Skip to main content

Introducing PsySec.io: Open Research on Psychological Security

, CEO
Introducing PsySec.io: the open research home of Psychological Security, with 48 studies, 25 secure behaviors, 6 manipulation tactics, and open data

Today, Hook Security launched PsySec.io, a free, open research database for Psychological Security (PsySec). It collects 48 studies on why people fall for manipulation and what actually changes their behavior, including the studies that challenge our own approach. It's the evidence base for a different answer to human risk: build people's instincts instead of scoring them.

PsySec.io is free, licensed CC BY 4.0, and maintained by Hook Security. We're launching it on October 1, the first day of Cybersecurity Awareness Month, because a month about awareness should start with what the evidence says awareness can and can't do.

What is PsySec.io?

PsySec.io is the home of Psychological Security and an open database of the research behind it. Every study is summarized in plain English, tagged by method and manipulation tactic, and labeled by whether it supports, challenges, or complicates the PsySec approach. Here's what's in it at launch:

  • Studies: 48 studies from journals and conferences including IEEE S&P, ACM CCS, and MIS Quarterly, each with its key finding and a link to the original paper.
  • Behaviors: 25 secure behaviors, from reporting suspicious messages to pausing when a message pushes you to act fast, each with how to observe it and the studies behind it.
  • Principles and tactics: the 8 PsySec principles and the 6 manipulation tactics attackers rely on: Urgency, Scarcity, Trust, Helpfulness, Authority, and Social Proof.
  • Papers: original research, starting with The Reporting Race.
  • Related work: 14 organizations doing serious work on the human side of security, including NIST, the UK NCSC, ENISA, and SANS.
  • Open data: every study and behavior as a CSV download or through the API, plus a citation guide.

Why did Hook Security build PsySec.io?

The security awareness industry has a research problem. Vendor claims are everywhere, the studies behind them are hard to find, and when independent research does show up, it often cuts against the product being sold. Buyers, MSPs, and program leaders deserve one place to check the evidence for themselves.

That includes evidence against us. Of the 48 studies at launch, 4 challenge the PsySec approach and 10 have mixed results. You can filter by stance and read those first. A research database that only agrees with its publisher isn't a research database. It's a brochure.

What is Psychological Security (PsySec)?

Psychological Security is the third domain of security, after physical and information security. It defends the human mind against manipulation by expanding people's agency, building the instincts and habits that make them an organization's best defense. Its working model is a chain: belief leads to emotion, emotion leads to behavior, and behavior repeated becomes habit.

Adam Anderson coined the term in 2018. Zach Eikenberry developed the body of work from 2019 on, including his book Psychological Security. Read the full introduction in What Is Psychological Security (PsySec)? or the short definition in our glossary.

The idea isn't new. Hook launched PsySec training in 2020, Expert Insights covered it in 2021, and Nasdaq ran a piece on psychological security in 2023. Zach and Adam have made the case on podcasts like What's Your Ask? and Easy Prey. PsySec.io is where that work now lives in the open. More coverage is on our press page.

How is PsySec different from human risk management?

Human risk management (HRM) is the industry's successor term to security awareness training, and it gets the diagnosis right. Gartner predicts that by 2030, widely adopted control frameworks will "focus on measurable behavior change rather than compliance-based training." Where most HRM products go wrong is the prescription: they give each person a number, rank them, and fire automated training at whoever clicks.

Gartner now recommends moving past the HRM label altogether. In an April 2026 Analyst Take, Richard Addiscott argued it's time to drop "human risk management" as a market name in favor of secure behavior management (SBM), because "SBM speaks directly to the CISO's goal of fostering more secure work behaviors and a more security-conscious corporate culture to reduce employee-initiated risks." SBM names the goal. PsySec is how it happens: secure behavior management, fully implemented and flourishing.

PsySec keeps the measurement and drops the verdict. We lay out the full argument in Human Risk Management vs PsySec: What the Research Actually Says. Here's the short version:

The HRM column describes the scoring model most HRM platforms use; practices vary by vendor.
QuestionHRM as usually implementedPsySec
What gets measuredPer-person risk scoring: one number that follows each employee.Resilience and vulnerability per manipulation tactic: a map, not a verdict.
Primary metricClick rate.Suspicious Email Reporting Rate (SERR). Click rate is diagnostic only.
What happens after a clickAutomated remediation training assigned to the person who clicked.A private learning moment, plus immediate recognition for everyone who reports.
How people are seenA risk to be managed.The organization's best defense.
EvidenceMostly vendor-published data.48 independent studies, published openly on PsySec.io.

Why SERR first? Because reports are what stop an attack. See what SERR measures.

What does the research say works?

Four findings from the database show where the evidence points:

  • Reporting works as an early-warning system. In the largest long-term field study of workplace phishing, 14,000+ employees over 15 months, reporting suspicious email worked as a fast, sustainable, crowd-sourced detection system, while embedded training didn't make people more resilient (Lain et al., IEEE S&P 2022).
  • Standard training barely moves click rates. A 2026 study of 12,511 employees, grounded in the NIST Phish Scale, found no significant training effect on clicks or reports. In 36–55% of simulations, a report arrived before the first click (Rozema & Davis, WWW '26).
  • People report to protect each other. The main reason employees report suspicious email is wanting to help the organization and their coworkers (Burda et al., 2025).
  • Feedback for everyone beats feedback for the people who clicked. Delayed feedback sent to all employees after a simulation was more promising than embedded feedback shown only to those who clicked (Yin et al., MIS Quarterly).

Put together, the research points toward programs that reward reporting, teach everyone, and stop treating a click as a verdict. The UK's National Cyber Security Centre lands in the same place, warning against a blame culture around phishing. It's also the argument of our working paper, The Reporting Race, and of Hook Labs' analysis of 691 real phishing emails, which found that trust, not fear, is the attacker's main weapon.

Who is PsySec.io for?

  • Security awareness program leaders who want evidence for a program built on reporting and habits, not completion rates.
  • MSPs deciding what to sell their clients, and looking for sources to hand a skeptical client.
  • CISOs and buyers evaluating human risk management platforms who want to check vendor claims against independent research.
  • Researchers and journalists who need an open, citable dataset on the human side of security.

How do I use PsySec.io?

  1. Search the research by topic, such as reporting, embedded training, or fear appeals.
  2. Filter by stance to see what supports, challenges, or complicates PsySec.
  3. Open any study for its plain-English finding and a link to the original paper.
  4. Download the data or use the API in your own analysis.
  5. Submit a study we've missed, or a correction to one we have.

FAQ

Is PsySec.io free?

Yes. There's no sign-up and no paywall. The content is licensed CC BY 4.0, and linked studies remain the property of their authors and publishers.

Is PsySec.io a Hook Security product?

Hook Security maintains it, but it doesn't sell anything, and it includes research that challenges Hook's approach. Hook's platform is how we put the research into practice.

Is PsySec an alternative to human risk management?

Yes. PsySec shares HRM's goal of measurable behavior change. It measures resilience by manipulation tactic, makes reporting the primary metric, and rewards people who report instead of scoring the people who click.

Is PsySec the same as secure behavior management?

They go hand in glove. Secure behavior management (SBM) is the name Gartner has proposed for this market, and its goal is more secure work behaviors and a stronger security culture. PsySec is how SBM happens, fully implemented: reporting is the primary metric, habits grow through regular practice, and resilience is measured by manipulation tactic instead of scoring individuals.

How do I get updates from PsySec.io?

Subscribe on PsySec.io for research updates by email as new studies and papers are added.

How does Hook Security use PsySec?

Hook Security is a security awareness training and phishing simulation platform built for MSPs and SMBs. Its security awareness training uses psychology and humor instead of fear, and every report earns immediate recognition, so the habit that stops attacks gets stronger.

Explore the research at PsySec.io, or see how Hook puts PsySec into practice.

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.