training reinforced what we've already learned. And three, it enabled us to train the new sailors who was working on the aircraft flight deck. And that training became second nature that when the call for a fight on a flight deck and we were training for that, or aircraft coming in with a missing landing gear, whatever it may be, we were able to respond instantly because we've been put through the training. Unfortunately, in most organizations, they don't have that rigor and that much time to dedicate to a security awareness because that's a cost to the organization, and I definitely understand that.
SPEAKER_01Yeah, that distinction is important because as we've as we've said, and as I've said, and I know you've said it as well, the awareness assumes that the primary gap is knowledge. And human factors really asks a deeper question. What's happening in the environment around the person? Are the tools usable? Are the controls creating friction? Are employees making decisions under pressure? Are incentives aligned? Is the secure behavior actually practical in the workflow where the decision is happening? And that shifts the conversation from why did the person fail to what conditions made failure more likely? So, where do you see the biggest failure points when organizations design security controls without accounting for human performance?
SPEAKER_00I think the biggest failure in that whole point that you just made is that we don't have people with the expertise contributing to those cybersecurity teams and those decisions. In other words, a network engineer does not answer questions about software engineering issues. And the same thing, if you got an issue in the cloud, information technology is not going to answer a cloud engineering question. They might have some understanding about it, but they're going to go to a cloud engineer to get specifically the expertise they need. But when it comes to cybersecurity, again, we don't have anyone on our teams today that understands that. And the other thing I would tell you, Dutch, and you heard me say this before, we suffer a lot from the Dunning Krug effect inside of cybersecurity around the human element. And that is where we think we know more than what we know about the human element. But understanding the human element in cybersecurity is really scientific. And that's what human factors bring to bear. Human factors bring, and it listen, human factors is not the only tool when it comes to understanding human behavior in cybersecurity. Like I said, there's a group of experts that can really help us. But anyway, just having somebody to help you understand human behavior and how people are going to respond to what you have built for them is the biggest gap that I see today.
SPEAKER_01Yeah, and I love that you brought up Dunning Kruger because I think the other one that goes with that is blind spot bias. We don't think we have any, we don't think we have flaws in our decision making or we don't think we have flaws in our operations until they're pointed out to us. And then all of a sudden it's that you see it everywhere kind of scenario. But like you said, you and as we've talked about before, security awareness often also focuses just on the individual employee. Whereas it seems like human factors broadens the lens to include systems, workflows, interfaces, incentives, stress, fatigue, all of the kind of buzzwords that we always talk about, and really it kind of all groups under organizational conditions. So, how should CISOs, who may not be human factors experts themselves, think differently when they make the shift away from security awareness and start looking at it as more of the human factors system level thinking?
SPEAKER_00I love that question. And I will start with this one. And I'm gonna blame my fellow peers and my colleagues who work in higher education where we have failed industry in terms of educating cybersecurity professionals, previous cybersecurity professionals, existing cybersecurity professionals, and those that's coming through right now, but we are not preparing them to really understand the human element. There's a huge educational gap, right? And so it's hard to ask a chief information security officer to have an understanding of something when they haven't been trained on something. So this is where I believe that the higher education system and landscape can build courses where we know we have a gap educationally to say we need to build a course to educate chief information security officers and assisting cybersecurity professionals on what it means to manage human factors in cybersecurity. And that's one of the gaps we see. And I think because we have that gap exist, it's very difficult to ask a sitting chief information security officer to go out and say, what do you know about the human factor? Because human factors mean so many things to different people, right? And I have to put that on the table. I did a research paper on it, and I looked at a hundred different research papers on human factors, where each paper defined human factors, and there were 17 different definitions of what human factors was or could be, right? And so I think that hurts too when we say when we talk about human factors, we could be in a discussion, and each one of us are talking about a different definition of what it means. And so I think one of the things that we have to do as scholars practitioners is make sure we standardize the language. So when we are communicating with each other, we're talking in the same vein and not talking passively across the gym.
SPEAKER_01So you said two things that I definitely want to emphasize. First of all, you used probably my favorite phrase, the one that's been beaten into me, sorry, trained into me by my doctoral program, which was the idea of scholar practitioner. And I love that idea. The fact that we've got the academic who also is the practical practitioner, and that's you know, that's really something that I've tried to embrace in my postdoctoral experience. But the other thing that you mentioned is the different definitions of human factors, and that's really why we asked the question at the beginning of the podcast that we always ask, which is what is the definition of what does human factors mean to you? And yeah, this is only the second episode, but I think it'll be really interesting to go back 10, 15, 20 interviews from now and see how different every person's answer is to that question. I think it's gonna really prove out and validate the research that you've done. If there's one takeaway for leaders in this first part of this conversation, it's that awareness is not wrong. It's incomplete when it becomes the default answer to every human-centered cybersecurity failure. We see the Verizon data breach report every year, and we go, Oh, yeah, it's a human problem. That's incomplete. It's it's incomplete. So that's I think the biggest takeaway for this first part of the conversation. I want to move from the conceptual distinction to what leaders can actually do with it. Most organizations can measure awareness activities, and they measure them the same way: training completions, fish click rates, policy attestations, campaign participation, but those metrics don't always tell us whether human factor risk is actually decreasing. So, what should organizations measure if they want to understand human factors risk more accurately than the traditional awareness metrics allow?
SPEAKER_00I think there's some things that they can do that's really on the surface to really help them understand the whole cybersecurity environment. And one of the things they can do is do a survey to understand and ask the question how complex are our cybersecurity operations? Because most people don't understand that if you are sitting in an organization and you're a cybersecurity professional, you understand things because that's where you live, eat, and sleep every day, right? But what does that look like for someone who works in HR or someone who works in logistics or someone who might be an engineer that's not on the IT and security side, right? It might look and sound very differently to them. So I think you gotta ask the question how complex is our how complex are the cybersecurity operations? I think you have to ask, do you understand the cybersecurity policies? Because we know policies to help drive behavior and shape behavior. I think the other thing that they can do is really understand what makes people very fearful.
SPEAKER_01This episode is brought to you in part by Cybersec Media, a cybersecurity media and community platform built for practitioners, leaders, and innovators who want sharper conversations about the human, technical, and operational realities of security. And if you want to be part of that community in person, get your tickets now for CybersecCon, happening September 15th and 16th of 2026 in Houston, Texas. Join cybersecurity leaders, practitioners, researchers, and innovators for two days of insight, connection, and actionable strategies. Secure your spot today at cyberseccon.com. That's cyber without the e at S E C C O N dot com.
SPEAKER_00Is really understand what makes people very fearful. We have a lot of people that come to work every day who are absolutely fearful about working in an environment where there's so much technology, there's so many things that we've implemented. Like I have a I know someone who gets up early every day and they log in for work about 90 minutes early every day. And the reason they log in early is because it was like, I don't want to make a mistake, I don't want to log in late because I have problems logging in sometime and I don't really understand how that technology works. So I want to be, if I got an issue, I want to make sure I identify early and I'm able to log in and get the IT uh help their support in case I have an issue, right? And I'm like, man, that's a lot of time. That's 90 minutes out of that person's day that they are concerned about logging in. Even if they log in successfully, they're logging in early, right? So I think to me, that highlights a usability issue, that highlights a design issue. And the other question that I would ask the chief information security officer is when they're implementing technologies or changing processes and procedures, how often are you bringing in different personas from your organization to say how will this work with you? Whether you might be, I just picked somebody around my parents' age. You might be 75 and still coming to work every day, or you might be somebody my age in mid 50s and say, How does this work with you? Or you might have someone who just joined your team who might be 21, right? Across these different demographics, how are the technologies and the processes and procedures you're implementing impacting different personas? Because we don't do that on a regular basis. And that's where I think we can get we can. Glean so much information is by asking very simple questions rather than thinking that these problems are these problems don't exist. Let's glean that information to see what problems are beneath the hood.
SPEAKER_01Wait, so are you saying that information security professionals should actually go out and talk to people? That's such a revolutionary idea. Maybe you should talk to the people in your organization before you create things. You know, but the other thing that you brought up, you know, this the whole starting 90 minutes early is even if, as you said, they get logged in on time, they're already coming in in a heightened state of stress. Yes, because they they started from that stressed point. And as we all know, because we've all experienced it, when you start stressed, going from 100 to zero is a lot harder than going from you know, perfectly calm to stressed out. Everything you're saying really feels like a practical maturity step. As we said again, awareness asks, did we tell people what to do? Human factors asks, did we design the environment so that the secure action is understandable, usable, timely, and sustainable? All the things you just mentioned. For cyber risk leaders, that has governance and implications. It changes what we measure, what we report, how we explain control failures, how we prioritize interventions, and really how we build the relationships that we build in organizations. And it it all makes things better when we shift our focus away from can we get somebody in trouble for not doing what they what we told them to do, versus can we create an environment that makes it safe for them to do their job as effectively as possible? Given everything we've discussed about awareness, human factors, control design, and the way that cybersecurity frames human behavior, I want to close with the question that we ask every guest on Cyberminded. What is one place where cybersecurity, the cybersecurity field, needs to slow down and think more carefully?
SPEAKER_00One of the things that I came across in my research was that the constant integration of technology doesn't make an organization more secure. What makes an organization more secure is understanding the human element. Because once you have the human element piece aligned, you can actually drive down organizational risk. I'm not saying that you wouldn't you won't ever need to use technology because as the environment continues to evolve and change, technology is definitely one of the things that we can leverage to make things easier. But I believe that you solidify the human element and understand what you're really trying to pursue in that. Because one of the things that human factors bring to the table is intentionally design the environment for what you want to optimize performance and behavior. And by doing that, you're also going to drive out organizational risk.
SPEAKER_01Yeah, and and again, I think that really sums it up well. And I know that's a large part behind the book that you just wrote, that you and Nikki just wrote, and a lot of the work and speaking that you're doing. So, you know, anybody who's listening should absolutely check out the work that Dr. Nobles is doing. But today's conversation really challenged one of cybersecurity's most familiar assumptions that if people know more, they're going to behave more securely. And Dr. Noble helped us examine what security awareness often misses: the role of cognitive load, workflow friction, stress, fatigue, incentives, tool design, and organizational pressure in shaping security behavior. And if you were playing podcast bingo, you probably just won because I used every keyword that I could think of. But the human side of cybersecurity is not just about education, it's about designing systems where secure behavior is understandable, practical, timely, and sustainable. My thanks to Dr. Calvin Nobles for joining the conversation and to CyberCog Labs and Cybersec Media for supporting the show. As always, until next time, look beyond the controls and pay attention to the human side of cybersecurity. Thanks, everyone. We'll see you again on the next episode.
SPEAKER_02This has been a Cybersec Media production recorded in partnership with CyberCog Labs. Cyberminded is hosted by Dr. Dustin Sachs. It's directed by Bill Brenner, produced by Lauren Andris, and edited by Ivan Basconcillo. The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. This show is for informational purposes only and does not render or offer to render personalized advice. Subscribe now so you never miss an episode. You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com. That's cyberwithout the e. And follow cybersecmedia on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube. You can keep up with our conferences by following us on LinkedIn, X, Instagram, and Facebook at Cybersec Events. And you can learn more about our events or buy tickets at cybersec.community slash cybersec.