Community News Security

Why the best security behaviours are the ones nobody has to think about

Banner to promote an interview with Professor Kristin Weber
Kristin Weber

Words: Jody Williams

Ask anybody working in security awareness what they’re trying to achieve, and you’ll usually hear a variation of: get people to think before they act.

Prof. Dr. Kristin Weber suggests a complementary approach: building security-conscious habits among staff, students and researchers. “I sometimes think salience and habits are opposites. Salience means I have to actively think. I have to know that I need to do a particular thing now. Habits are just automatic, which makes them very powerful.”

An ingrained habit will persist even on the hectic days when you have zero spare attention for awareness posters or email banners.

“It’s exactly in busy, stressful situations that habits can help us, because they just kick in. I don’t have to think about it, I just do the same action every time, every day, maybe every hour. It doesn’t matter what’s happening around me, I’ll still do it.”

Kristin is Vice President for Digitalisation and CIO at the Technical University of Applied Sciences Würzburg-Schweinfurt (THWS), where she teaches and researches the human factor in information security. This year, Kristin is delivering the keynote webinar — The psychology behind secure habits — for GÉANT’s awareness campaign, which is built around the theme ‘Small habits. Big impact.’

Knowing the rules isn’t enough

Kristin is clear that knowledge still matters. “We need the whole picture. Knowledge is important, behaviour is important, habits are important.”

But knowing a rule doesn’t automatically lead to following it — or we wouldn’t still see passwords written on scraps of paper, dodgy links clicked on, or documents forwarded to a personal account for home printing.

“Very often we know the rules, we know how important security is and what we should do. But we just can’t translate this knowledge into action. That’s sometimes a big, big hurdle.”

Habits can help overcome that hurdle.

Which behaviours can become habits?

Our lives are shaped by dozens of tiny habits, from fastening seatbelts when getting in a car to brushing teeth after breakfast. They’re a useful tool, but they only work in specific situations.

“A habit has to be repetitive behaviour which always has the same trigger, in the same environment. And it needs to be something you do really, really often.”

This gives you two tests to assess whether you can create a habit out of a specific behaviour:

Does it have a consistent, frequent trigger? Screen locking has an excellent one. If you work at a desk, you’ll stand up to walk away several times a day. “You have a perfect trigger to lock your screen: it’s the same every time.”

Email checks are another good candidate. “Before clicking on an email, check it. It’s not as good a trigger as leaving your desk, but it works.”

By contrast, creating or changing passwords happens too infrequently to form a habit around.

Is it small enough? This is where Kristin thinks most attempts go wrong. “‘Check an email for signs of phishing’ is too broad, too big.” It’s not clear to everyone exactly what that means in practice.

Aim for actions that take just a second or two: before you click a link, check whether the URL is spelled correctly. Before you leave your desk, close your laptop.

“Pick something really tiny, like checking the file type of an attachment before you open it. It’s easier for tiny behaviours to become a habit.”

Examples of secure habits to build

Kristin has identified many small behaviours that make good candidates for habit-building, including:

  • Classify a new document the first time you save it
  • Check nobody can see the keyboard before you enter a password or PIN
  • Check nobody unauthorised can listen in when you answer a phone or video call
  • Log out of application systems before your lunch break
  • Switch on the VPN when working on a train or in a café
  • Shut down your computer at the end of the working day.

Each takes seconds, and comes with a reliable trigger.

When habits aren’t enough

“Habits won’t solve all our problems. It’s not possible to install habits in every behaviour,” says Kristin. “Scam phone calls asking for my password only happen infrequently, and with different voices and messages. So that’s not something I can turn into a habit.”

Even a well-established habit can be overridden, which is why Kristin points to a skill people can only build for themselves: spotting the situations that make them act impulsively. Once, when receiving a flattering email inviting her to be interviewed, Kristin opened the attachment before she’d performed her usual checks. Fortunately, it was legitimate.

“As a researcher, you like to be interviewed and asked about your expertise, so this invitation really triggered me to override my usual secure habits. Now I know I respond to those triggers, I’m especially suspicious in those situations.”

Kristin talks openly about her own slip-ups so her students see such mistakes as normal rather than shameful. “You cannot get 100% security. That’s impossible. As a security professional, you need to know that mistakes will happen, and prepare for that.”

Getting the conditions right

Encouraging staff and students to build secure habits is easier when the conditions are right. Firstly, a pragmatic focus on viability. Nobody will form a habit around something that gets in the way of their job, so test your security mechanisms with the people who have to use them, and change what doesn’t work in practice.

Secondly, a positive security culture rather than a blame culture. Kristin recently rewrote a letter her university was legally required to send about a data protection breach, softening the stern language and acknowledging the mistake wasn’t the recipient’s fault.

“If you have negative emotions about a topic then you don’t learn anything and you don’t want to deal with it. We want people to know they can come to us if there’s something wrong, and we’ll help them.”

How habits form, and how to break them

Picking the behaviour you want is the first step, and turning it into a habit is the next and bigger task. How many repetitions before a habit becomes automatic? What role does positive feedback play, and does celebrating a tiny success really help it stick?

There’s also the reverse problem. Most of us already have habits we know aren’t ideal, from immediately opening email attachments to holding the door for whoever’s walking in behind us. The good news is you can apply the same principles to breaking an established habit as to building a new one.

Kristin covers the psychology behind habits in the webinar, with practical tips and examples beyond those shared here.

Small enough to stick

The beauty of a secure habit is that once established, it doesn’t make any demands on your attention. It just runs in the background whenever it’s triggered.

The catch is this only works if you choose your target habits carefully. Pick a behaviour with an erratic trigger, or one too big to do without thinking, and no amount of effort will make it automatic. Pick a tiny one that’s prompted by the same situation day after day, and there’s a good chance it will still be working long after the awareness campaign posters have come down.

Tune in on 10 September 2026 for Kristin’s webinar, The psychology behind secure habits, to learn more about how habits form, how you can support them in your own organisation, and how to break the insecure ones, with examples from everyday life and information security. 

About Kristin Weber

Prof. Dr. Kristin Weber

Prof. Dr. Kristin Weber is Vice President for Digitalisation and CIO at the Technical University of Applied Sciences Würzburg-Schweinfurt (THWS). As a professor in the Faculty of Computer Science and Information Systems, she researches and teaches the human factor in information security. She’s also an author, speaker and consultant in security awareness, ISMS, data governance and data quality management, and served as THWS Information Security Officer from 2017 to 2024.

About the author

Davina Luyten

Davina Luyten is communications officer at Belnet. She has a background in translation, journalism and multilingual corporate communication. At Belnet, she focuses on external communication, public relations, crisis communication and security awareness. She has participated in the GÉANT project since 2020, where her involvement includes the annual cyber security awareness campaign.

Skip to content