Human factors & cyberpsychology

Most incidents start with a decision made under pressure

An invoice inside a real supplier thread. A voice on the phone that sounds like the CEO. A team using an AI tool nobody approved because the sanctioned one was too slow. Controls fail at the human step, so we treat that step as part of the work — facilitated by a psychologist, with the technical content owned by our security lead.

What it is

Structured, facilitated sessions that make the human side of a security decision visible: who decides, under what pressure, with which shortcuts — and what a defensible decision protocol looks like. The output is documented, board-readable and usable as management-training evidence. It is not therapy, not a test of individuals, and not a simulated attack.

How it is bought

As priced options on packages you have already chosen. No option is required, and none changes the package’s own scope or price.

Executive fraud-decision workshop

+€900 per workshop

Option on the DORA / NIS2 Evidence Sprint. Intake, a 90-minute session for up to eight leaders, two defensive scenarios built around pretexting — a payment pretext inside an existing supplier thread and an executive-impersonation call — and a written decision protocol and action record.

Human-factors annex on shadow AI

+€700 per annex

Option on the AI Governance & Shadow-AI Sprint. Structured, voluntary interviews with six to eight staff on why unsanctioned tools are used — workload, status, fear of looking slow — feeding the acceptable-use wording and the governance evidence. Themes only; no role or department is attributed.

Quarterly refresh

+€900 per quarter

A new scenario, a 60-minute rehearsal and an updated action record. Scheduled, 30-day cancellation, no on-call element.

Standalone workshop. The fraud-decision workshop can be delivered on its own for a board or leadership team. It is quoted on request after a scoping call, not sold from a price list.

How it is delivered

  • A psychologist facilitates; Dyasol’s security lead owns every technical statement, scenario and control recommendation and attends or is reachable throughout.
  • Sessions produce a written decision protocol and an action record your management can file as documented training. We do not describe any session as compliance with a specific law.
  • Interviews are voluntary. Reports carry themes only. Raw notes are destroyed once the report is accepted, and the report is never personnel evidence.

What we will not do

  • No phishing-susceptibility scores or profiles on named employees.
  • No insider-risk or “disgruntlement” indicators on individuals.
  • No design or operation of social-engineering attacks, and no manipulation content tailored to individual vulnerabilities.
  • No clinical therapy, diagnosis or crisis counselling under the Dyasol brand.
  • No emergency or out-of-hours availability.
  • No interview or survey output that identifies an individual.
These are dual-use techniques, they create GDPR and employee-monitoring exposure, and they would breach the principle we apply to systems: we do not assess what we also build — or, here, the people we also train.

Who delivers it

Angel Brenishki

Managing director — security lead

Practising chief information security officer. Leads every Dyasol engagement and owns its technical content: threat scenarios, control recommendations and the regulatory mapping.

Diana Ginova

Partner — human factors

Certified psychotherapist. Fourteen years of psychotherapy and organisational-psychology practice. Developing her practice into cyberpsychology.

Who does the work →

Cyberpsychology as a direction

We treat cyberpsychology — manipulation of executives, decision-making in incidents, human factors in AI adoption — as a research and content theme we publish on, and as the direction our human-factors practice is developing in. Services are added to this page only once they have been delivered and measured, not before.