Skip to content

Cybersecurity practices in organisations

New publication

The CYREN team has developed a standardised definition and taxonomy for cybersecurity behaviour within organisations. TECBO classifies employee behaviour into five domains – ranging from IT usage to the handling of security incidents – and is freely available for use in both research and practice.

Ambuehl, B., Ebert, N., Geppert, T., Schaltegger, T., Knieps, M., & Zimmermann, V. (2026). Towards an action-based taxonomy of employee cybersecurity behaviour in organisations (TECBO). Computers in Human Behavior Reports, 22, 101090. https://doi.org/10.1016/j.chbr.2026.101090

Further training CAS Cyber Risk Awareness

For those wishing to introduce this topic within their own organisation: the CAS Cyber Risk Awareness programme will begin its third round in March 2027. Technical measures alone are not enough; a single careless click on a malicious attachment can lead to business disruption, data loss and reputational damage. The CAS programme teaches how to raise awareness among staff, management and IT departments in a targeted manner and empower them to adopt secure behaviour.