Cognitive dissonance

Cognitive dissonance is the psychological discomfort from holding conflicting beliefs or acting against one's convictions, leading people to rationalize risky behaviors—a key factor in cybersecurity awareness.

Cognitive dissonance is a concept from social psychology that describes the mental discomfort experienced when a person holds two or more contradictory beliefs, values, or attitudes simultaneously—or when their actions conflict with their convictions. To relieve this tension, individuals typically change their beliefs, modify their behavior, or rationalize the inconsistency by minimizing its importance.

In cybersecurity, cognitive dissonance plays a critical role in understanding why people fail to follow security best practices even when they know the risks. For example, an employee aware of phishing threats may still click suspicious links and then justify the behavior by thinking "it probably won't happen to me." This rationalization creates exploitable vulnerabilities that attackers can leverage. Effective security awareness training must address these psychological barriers head-on, helping individuals recognize and resolve their internal conflicts rather than dismiss them, thereby strengthening organizational resilience against cyber threats.