Skip to content
Emmanuel's Thoughts
Search
  • Home
  • Registration
  • Book Reviews
  • NL
  • FR

The Psychology Of Information Security

Reviewed by Manu Steens in Risk Management
  • AuthorLeron Zinatullin

Author: Leron Zinatullin

In this book the author explains the human side of IT Security. By linking the behavior of the target group (the people in the organization) to the desired outcomes (an information-safer environment) the IT security consultant has to bring this about.

But that requires knowing what the situation is, what the employees’ world is, what they view as their goals. And what they experience as being onerous.

Research shows that there are three objections to information-safe work by the employees:

  • There is no clear reason to comply with the IT security rules
  • The cost of fulfilling it is too high
  • There is an inability to comply with the rules

The author doesn’t claim that this list is exhaustive. The author does not go much further than the fact that you have to solve this with empathy for desired usability. How you do that is by communicating intensely with the target group. Unfortunately, the author proposes a classical scheme of communication, completely bilateral, one on one, instead of a communication in a network of people, many to many.

According to him, the goal of working on the information security culture is to show the employees that it can be an easy way of working. One of the explanations of a weak culture in this area is the “broken windows theory”: if a window falls in a neighborhood, the whole neighborhood will have to deal with a negative influence. But the theory would also work the other way around, and showing the good example is worthwhile.

Then the author talks about the psychology of compliance with the rules: this includes external and internal factors. The external factors include reward, punishment, competition. The internal factors include giving meaning, pleasure and interest. There are interactions between both groups of motivations, strengthening or weakening. In addition, other factors are decisive, such as autonomy, etc.

In the last chapter, the author gives a first glance at how changing the approach to security.

About Leron Zinatullin

Leron Zinatullin is an expert in cybersecurity and information security strategy. He has led significant security transformation projects globally. He holds a Master's degree in Information Security from University College London (UCL), focusing on the human aspects of security. Zinatullin is the author of "The Psychology of Information Security," which explores human factors influencing information security. He provides practical advice for security professionals and is highly respected for addressing the psychological aspects of security. In addition to writing, Leron is active in the cybersecurity community, speaking at events, mentoring newcomers, and sharing knowledge through various platforms. For more information on his work and publications, visit his website or check out his Goodreads profile under "Cyber Security Leadership" by Javvad Malik. Linkedin

OTHER BOOKS BY THIS AUTHOR

The Psychology of Information Security - Resolving conflicts between security compliance and human behaviour

Manu Steens

Manu works at the Flemish Government in risk management and Business Continuity Management. On this website, he shares his own opinions regarding these and related fields.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Content

link to How Migration Really Works - The True Story …

How Migration Really Works - The True Story …

The Facts About the Most Divisive Issue in Politics In some previous posts, I provided an analysis of global risks from the OECD's 2024 Global Risks Report document. What stood out in previous...

Continue Reading
link to The Anxious Generation - which is the trap we push kids into?

The Anxious Generation - which is the trap we push kids into?

Jonathan Haidt, in "The Anxious Generation", describes the risks we are putting our children at, from Generation Z onward. These are not small: social deprivation, not enough physical exercise,...

Continue Reading

About Leron Zinatullin

Leron Zinatullin is an expert in cybersecurity and information security strategy. He has led significant security transformation projects globally. He holds a Master's degree in Information Security from University College London (UCL), focusing on the human aspects of security. Zinatullin is the author of "The Psychology of Information Security," which explores human factors influencing information security. He provides practical advice for security professionals and is highly respected for addressing the psychological aspects of security. In addition to writing, Leron is active in the cybersecurity community, speaking at events, mentoring newcomers, and sharing knowledge through various platforms. For more information on his work and publications, visit his website or check out his Goodreads profile under "Cyber Security Leadership" by Javvad Malik. Linkedin

OTHER BOOKS BY THIS AUTHOR

The Psychology of Information Security - Resolving conflicts between security compliance and human behaviour

About Manu

Who am I? What do I do?

By education I am a Civil Engineer (Master in Engineering Sciences option Physics) and Master in Sciences, option Physics. After seven years of working as a consultant, I was able to work for the Flemish Government where I still work.

Since 2003 I have been committed to ICT security and since 2013I have been responsible for Business Continuity Management and Crisis Management. It is through that trajectory that I picked up the virus to study and apply everything that has to do with risks.

  • Privacy Policy
  • About This Website
  • Terms and Conditions
© 2025 Copyright Emannuel's thoughts