PEBKAC Rebooted: A Hacker’s Guide to People‑Patching in 90 Days

David Shipley (Co-founder · Beauceron Security)

BSides Las Vegas 2025 · Day 1

Overview

David Shipley opens by reframing “PEBKAC” from an insult about user stupidity to a more constructive idea: people as partners between keyboard and chair—capable, human, and shaped by biology and cognition. The talk argues that cybersecurity’s decades-long emphasis on using technology to control human risk is incomplete without programs that align with how brains actually work. Shipley positions the content as empirical, drawn from a large multi-industry dataset (more than 1,300 organizations across 20+ industries, with global reach though skewed Canadian), combining learning outcomes, phishing simulation metrics, real phish reporting behavior, and survey-derived attitudes. The central operational claim is that security awareness and phishing simulations can work, but not as annual compliance theater; frequency, fairness, feedback quality, and neuroscience-aligned design determine outcomes.

Watch on YouTube

Visual summary for PEBKAC Rebooted: A Hacker’s Guide to People‑Patching in 90 Days by David Shipley
Visual summary for PEBKAC Rebooted: A Hacker’s Guide to People‑Patching in 90 Days by David Shipley

Key moments

  1. 2:00 Etymology of ‘cyber’ and reframing PEBKAC from insult to ‘partner exists between keyboard and chair.’
  2. 6:00 Decay curve statistics: ~3.5% same-day click probability vs ~15% at 90 days vs ~95% at 360 days post-training.
  3. 8:00 Operational outcomes: click rates falling from 35% to under 5% in 90 days; reporting volume surges and filter bypass discovery.
  4. 10:00 New clicker survey: mimicry dominates reasons; 21% don’t remember clicking; fear-driven clickers report far less post-click.
  5. 14:00 Optimism bias (+37% click likelihood) and technology trust (+140% click rate vs doubters) with one-third strong tool trust in 2025.
  6. 16:00 System 1 vs System 2 explanation of why scams succeed under cognitive load and time pressure.
  7. 20:00 SCARF model mapped to security culture: status-safe scoring, fairness in simulations, autonomy in learning paths.
  8. 22:00 Closing call to measure post-click reporting, reporter accuracy, and filter bypass—not just click rate.

PEBKAC Rebooted: A Hacker’s Guide to People‑Patching in 90 Days

Speakers: David Shipley, (title not stated), organization referenced as “Bosron” in the recording

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=nIxC43qKZvI

Overview

David Shipley opens by reframing “PEBKAC” from an insult about user stupidity to a more constructive idea: people as partners between keyboard and chair—capable, human, and shaped by biology and cognition. The talk argues that cybersecurity’s decades-long emphasis on using technology to control human risk is incomplete without programs that align with how brains actually work. Shipley positions the content as empirical, drawn from a large multi-industry dataset (more than 1,300 organizations across 20+ industries, with global reach though skewed Canadian), combining learning outcomes, phishing simulation metrics, real phish reporting behavior, and survey-derived attitudes. The central operational claim is that security awareness and phishing simulations can work, but not as annual compliance theater; frequency, fairness, feedback quality, and neuroscience-aligned design determine outcomes.

Background

▶ Watch: Etymology of ‘cyber’ and reframing PEBKAC from insult to ‘partner exists betw... (2:00)

Shipley grounds “cyber” etymology in cybernetics—control and communication in animals and machines—and notes the Greek root referencing a helmsman, implying people, technology, and control as intertwined. He contrasts that holistic origin with a modern security culture that often treats users as the “weakest link.” His counterpoint is empirical: if employees were uniformly incompetent, cybersecurity would not be the organizational priority it is; failures are often human-normal responses (speed, distraction, trust heuristics), not stupidity.

He cautions that much academic literature on phishing and awareness relies on small samples, often in university settings, limiting generalizability. His team’s dataset is presented as unusual for combining multiple behavioral streams at scale, though he acknowledges industry skew and invites others to replicate and challenge findings.

Key Findings

▶ Watch: Operational outcomes: click rates falling from 35% to under 5% in 90 days; re... (8:00)

Training decay and timing: Citing collaborative analysis with Michael Joyce at the University of Montreal, Shipley describes estimated probabilities of clicking after training: about 3.5% the same day as training (accidents still happen), about 15% at 90 days, and about 95% at 360 days. He interprets this as evidence that annual-only training does not sustain phishing resistance, while 90-day intervention cycles can maintain vigilance.

Phishing simulation frequency: Shipley warns that over-phishing creates security fatigue. In their sorted analyses, monthly simulations correlated with the lowest click rate and comparatively strong reporting (about 25% reporting rate in the cited slice). When organizations paused simulations for three months, clicks doubled—used as evidence that vigilance is perishable.

Outcomes when “done well”: He reports organizations reducing click rates from 35% to under 5% within 90 days, with further improvement over the first year, and reporting volumes increasing 2.5× to 3× in 90 days and up to 285% in a year when programs emphasize feedback quality and reporter experience.

Filter leakage reality: High-performing reporting programs surfaced measurable email filter bypass: reported phish implied leakage rates ranging from about 3.8% to 10% across providers—almost one in ten in the high end—supporting the argument that simulations test human judgment in conditions that match real residual risk.

Post-click landing pages are weak education: Shipley states median dwell time on post-click training pages is about 11 seconds (mean about 14 seconds), with only 10% staying 30+ seconds. He aligns this with published findings that this delivery mode is ineffective—people cannot learn from pages they do not read.

Why people click (new survey data): A December 2024–June 2025 survey of 4,594 clickers across 211 organizations asks whether respondents remember why they engaged. Nearly half cite mimicry drivers: ~25% “looked legitimate,” ~24.75% “expected something similar.” About 21% do not remember—interpreted as System 1 / automatic processing. Only ~5% cite fear of consequences of not acting; that small group shows >12% click rate over time and ~5% post-click reporting versus ~10% baseline—framed as a psychological safety signal.

Biases: Optimism bias correlates with higher susceptibility: people who do not believe they are targets are 37% more likely to fall for simulations. Technology trust is stronger: respondents who strongly agree their tools fully protect them show 140% higher average click rates than those who strongly disagree; one in three people reportedly hold strong tool-trust as of 2025, up 25% since 2021. Dunning–Kruger dynamics appear in training volume: 35–45 minutes/year of training outperformed heavier annual loads in their data—interpreted as overconfidence risk after training.

Technical Deep Dive

▶ Watch: Optimism bias (+37% click likelihood) and technology trust (+140% click rate ... (14:00)

The “technical” core is cognitive science translated into program design. Shipley explains System 1 (fast, low-energy, heuristic) versus System 2 (slow, deliberate, calorie-expensive). Phishing succeeds, in this framing, because attackers trigger System 1 under cognitive load—timing emails for Friday finance crunch or quarter-end pressure—rather than because users lack IQ.

He applies David Rock’s SCARF model domains—Status, Certainty, Autonomy, Relatedness, Fairness—to security culture mechanics:

  • Status: Avoid humiliation; use visible scoring that improves with good behaviors rather than shame walls.
  • Certainty: Give understandable metrics (he compares clarity to a credit score mental model).
  • Autonomy: Offer choices in learning paths, including alternating work/home-relevant modules when using 90-day cycles.
  • Relatedness: Showcase positive reporting stories to normalize defense as social norm.
  • Fairness: Simulations must be transparent, winnable, and difficulty-balanced; people should earn points for reporting even after a click to preserve post-click reporting.

He rebuts a Google blog critique of phishing simulations (December 2024 paper cited: “Employees’ attitudes towards phishing simulations”) claiming 86.9% positive/very positive attitudes; his own clicker survey claims 70% learned from simulations.

The SCARF mapping is doing more than motivational speaking. In many enterprises, phishing programs fail politically before they fail technically: unions push back, managers complain about embarrassment, HR worries about psychological harm, and IT worries about ticket load. “Fairness” and “status safety” are not soft words here; they are risk mitigations for a program that can otherwise become adversarial to the workforce it needs as sensors. Shipley’s emphasis on positive scoring and “walls of fame” is a deliberate attempt to align incentives so reporting is rewarded rather than punished.

The technology-trust finding deserves extra scrutiny from security architects. If employees believe filters are perfect, they will behave as if links are pre-vetted. That belief is not only wrong; it is increasingly dangerous as attackers adopt faster credential phishing, MFA fatigue, and adversary-in-the-middle kits that can make malicious pages look “normal.” Shipley explicitly ties rising tool-trust sentiment to hype cycles around AI, arguing awareness content must push back on magical thinking without making people feel mocked.

The Dunning–Kruger / training-load result is also a warning to compliance programs that measure success by seat time. If longer courses correlate with worse outcomes in his dataset, the intervention may be generating performative confidence rather than durable judgment. A better model may be shorter, repeated, varied exposures paired with simulations that track difficulty and progressively introduce realistic lures—though Shipley does not prescribe a single vendor workflow; he prescribes principles.

Demo / Proof of Concept

▶ Watch: System 1 vs System 2 explanation of why scams succeed under cognitive load an... (16:00)

There is no software demo. The “proof” offered is aggregate statistics, charts referenced verbally, and described A/B-style organizational outcomes.

Defensive Implications

▶ Watch: Closing call to measure post-click reporting, reporter accuracy, and filter b... (22:00)

Treat human risk as continuous control, not annual training completion. Prefer quarterly cadences over yearly spikes; measure not only click rate but post-click report rate, reporter accuracy, and filter bypass insights from user reports. Design interventions to reduce technology trust overconfidence and optimism bias without victim-blaming.

Operationally, invest in reporter feedback loops—easy reporting channels and meaningful responses—because Shipley ties them to 55% more reporting when done well. Avoid public shame practices (pinned “always clickers” photos) in favor of recognition.

For phishing program owners, the talk also implies a measurement stack upgrade: treat click rate as a lagging indicator heavily influenced by campaign difficulty and seasonal workload. Add post-click reporting rate as a leading indicator of culture and psychological safety. Add reporter precision where feasible so SOC teams do not drown in noise. And use reported phish as a quality signal for email security controls, not as a sign users are “bad.”

Finally, Shipley’s cognitive-load discussion should change when simulations run, not only how often. If finance teams are predictably overloaded at quarter close, that window is also when realistic BEC lures land. A program that ignores operational calendars is effectively testing users under adversary-optimal conditions without providing compensating support—extra staffing, slower approvals, or explicit escalation paths.

Key Takeaways

  • Reframe users from liability to sensor network when programs respect cognition and incentives.
  • Annual training does not match measured decay curves; 90-day reinforcement aligns better with observed probabilities.
  • Monthly simulations showed favorable tradeoffs in the cited dataset, but pauses sharply erode vigilance.
  • Post-click pages fail if engagement time is seconds; move education to modes people actually consume.
  • Mimicry, memoryless clicks, and tool trust are major measurable drivers—programs should explicitly train and message against them.
  • SCARF-aligned design (status safety, fairness, autonomy) is presented as a practical blueprint for culture metrics that move behavior.

About the Speaker(s)

David Shipley presents as leading a team working on security awareness, behavior, and culture at an organization pronounced “Bosron” in the recording (spelling uncertain). He references partnership with Michael Joyce (University of Montreal) for probability-of-click research and cites multiple external studies including a December 2024 employee attitudes paper. Exact job title is not stated in the captured intro.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A data-heavy culture-and-behavior talk with several memorable quantitative hooks; useful for defenders running phishing programs, light on novel security mechanisms and occasionally survey-self-report fragile.

Heather Calloway (CISO) — STRONG ACCEPT

This belongs in the human-risk governance stack: it gives executives measurable cadence guidance, clarifies what metrics beyond click rate actually matter, and ties culture design to psychological safety in a way IR and GRC leaders can operationalize.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025