Cyber Psychology: The Hidden Human Factor Behind 80% of Cyber Attacks

Jun 8, 2026 | Risk-!n

Summary

At Risk-!n 2026, cyber psychologist Sarah Pauli sat down with Philippe Séjalon to discuss the often overlooked human side of cybersecurity. Drawing on economic psychology, she highlights that as far back as 2014, Deloitte found 80% of zero-day attacks stemmed from human behavior, including social media oversharing and compromised personal devices. Moving beyond standard phishing awareness, Pauli focuses on deeper psychological dynamics inside organizations. Her advice is simple but powerful: practice digital detox and think before you share.

A New Discipline at the Crossroads of Psychology and Digital Risk

At Risk-!n 2026, Philippe Séjalon had the opportunity to speak with Sarah Pauli, a cyber psychologist and one of the first professionals in this emerging field. Rooted in economic psychology, her work focuses on human behavior, emotions, and dynamics in the digital world, with a particular emphasis on cybercrime and the risks that people unknowingly create for themselves and their organizations.

The Human Factor: The Most Underestimated Threat

Sarah Pauli points to a striking statistic: back in 2014, Deloitte already reported that 80% of all zero-day attacks against companies originated from the human factor. This includes employees casually discussing company matters in their personal lives, oversharing on social media, or simply carrying a compromised personal device into the workplace. According to Pauli, your private mobile phone may be the single greatest security risk you bring through the office door each day.

Beyond Phishing: The Hidden Dynamics in Organizations

While most people are familiar with security awareness training and phishing simulations, Pauli focuses on something deeper. She is particularly interested in the effects that are harder to detect and slower to surface within organizations. Rather than addressing the obvious threats, her approach uncovers the subtle psychological patterns and social behaviors that quietly expose companies to significant vulnerabilities. Her work sits firmly outside clinical or forensic psychology, staying grounded in organizational and economic behavior.

Two Simple but Powerful Rules to Stay Safe

When asked for practical advice, Pauli kept it clear and direct: practice digital detox, and think before you share. In a world where oversharing has become second nature, these two principles serve as a powerful reminder that human awareness remains the first and most essential line of defense in cybersecurity.

Share this article

Sponsors & Partners

Risk-!n
thebrokernews
RiskAwarenessWeek

Solutions to boost your business!

Increase your productivity

Increase your productivity

We solve YOUR problem, fast. We ask you questions about the key problem you want to solve and  build an initial prototype within 1 day. You only review and approve. Tell us the problem that’s slowing your team, and we’ll handle discovery, design, integration, and...

read more...
Attract more attendees to your event

Attract more attendees to your event

Make the buzz! As an event manager, your goal is not simply to promote an event. It is to create an experience that feels relevant, valuable, easy to access, and worth talking about. Your attendees are experienced professionals with ideas worth sharing. Give them...

read more...
Show your experience and get leads

Show your experience and get leads

Share your expertise with the insurance, risk, cyber, and AI community Publish an article or expert video with The INGAGE Institute and reach professionals who care about practical insight, innovation, and real industry experience. Start now!   Why publish with...

read more...
Boost your presence on LinkedIn

Boost your presence on LinkedIn

Finally write strategic LinkedIn comments in your own voice. Writing posts on LinkedIn in the hope of being shown to the World does not work.  The new way to do it in 2026? Writing comments!  Elevate helps you write strategic comments in minutes – plus posts and DMs....

read more...