You’ve built the biggest, strongest cyber security wall ever. Then your organisation’s staff unlocks the front door to welcome in the intruders. AI is touted as the magic fix for solving the weakness of human factors in the cyber security chain. But the technology is seen as immature relative to need and is perceived as taking more time and budget to implement than is worth the pay-off. Most of all, there is no ‘press a button and problem’s solved’ solution here – there is no replacement for human IT managers understanding what such systems recommend and why. Trust and transparency in AI platforms handling cyber security are essential – but will vendors provide this?This keynote will look at what the international academic research finds about human factors in cyber security. What are they and what approaches can be used to address them? This isn’t just about understanding human behaviour, it’s also about how organisations can make their security responses fit with the humans, instead of demanding the humans fit security programmes and protocols. Some IT security experts recommend punitive measures against employees who repeatedly don’t attend to cyber security – but is it realistic to punish the busy C-suite exec? Are there better ways to win security for your organisation?