About
Human risk is a behaviour problem — so we solve it with pedagogy and psychology, not another policy PDF.
Attackers have given up on your systems and gone after your people. People aren't a patchable vulnerability — changing what they do takes teaching pedagogy, behaviour-change psychology and behavioural economics. We distil 10+ years of that practice from some of the largest, most sophisticated organisations into an AI-powered platform that orchestrates campaigns while it does the heavy lifting on personalising.
Why "Switched On Security"
Security works when your people are switched on.
Most awareness programs leave people switched off — clicking through a slide deck on autopilot, half-noticing the message that would have mattered. That distracted, going-through-the-motions state is exactly what an attacker counts on.
We build for the other setting. Switched on means alert, engaged, and thinking clearly in the moment a decision actually carries risk — and you get people there through practice and motivation, not another policy PDF. Reach that state and your widest attack surface becomes your sharpest sense for trouble.
Where it comes from
Built on 10+ years of practice, not a hunch
The platform distils more than a decade of teaching pedagogy and Culture & Awareness practice from some of the largest, most sophisticated organisations — the kind with security programs mature enough to know that a completion rate was never the point. That experience is what tells us struggle-based, peer-based and experiential learning actually change behaviour where a policy PDF doesn't, and it's why the platform is built to automate the personalising, not the judgment.
Teaching philosophy
Nobody else leads with pedagogy
Three ideas from how people actually learn, not from how software is usually marketed.
Struggle-based learning
Productive difficulty makes lessons stick. We let people work through a real decision under pressure, not watch someone else make it.
Peer-based learning
People learn security from the people around them, not from a policy PDF. We build for the way teams actually pick up habits.
Experiential learning
Do it, feel the consequence, keep the lesson. Every simulation plays out its impact so the learning is earned, not told.
Psychology principles
Behaviour change, measured — not vibes
The science behind what the platform moves and how it measures the movement.
Motivation × Ability
The two primary drivers of behaviour change. Secure behaviour happens only when someone is both able to act securely and motivated to. We move both.
DOSPERT risk-taking
A validated, repeatable instrument for measuring how much risk a person will actually take — so the picture is comparable over time, not a one-off guess.
Experimental risk perception
We measure how well people perceive risk scientifically — through what they do in a controlled simulation, then how they rate it — not by asking them to self-report.
What most People Security gets wrong
Most People Security just disseminates policies or runs rigid phishing simulations built to trick employees. No learning principles, no real aim at behaviour or mindset change.
What we do instead
We put people in the driver's seat of realistic simulations, give them the ability to act securely and the motivation to do so, and measure the change — because that is what the psychology of behaviour change actually requires.
- Facilitated simulations people learn from — not gotcha phishing tests that sow mistrust
- Grounded in teaching pedagogy and behavioural science, not a compliance checkbox
- AI-native and role-tailored: the personalisation is automated, you orchestrate the campaign
- Measured with validated instruments (DOSPERT risk-taking, motivation, ability), not vibes
Who's behind it
The founder
Adam has spent his career on the human side of security — teaching it, and changing how people behave around it.
He has taught cybersecurity at UNSW's School of Computer Science and Engineering since 2017, alongside Professor Richard Buckland — building gamified challenges that introduce generations of engineers to application security, and publishing explainers watched tens of thousands of times. He holds a Bachelor of Engineering (Honours) in Computer Engineering from UNSW, where he specialised in embedded systems and cybersecurity and held the SECedu scholarship for security research.
At Okta he leads Security Culture — the behavioural-change campaigns, internal security podcast and threat-informed storytelling that keep a global workforce alert. Before that, at the Commonwealth Bank (Australia's largest), he ran Cyber Outreach: engaging more than 10,000 people at a +70 NPS, driving a re-skilling program that cut risky behaviours by 15%, and scaling the Schools Cyber Security Challenges to 250,000 students across Australia and New Zealand.
Switched On Security is the distillation of that work — the conviction that people aren't a vulnerability to patch but a behaviour to teach, and that doing it well takes real pedagogy and psychology.
- Since 2017
- Teaching cybersecurity at UNSW
- 10,000+
- People engaged in cyber outreach at CBA
- 250,000
- Students reached through schools challenges
- +70 NPS
- On his cyber-education programs
See the approach in practice.
Switched On Security is in active development with a small group of design partners — early access is free, and it shapes the roadmap.