Understanding the Cyberpsychology Behind Every Online Decision, with Dr. Mary Aiken

Dr Mary Aiken

Attackers rarely need to break your systems when they can bypass your judgment instead. Urgency, authority, familiarity, and fatigue aren’t just emotions—they’re mental shortcuts, and shortcuts can be hacked just as easily as software. As deepfakes, synthetic identities, and AI-generated trust reshape social engineering, understanding the psychology behind every click, approval, and escalation is no longer a soft skill for MSPs: It’s the front line.

Dr. Mary Aiken, Professor and Chair of the Department of Cyberpsychology at Capitol Technology University in Washington, D.C., and Professor of Forensic Cyberpsychology at the University of East London, has spent her career studying the intersection of technology, and human behavior. A member of the INTERPOL Global Cybercrime Expert Group, and academic advisor to Europol’s EC3, she was co-lead scientist on one of the largest EU cyberpsychology-informed cybercrime research projects to date, and her work inspired the CBS series CSI: Cyber. Her bestseller The Cyber Effect was named a Sunday Times book of the year, and she has been ranked the world’s #1 female cybersecurity speaker in both 2025 and 2026.

In this interview, Dr. Aiken explains why treating end users as “the weakest link” is a limiting—and counterproductive—framing, how automation bias and algorithm aversion are quietly reshaping trust between humans, and AI-driven security tools, and why she believes the strongest defense against engineered trust is what she calls the Trust Paradox: trust matters but always verify. She also outlines the one human factor she’d urge every MSP leader to redesign before the next wave of cyber risk hits: How decisions get made under pressure.

When you say that the future MSP ecosystem is “profoundly human,” what are MSPs still misunderstanding about the people inside their digital environments?

MSPs often have a sophisticated understanding of the technical environment, endpoints, platforms, identity, networks, vendors, and controls but a much less developed understanding of the human environment operating within it. People in cyber systems are not rational actors calmly processing perfect information. They are making decisions under pressure, under uncertainty, and often under cognitive stress and load. In those conditions, people rely on heuristics, that is, mental shortcuts, and those shortcuts can be exploited. In cybersecurity, attackers often hack the shortcut, not the system. Urgency, authority, familiarity, fatigue, fear, optimism bias, and confirmation bias all shape behavior. Therefore, from a cyberpsychology perspective, the MSP is not just managing infrastructure. It is managing human decision-making in a high-speed, high-risk cyber environment, and ecosystem.

MSPs often focus on tools, platforms, and response times. Where do human judgment, trust, and responsibility fit into the service model of the future?

They become core parts of the service model. Tools can detect, automate, and accelerate, but judgment is still required when signals are ambiguous, when context matters, or when action has consequences. Clients are not only buying technical capability; they are buying confidence that someone will interpret risk wisely, and act responsibly on their behalf. This is where human biases matter. Automation bias can lead people to over-trust a system. Confirmation bias can make teams see what they expect to see. Optimism bias can delay escalation. A mature MSP service model must therefore include decision quality, accountability, communication, and trust not just response time.

Yes. It is a limiting and often counterproductive framing of the problem space. Humans are not simply the weakest link; they are the most targeted interface in the system. Attackers target people because people carry access, authority, emotion, trust, and routine. Social engineers exploit predictable psychological mechanisms: authority bias when a request appears to come from a senior leader, urgency bias when immediate action is demanded, familiarity bias when a message appears to come from a known contact, and the affect heuristic when emotion can override verification. Blaming the user misses the larger design failure. The better question is: why was the person placed in a situation where the unsafe decision was easy, urgent, and psychologically compelling?

As AI becomes part of support, monitoring, threat detection and customer communication, how should MSPs think about the psychological impact of machines making or influencing decisions?

AI changes more than workflow; it changes the psychology of human trust, agency, and responsibility. When a machine recommendation appears confident, people may defer to it too readily, that is automation bias. When an AI system makes a visible error, people may reject it too quickly, that is algorithm aversion. Both responses are problematic.

Algorithm aversion describes the tendency to distrust or reject recommendations from algorithms or AI, even when those systems may outperform human judgment overall. This resistance is often rooted in a lack of transparency, a desire to preserve human agency, and the fact that people tend to judge machine errors more harshly than human mistakes. There is also the risk of deskilling. If AI is always suggesting the answer, human operators may gradually lose confidence in their own judgment, or stop practicing the critical thinking needed to challenge the system. For MSPs, the answer is not blind trust in AI, nor reflexive rejection of it. Arguably the answer is calibrated trust.

That means designing AI use around clear human roles: when should a human be in the loop, actively reviewing or approving a decision before action is taken; and when should a human be on the loop, supervising, auditing and intervening when an autonomous system behaves unexpectedly? MSPs need to know when to rely on AI, when to challenge it, when to escalate, and who remains accountable for the final decision. In the future service model, AI may support decisions, but responsibility cannot be automated.

Social engineering is no longer just suspicious emails; it is deepfakes, synthetic identities, emotional manipulation and trust hacking. What should MSPs be preparing their clients for now?

MSPs should prepare clients for attacks that are cyberpsychologically convincing, not merely technically sophisticated. The next generation of social engineering will exploit belief, identity and emotion, at scale. It may appear as a familiar voice, a trusted supplier, a senior executive on video, a distressed colleague, or a synthetic identity: a fabricated but believable digital persona designed to earn trust over time. These attacks exploit powerful human behavioral drivers, including authority bias, familiarity bias, social proof, emotional reasoning, reciprocity and urgency. We are moving beyond phishing into the era of engineered trust.

The response cannot be awareness training alone. MSPs need to help clients build verification cultures: clear protocols that make it normal, safe and expected to pause, verify and challenge, even when something appears authentic. I describe this as the Trust Paradox: the best way to protect trust in digital ecosystems is through zero trust, and disciplined verification. In other words: trust matters but always verify.

MSPs sit between vendors, clients, employees, platforms and attackers. How can they build healthier digital ecosystems rather than simply adding more security controls?

A healthier digital ecosystem is one in which people understand their roles, decisions are structured, escalation pathways are clear, and communication is trusted before a crisis occurs. More controls do not automatically create more safety if the human system around them is confused, cognitively overloaded, or reluctant to speak up. Under pressure, people default to cognitive shortcuts: they follow authority, stick with defaults, conform to the group, or focus on the most vivid or recent threat—what we call the availability heuristic. MSPs can improve ecosystem health by reducing cognitive load, simplifying decision pathways, clarifying responsibility, designing psychologically safe reporting cultures, and making secure behavior the default behavior.

When it comes to cybersecurity, we want our technical systems to be robust, resilient, safe, and secure. But we also need the humans who use, manage, and operate those systems to be psychologically robust, resilient and secure. It is the combination of technical resilience and human resilience that delivers true 360-degree resilience.

For an MSP owner or leader attending MSP GLOBAL 2026, what is the one human factor they should redesign in their business before the next wave of cyber risk arrives?

I would redesign decision-making under pressure. Many cyber incidents escalate not because nobody had tools, but because people were overwhelmed, uncertain, tired, or afraid of making the wrong call. In those moments, biases intensify, normalcy bias delays action, confirmation bias narrows attention, authority bias prevents challenge, groupthink suppresses dissent, and decision fatigue reduces judgment quality. MSP leaders should know in advance who decides, who verifies, who communicates, who challenges assumptions, and who has authority to pause a risky action. If decision-making is redesigned before the crisis, the organization is far less likely to make panic part of the breach.

Bottom line, you can’t serve your ecosystem if you don’t understand the humans in it. The future MSP must secure systems but also support better human judgment under pressure in cyber contexts. That is where cyberpsychology comes in. Looking forward to delivering my keynote “Humans in Your Ecosystem: The Cyberpsychology of the Future MSP at MSP GLOBAL 2026!

Stay up to date with all industry reports, trends, and news — sign up to our newsletter here and receive a FREE code to register for MSP GLOBAL, saving €399!

Eugenio Cirmi Avatar

This might also interest you

Verify your email

Please check your inbox and verify your email address to complete the registration.

Check your email

We have sent you a password reset link. Please check your inbox.