The Deficit Thinking Trap: Why Knowing Better Doesn't Lead to Better Security Behavior
The Deficit Thinking Trap: Why Knowing Better Doesn't Mean Doing Better There's a question that should make every security professional uncomfortable: if our users already know they shouldn't click suspicious links, why do they keep clicking them? π€ We've been running security awareness programmes for decades, and yet breach after breach still starts with a human. So what's going wrong? One answer lies in a flawed assumption β one that psychologists and public health researchers abandoned years ago. It's called deficit thinking. Thatβs the belief that poor decisions stem from a lack of information, and that simply giving people the right facts will change their behaviour. To our logical, IT-professional brains, that sounds entirely reasonable. It's also wrong - and neuroscience has been telling us so for thirty years. π³ In his 1994 landmark work βDescartes' Errorβ, neurologist Antonio Damasio dismantled the idea that decisions are purely rational. He studied patients with damage to the emotional centres of the brain. These were people with perfectly intact IQs, who could solve complex puzzles and pass knowledge tests, yet they couldn't make simple everyday decisions - choosing what to eat, managing money, picking between two options β all became paralysing exercises in endless deliberation. Why? Because without emotion, decision-making breaks down entirely. π Damasio showed that healthy brains use somatic markers β gut feeling, or emotional shortcuts β as rapid filtering mechanisms. These aren't noise cluttering up our rational thinking - they are the thinking. Logic and emotion work together, and when emotion is absent, even the smartest people can struggle and make poor choices. So what does this mean for security awareness? It means that handing someone a training module and expecting behavioural change is just wishful thinking. Itβs like being on a weight loss journey. You know precisely what you should eat, and can recite the basics of a healthy diet without hesitation, yet knowing it and doing it when you're tired, stressed, and someone's put birthday cake in the office kitchen are entirely different things. π The emotional and contextual wiring to act on your knowledge in that moment is where the gap exists. Consider what attackers actually exploit β urgency, fear, authority, the anxiety of a deadline π¬. These are precisely the emotional triggers that Damasio's somatic markers engage with & respond to. A phishing email that creates panic is bypassing rational thought deliberately, and a training video watched six months ago has almost no emotional weight in that moment. It simply isn't in the fight. Deficit thinking also ignores:
Context β under pressure, the brain defaults to fast, emotional shortcuts, not careful risk calculation;
Environment β if the secure choice is harder than the insecure one, you've already lost before awareness enters the picture.
This is where Adaptive Defence reframes the challenge entirely. Rather than asking "did they receive the training?", it asks "what shaped their behaviour in that specific moment?" Effective interventions are contextual, timely, and emotionally resonant β a nudge at the point of risk, not a lecture delivered weeks before the threat arrives. The science is clear: we are not rational actors who occasionally get emotional. We are emotional actors who occasionally get rational. Security programmes that ignore this will keep solving the wrong problem. Over to you:
Do your users know what good security behaviour looks like β but still don't do it? What factors do you see driving that gap?
Have you found that interventions work better at an emotional level, rather than just an informational one? What were the best ones?
Are we too focused on what people know and not enough on the various environmental forces we're asking them to operate within? How can we change these forces?
