The Cloud Security Alliance Swiss Chapter has started a new Research Project on Cyber Threat Psychology

The new Cyber Threat Psychology Research Project intends to set the focus on the supply side i.e. the hackers and their motivations and incentive structures, what made them become a hacker, the transmission mechanisms supporting the attack to succeed, and of course also on the receiving side i.e. the victims.

CSA Swiss Chapter Research Topics
April 21, 2025

Cyber Threats often have a strong psychological component underneath which facilitates the success of the attacks. The new Cyber Threat Psychology Research Project intends to set the focus on the supply side i.e. the hackers and their motivations and incentive structures, what made them become a hacker, the transmission mechanisms supporting the attack to succeed, and of course also on the receiving side i.e. the victims. Our goal is to find patterns which can be leveraged to influence the supply side and the transmission mechanisms, and to broadly communicate these, with the goal of changing mindset at the supply side and interrupting the transmission channels where possible.

Working Group Sessions have taken place on 10 Feb 2025, 24 Feb 2025 and on 10 March 2025. Initial activities have encompassed scoping of the activities, goals and deliverables definition, and description of the research topics to be addressed. Next steps are the creation of the Research Project’s Baseline and Working Group Charter.

Active contribution by specialists in defensive and offensive security, Security Operations, Threat & Vulnerability Management, Cyber Forensics, Cyber Criminology, Youth Psychology, Psychology and Behavioural Sciences are encouraged you contact us for participation. Please reach out to Rolf Becker.

More like this

Agentic AI in Supply Chain Security

Agentic AI is the next big thing in artificial intelligence. Smart computer programs, that can set goals, make decisions, and learn on their own, without always needing a person to tell them what to do. Old systems just follow rules. But AI agents can change and get better as things around them change. According to Gartner, by 2026, companies using agentic AI for security will find and fix supply chain threats 60% faster than those using older security tools.

Read More

Elevating Board-Level Accountability: Cybersecurity Duties and the New BSI Guideline

In today’s interconnected world, the NIS 2 Directive sets out unambiguous obligations for executive management: it makes clear that ultimate accountability for an organisation’s cybersecurity cannot be outsourced to IT teams alone and must remain firmly with the board. Among other things, NIS 2 requires that board members undertake regular, targeted training so they acquire the necessary knowledge and skills to fulfil these duties.

Read More