"Is Your Brain Wired for Insecurity?" - AJ King on Behavioural Science
Manage episode 492301414 series 3672475
This week on The Awareness Angle Interviews… Anthony sits down with AJ King, a UX researcher and behavioural science expert, to explore what it really takes to change security behaviour.
Forget check-the-box training and flashy nudges—this episode gets into the messy, human side of behaviour change, why habits are hard to break, and how your gym routine might just explain why people keep clicking phishing links.
🧠 Why People Don’t Remember Training – AJ breaks down the cognitive reasons annual awareness programs often fall flat.
🎯 Nudges Aren’t Enough – We explore why simple prompts can help—but won’t fix—behavioural gaps without deeper engagement.
💪 The Gym Metaphor – Building secure habits is like fitness: it takes consistency, relevance, and personal motivation.
📈 Beyond Compliance – Compliance might drive reporting, but it rarely changes how people actually act.
🔁 Repetition & Real Life – Training sticks when it reflects daily behaviour—not once-a-year reminders.
📣 Speaking Their Language – Why tailoring awareness efforts to people’s lived experience matters more than security buzzwords.
🤝 Behavioural Science Meets UX – AJ shares how user research and human-centred design can elevate your awareness program from frustrating to effective.
💬 Feedback as a Force Multiplier – What users tell you (and what they don’t) can reshape how you teach security.
⚖️ Fear vs. Motivation – We talk about the psychology of risk, and why scaring people isn’t a sustainable strategy.
🔄 Security is a Human System – Tools help, but behaviour drives outcomes. Awareness needs to meet people where they are.
If you're trying to move the needle on secure behaviour—not just track who opened the training email—this one's packed with fresh thinking, honest insights, and practical ways to rethink your approach.
The Awareness Angle: Interviews is our ongoing series of real, no-fluff conversations with the people reimagining how we approach security, risk, and human behaviour.
🕒 Timestamps
00:00 – Why AJ’s Here: Behaviour and Security01:29 – Why AJ is Ant’s go-to behaviour guy03:06 – What actually *is* human behaviour?05:15 – Why behaviour change isn’t a 5-minute training course09:02 – The problem with “mandatory training”12:09 – Should we focus on personal security instead?14:25 – Does compliance culture harm behaviour change?18:35 – Why annual training is a compliance box, not a solution20:11 – The myth of the nudge silver bullet24:31 – Present bias and procrastinating secure behaviour30:45 – You can’t predict when behaviour will matter32:44 – Engagement is everything: the gym metaphor34:05 – Why nudging alone won’t work for everyone38:06 – What should the function be called – and does it matter?42:46 – Reframing security for leadership48:06 – Using behavioural change to get more support from the top56:05 – Fear vs Reward: What really works?59:01 – Phishing screen colours and peer influence01:03:13 – Simulated phishing: don’t destroy your brand01:08:04 – Be the purple cow – standing out in awareness01:14:11 – Nudges, newsletters, and long-term behaviour change01:18:41 – Book recs: Freakonomics & Very Good Copy01:21:09 – AJ will be back for The Art of Change01:22:45 – Where to find AJ King
💬 Check Out This Episode's Discussion Points
📧 [email protected]
🔗 riskycreative.com
🎵 Our Intro & Outro Song (© 16! by falling forever)
License: https://creativecommons.org/licenses/by/4.0
39 episodes