Behavioural Science

The intention-behaviour gap: why knowing better is not enough in security

Dr. Christian Reinhardt Dr. Christian Reinhardt · 21 August 2026 · 2 min read

Most of us recognise this feeling without needing behavioural theory to explain it. You decide to get to bed earlier, eat better, or clear an admin backlog that has been sitting on your desk for a fortnight. At the moment you make the decision, you genuinely mean it. Then the day turns long, energy drops, and the option that asks for the least effort wins out.

In my work with security leaders at SoSafe, I see this exact dynamic playing out across organisations every day. Employees are constantly balancing competing priorities and tight deadlines. When a task needs to get done quickly, human decision-making naturally favours the path of least resistance.

Key Takeaways

  • Intent rarely equals action: Research shows even a major shift in intention produces only a modest change in real-world behaviour.
  • Convenience beats delayed rewards: Immediate operational speed usually wins over an invisible, delayed security outcome.
  • Edit the path, not the person: Effective security leadership removes friction from safe choices rather than repeating policy rules.

Why convenience usually wins under pressure

When time pressure meets a cumbersome process, people default to immediate convenience. Behavioural scientists refer to this difference between what people plan to do and what they actually do as the intention-behaviour gap. Research into goal attainment shows that even a significant shift in intent produces only a modest change in actual behaviour.

Part of the mechanism behind this is delay discounting, where people naturally place less value on outcomes that sit further in the future. In security, choosing a workaround provides instant operational relief. The reward for taking the safe route is invisible and delayed. You can see why the workaround wins.

Behavioural Insight: To bridge this distance, the safe action needs to be obvious before pressure arrives. Using implementation intentions, structured as pre-set decision triggers, helps people decide their response in advance: “If payment details change unexpectedly, verify them through a second channel before approving.”

Editing the path instead of repeating the policy

Once you look at human risk through this lens, the leadership challenge shifts. The work becomes less about reminding people of policy and more about working out the path they follow during a busy afternoon.

Password management is a great example. Expecting people to create and remember dozens of unique, complex credentials was never realistic. Introducing password managers changes the mechanics of the system itself, removing cognitive friction so that secure practice becomes the path of least resistance.

To evaluate whether daily processes support secure habits, look closely at these conditions around the decision point:

  • Accessibility: Can an employee report a suspicious message in a single click without leaving their main workflow?
  • Culture: Does the organisation normalise taking an extra minute to double-check an unusual request?
  • Incentives: Do operational targets inadvertently reward speed over verification?

Designing for real-world context

Generic awareness training often falls short because it asks employees to translate abstract rules into their daily reality on the fly. A finance specialist, a software engineer, and an operations manager face entirely different decision points, even when they share the exact same security policy.

At SoSafe, we design personalised awareness training to address this reality directly. By adapting content to an employee’s specific role, language, and operational context, security guidance mirrors the actual decisions people face during their workday.

The takeaway for leaders: Doing the right thing should not be a constant test of willpower. When you design the surrounding environment around human decision-making, secure behaviour becomes second nature.

Want deeper insights on human risk and behavioural security? Sign up for the SoSafe newsletter for regular perspectives on building organisational resilience.

About the author

Dr. Christian Reinhardt
Director of Human Risk Management, SoSafe

Dr. Christian Reinhardt is a sports psychologist, author, speaker, and former Managing Director of the Saxony-Anhalt Football Association. As an expert in human behavior and adult education, he brings deep psychological insight to his role as Director of Human Risk Management at SoSafe. There, he focuses on how cybercriminals exploit psychological mechanisms to manipulate individuals—and how organizations can harness the same behavioral science to foster secure habits. Previously, he lectured at Martin Luther University Halle-Wittenberg and worked as a learning consultant with international companies, always with a passion for turning complex psychological concepts into practical, people-centered strategies for awareness and behavior change.

Learn more

Do you want to stay ahead of the cyber game?

Sign up for our newsletter to receive the latest cyber security articles, events, and resources. No spam, only content that truly matters.

Newsletter visual
Hero Background

Experience our products first-hand

Use our online test environment to see how our platform can help you empower your team to continuously avert cyber threats and keep your organization secure.

SoSafe Security Awareness Training Leader Enterprise 2026 Sosafe Cyber security training platform top 50 award 2026 SoSafe Security Awareness Training Leader 2026 SoSafe Security Awareness Training Momentum Leader 2026 SoSafe Security Awareness Training Leader Mid-Market 2026 SoSafe Security Awareness Training Leader Europe 2026

This page is not available in English yet.

Diese Seite ist noch nicht in Ihrer Sprache verfügbar. Sie können auf Englisch fortfahren oder zur deutschen Startseite zurückkehren.

Cette page n’est pas encore disponible dans votre langue. Vous pouvez continuer en anglais ou revenir à la page d’accueil en français.

Deze pagina is nog niet beschikbaar in uw taal. U kunt doorgaan in het Engels of terugkeren naar de Nederlandse startpagina.

Esta página aún no está disponible en español. Puedes continuar en inglés o volver a la página de inicio en español.

Questa pagina non è ancora disponibile nella tua lingua. Puoi continuare in inglese oppure tornare alla home page in italiano.