Office environment with diverse team members brainstorming and collaborating on a project.

TL;DR SUMMARY: Cyber security behaviour change works best when organisations understand what people are already doing. Nudge theory examples and behavioural data can reveal where employees need support, which tools they rely on and where policy is failing to match reality. Control can feel decisive before visibility exists, although it often pushes risky behaviour out of sight.

Why control-first governance can miss the work being done

Control-first security has a tempting simplicity: block the tool, ban the behaviour, write the policy, escalate the exception. Some situations do call for firm controls, although they work better when they’re built on a clear view of how people are actually working. Without that view, organisations can end up treating symptoms while the real pattern continues elsewhere.

This becomes especially clear with emerging technologies such as AI. Employees may use tools because they are curious, though pressure often plays a larger role. A policy that says “don’t use this” may not resolve the workload, deadline or process friction that made the tool attractive in the first place.

Tim Ward, CEO and Co-Founder of Redflags, brings more than 25 years in IT, including senior roles at Logica, PA Consulting, Sepura and BAE Systems’ cyber division Detica. Ward gets to the operational difficulty quickly: “It’s very hard to put guard rails in place when you really don’t know which of your staff are using tools, what tools those staff are using, and for what.” Visibility, handled responsibly, gives security teams a starting point that policy alone can’t provide.

Visibility changes the conversation. It helps organisations see which teams are experimenting, which use cases are common, which tools are creating risk and where people may need clearer routes to safe adoption. With that insight, intervention can become more precise.

Ward has framed visibility as the step that allows organisations to identify hotspots, make better decisions about tooling and define the behaviours they actually want people to follow. That shift is consistent with the Redflags approach, where behavioural data is used to guide timely, contextual interventions rather than simply record whether a user has done something risky. Secure behaviour is easier to encourage when it has been clearly described.

For example, “don’t use unauthorised AI” is blunt. “Use the approved tool for internal summaries, never enter personal data into public tools, and ask for review before using AI for customer-facing decisions” gives people something more usable. A real-time nudge can then reinforce that guidance when it matters.

Turning visibility into guidance

Nudging examples work best when they are grounded in actual behaviour. If data shows that employees visit public AI tools after receiving long policy documents, the organisation has learned something useful about both AI risk and communication design. If one department repeatedly uploads sensitive files to consumer cloud tools, the issue may be tool access rather than awareness. The pattern often becomes clearer over time, particularly when security teams treat the data as a way into conversation rather than as a final judgement.

Handled well, visibility can be presented as a form of support: a way for security teams to understand where people are under pressure, where tools are creating friction, and where a timely intervention could help someone make a safer choice without feeling watched or blamed. Psychological safety sits underneath that work, because people are far more likely to report workarounds, confusion and mistakes when they trust the organisation’s response.

Sequencing is the useful principle here: see the behaviour, understand the need, design the safer path, then apply controls that make sense. In practice, that order can change the relationship between security and the rest of the business. The conversation becomes less about why people broke the rule and more about what the rule failed to understand.

Key takeaways

  • Control without visibility can push risky behaviour underground.
  • Behavioural data helps organisations design more relevant interventions.
  • Clear desired behaviours are easier to support than vague prohibitions.
  • Visibility works best when it is framed as support, with clear guardrails around trust and psychological safety.