
Behavioural Science
The intention-behaviour gap: why knowing better is not enough in security
Most of us recognise this feeling without needing behavioural theory to explain it. You decide to get to bed earlier, eat better, or clear an admin backlog that has been sitting on your desk for a fortnight. At the moment you make the decision, you genuinely mean it. Then the day turns long, energy drops, and the option that asks for the least effort wins out.
In my work with security leaders at SoSafe, I see this exact dynamic playing out across organisations every day. Employees are constantly balancing competing priorities and tight deadlines. When a task needs to get done quickly, human decision-making naturally favours the path of least resistance.
Key Takeaways
- Intent rarely equals action: Research shows even a major shift in intention produces only a modest change in real-world behaviour.
- Convenience beats delayed rewards: Immediate operational speed usually wins over an invisible, delayed security outcome.
- Edit the path, not the person: Effective security leadership removes friction from safe choices rather than repeating policy rules.
Why convenience usually wins under pressure
When time pressure meets a cumbersome process, people default to immediate convenience. Behavioural scientists refer to this difference between what people plan to do and what they actually do as the intention-behaviour gap. Research into goal attainment shows that even a significant shift in intent produces only a modest change in actual behaviour.
Part of the mechanism behind this is delay discounting, where people naturally place less value on outcomes that sit further in the future. In security, choosing a workaround provides instant operational relief. The reward for taking the safe route is invisible and delayed. You can see why the workaround wins.
Behavioural Insight: To bridge this distance, the safe action needs to be obvious before pressure arrives. Using implementation intentions, structured as pre-set decision triggers, helps people decide their response in advance: “If payment details change unexpectedly, verify them through a second channel before approving.”
Editing the path instead of repeating the policy
Once you look at human risk through this lens, the leadership challenge shifts. The work becomes less about reminding people of policy and more about working out the path they follow during a busy afternoon.
Password management is a great example. Expecting people to create and remember dozens of unique, complex credentials was never realistic. Introducing password managers changes the mechanics of the system itself, removing cognitive friction so that secure practice becomes the path of least resistance.
To evaluate whether daily processes support secure habits, look closely at these conditions around the decision point:
- Accessibility: Can an employee report a suspicious message in a single click without leaving their main workflow?
- Culture: Does the organisation normalise taking an extra minute to double-check an unusual request?
- Incentives: Do operational targets inadvertently reward speed over verification?
Designing for real-world context
Generic awareness training often falls short because it asks employees to translate abstract rules into their daily reality on the fly. A finance specialist, a software engineer, and an operations manager face entirely different decision points, even when they share the exact same security policy.
At SoSafe, we design personalised awareness training to address this reality directly. By adapting content to an employee’s specific role, language, and operational context, security guidance mirrors the actual decisions people face during their workday.
The takeaway for leaders: Doing the right thing should not be a constant test of willpower. When you design the surrounding environment around human decision-making, secure behaviour becomes second nature.
Want deeper insights on human risk and behavioural security? Sign up for the SoSafe newsletter for regular perspectives on building organisational resilience.












