Why Security Policies Fail: The Human Side of Cybersecurity
with John Elliott • March 10, 2026
Episode overview
Most security failures aren't technical — they're human. So why do we keep designing security programs that ignore how people actually think and behave?
In this episode of The Pluralsight Podcast, John Elliott — Pluralsight author fellow, PCI DSS contributor, and specialist in regulated security and data protection — makes the case that the language, culture, and psychology behind your security program matter just as much as the controls themselves.
John breaks down why policies get misread, ignored, or worked around, and what leaders can do differently. From the neurolinguistics of security training to the aviation concept of "just culture," this conversation is packed with practical frameworks for building security programs that people actually follow.
We also dig into the expanding attack surface of agentic AI, why your cybersecurity team is likely more anxious than you realize, and what organizations need to do right now to prepare for what's coming.
Want to go deeper? Check out our weekly newsletters focused on Security, Cloud, and AI.
Follow Pluralsight on Linkedin and join the conversation.
Connect directly with John Elliott on LinkedIn.
Questions or comments? podcast@pluralsight.com
Chapters
02:58 How John Discovered the Human Side of SecurityÂ
05:30 Why Security Communication Is So Often OverlookedÂ
06:03 Where Policies Break Down in PracticeÂ
08:26 The Importance of Explaining the "Why"Â
09:31 Connecting Individual Behavior to Organizational SecurityÂ
11:41 Designing Controls and Training People Will Actually FollowÂ
12:49 Compliance Is Always a Risk DecisionÂ
14:36 Can You Ever Hit 100% Security Coverage?Â
17:03 Beta Testing Policies Before You Roll Them OutÂ
18:05 What Most Teams Get Wrong About Security TrainingÂ
19:15 The COM-B Model: Capability, Opportunity, and MotivationÂ
21:04 How to Diagnose the Real Skill Gap in Your OrganizationÂ
24:24 Don't Patronize People — And Don't Give Them 50 Things Not to DoÂ
25:44 The Compliance Budget: You Only Get 3% of Someone's BrainÂ
27:55 Building a Healthy Security CultureÂ
28:10 Psychological Safety as the Foundation of Security CultureÂ
29:10 What "Just Culture" Means and Where It Comes FromÂ
30:34 The Badge Policy Problem — And Why It BackfiredÂ
34:07 Balancing Risk Appetite Across Large Enterprises
35:22 AI's Unique and Poorly Understood Attack SurfaceÂ
38:09 Agentic AI, Open Source Agents, and the Enterprise RiskÂ
41:49 Two Practical Changes Leaders Can Make Right NowÂ
44:49 Benchmarking Security Skills