Tackling the 'human factor' to transform cyber security behaviours
ThinkCyber's CEO Tim Ward reflects on the challenges that startups face when developing innovative products.

Like many startups, ThinkCyber was founded with an intense desire to solve a problem in a much, much better way. We've seen that even some of the newer entries into this market talk a good talk about behaviour change and behavioural science, but still seem to fall back on 'more eLearning' as the solution to insecure behaviour.
At ThinkCyber, we apply behavioural science to tackling human risk, and so are used to considering how to bring psychology theories into business. We understand that by definition, if there’s a better way to do things, there are also many people entrenched in a traditional approach.
One way of thinking about this is in terms of the 'status quo bias' named by Samuelson and Zeckhauser. Everyone else is doing it the old way, there’s safety in that status quo which creates inertia. Part of this inertia comes from our innate loss aversion; the fear of losing something we have overshadows the potential benefits of gaining something we don't have. Thaler called this 'the endowment effect' and found that people irrationally overvalue benefits they currently possess relative to those they don’t.
Further research has shown that this resistance to change can be quite independent of a new product's qualities. This means that for startups, even if your new product is superior, the reality is that people may not buy because of their tendency to stick to the status quo. As Moore notes in 'Crossing the Chasm', startups should expect the journey to be longer and harder than they would like, but it’s possible to manage the process. From a product perspective, it means striving for 10x improvements in current approaches.
In ThinkCyber's case, that's about driving 80-90% engagement without incentives. We do this by making behavioural risk measurable - right there on the device - and by offering real-time interventions to gently steer users away from insecure behaviours as they happen.
In applying for NCSC for Startups, I believed ThinkCyber's Redflags product was an ideal fit for the 'Better engagement' challenge, and the positioning that "traditional ways of engaging people in cyber security do not create enough of a behavioural change".
We’re the first and only people to be doing this in real-time across a wide range of cyber risks people face on their devices, and I believe the potential of the approach for measurable secure behaviour change is phenomenal.
But shifting the status quo requires even more effort, and a significant enabler is peer and industry recognition and that’s a huge part of why the NCSC For Startups programme is so important to us at ThinkCyber. It offers us more than just mentoring and guidance, but also recognition that we’re doing something right.
For ThinkCyber, being techUK's Cyber Innovator of the Year in 2021, chosen for the first cohort of Plexal's LORCA programme and for Accenture's FinTech Innovation lab also helped reinforce our direction. These, combined with feedback from customers, early adopters and evangelists start to break through and create that idea that people are missing out by not having some of this great innovation.
Back to the psychology of buying - this plays to "social proof" and allows us to start to reframe the problem: from adopting a new approach, to highlighting that the greatest risk here is in missing out on what Redflags has to offer. And with the support of NCSC For Startups, we’re able to understand what truly sets us apart and how we can contribute to the mission of making the UK the safest place to live and work online.