TITLE:
Cyber Human Risk Framework: Measuring and Mitigating Human-Centered Cyber Risk
AUTHORS:
Troy C. Troublefield
KEYWORDS:
Cyberpsychology, Cyber Human Risk, Behavioral Cybersecurity, Human Factors, Cognitive Vulnerability, Social Engineering, Organizational Security Culture, CHRF
JOURNAL NAME:
Journal of Information Security,
Vol.17 No.4,
August
25,
2026
ABSTRACT: The proliferation of sophisticated cyber threats has increasingly exposed the inadequacy of purely technical defenses in protecting organizational and national security infrastructure. Human behavior remains the predominant attack surface exploited by adversaries across all sectors, yet existing cybersecurity frameworks insufficiently account for the psychological, cognitive, and behavioral dimensions of human-centered risk. This article introduces the Cyber Human Risk Framework (CHRF), an original theoretical model grounded in cyberpsychology, cognitive science, behavioral economics, and organizational psychology. The CHRF posits that human cyber risk is a dynamic, multi-layered construct composed of five interdependent domains: Cognitive Vulnerability, Behavioral Susceptibility, Affective Influence, Social Engineering Exposure, and Organizational Context. The framework introduces a novel risk quantification schema, the Human Cyber Risk Index (HCRI), enabling practitioners, researchers, and policymakers to assess, benchmark, and mitigate the human dimensions of cyber risk at individual, team, and enterprise levels. The CHRF draws upon established theoretical predecessors including the Technology Acceptance Model, Dual-Process Theory, Terror Management Theory, Social Influence Theory, and Cyberpsychology’s unique contributions to understanding online behavior and identity. Theoretical synthesis, the empirical foundations drawn from existing behavioral and cyberpsychology research, and provisional practical application mechanisms are elaborated across a structured discussion that includes framework architecture, domain exposition, measurement considerations, and integration with existing cybersecurity governance standards. The CHRF’s quantitative elements, including the Human Cyber Risk Index formula, domain weights, and risk tier thresholds, are explicitly provisional and are offered as empirical hypotheses requiring validation rather than as established measurement parameters.