Business Academy Copenhagen (EK)

da

Cybersecurity Culture and Human Risk

2026/2027
Danish title
Cybersecurity Culture and Human Risk
Study programme
Cyber Security
Type of education
Full time education
Level of education
Bachelor Programme
Semester
3. semester
Duration of the subject/module
1 semester
Ects
10
Programme elements
Elective
Language
English
Start time
Autumn
Spring
Location
Guldbergsgade 29 N, København N
Subject number
4050304
Responsible for the subject(s)/modul(es)
Jim Bauer
  • Purpose and learning objectives

    Most cybersecurity incidents are not caused by technology alone, but by human behavior.
    This course introduces students to the human side of cybersecurity and provides a practical, risk-based approach to working with security awareness, behavior, and culture in organizations.

    Instead of focusing only on knowledge and training, the course explores how and why people make decisions, how behavior creates risk, and how organizations can design solutions that make secure behavior the easy choice.

    This approach reflects a growing industry focus on human risk as a key component of cybersecurity.

    After completing this course, students will be able to design and implement targeted, behavior-driven cybersecurity initiatives that reduce real risk and can be anchored in organizational practices and compliance frameworks.

    Knowledge

    • The role of human behavior in cybersecurity risk
    • The difference between awareness (knowledge) and behavior
    • Cognitive biases and decision-making processes affecting security behavior
    • How risk arises from everyday actions and situations in organizations
    • Principles for designing security solutions aligned with human behavior
    • Basic concepts of risk-based security culture and human risk management

    Skills

    • Identify and describe risk scenarios involving human behavior
    • Analyze target groups and assess their exposure and level of “risk savviness” (risk awareness and decision-making ability)
    • Identify behavioral barriers and friction that prevent secure behavior
    • Design interventions that make secure behavior easier in practice
    • Prioritize initiatives based on risk rather than activity
    • Communicate security initiatives in a way that supports engagement and action

    Competences

    • Work systematically with the human factor in cybersecurity
    • Translate risk insights into practical and targeted initiatives
    • Contribute to building a security culture that goes beyond awareness
    • Support decision-making with a clear link between behavior and risk
    • Contribute to organizational decision-making related to cybersecurity risk and behavior
    • Reflect on and evaluate the effect of security initiatives

  • Type of instruction
    Teaching in the Cybersecurity programme is conducted as a dynamic and interactive process, with a strong emphasis on active student participation. The teaching is based on relevant industry practices and combines practical experience with theoretical knowledge. Problems and cases from different types of companies within the IT industry are incorporated into the learning activities. Students are expected to take responsibility for their own learning, and both students and lecturers contribute constructively to the learning process.

    To ensure optimal academic learning and personal development for each student, the programme applies a varied pedagogical approach with emphasis on dialogue, discussion, and project-based learning.

    Teaching is organized through a variety of learning activities, including classroom teaching, guest lectures, company visits, group project work, and individual assignments — often involving interdisciplinary challenges and always with an application-oriented perspective. In addition to the academic content, these different learning methods help develop the students’ ability to work both independently and collaboratively.

    Common to all these activities is that EK consistently aims to establish clear objectives for the learning activities.
  • Exam

    The learning outcomes of the exam are identical with the learning outcomes of the subject(s)/modul(es)

    Prerequisites for access to the examination
    It is a prerequisite for being admitted to the exam that the student submits 2–4 written assignments, which must be approved before the student takes the exam for the first time.
    The assignments will be described during the semester.

    Failure to fulfill this prerequisite means that the student will have used one exam attempt.
    Exam in one or more subjects
    Subject/module is tested standalone
    Type of exam
    Combined written and oral examination
    The exam is based on a project developed during the course.
    Students will work with a chosen case and:
    • identify a relevant risk scenario
    • analyze behavior and contributing factors
    • design a targeted intervention
    • document and reflect on expected and/or measured impact

    The exam consists of:
    • A written report
    • An oral presentation and discussion
    Assessment is based on the student’s ability to connect theory, method, and practical application.
    Individual exam or group exam
    Individual
    Exam languages
    English
    Duration
    30 minutes, including deliberation.
    The student starts with a 10 minutes presentation.
    Type of evaluation
    7-point grading scale
    Examiners
    Internal censure
53
hours of teaching
221
hours of preparation
The figure shows the extent of workload related to the subject divided into different study activities.

In the subject Cybersecurity Culture and Human Risk you will receive 53 hours of instruction, which corresponds to 70 lessons (1 lesson = 45 min.) and 19% of your total workload for the subject.

The teaching primarily consists of the following activities: classroom teaching, group work, exercises.
The preparation primarily consists of the following activities: group work, exercises.

Read about KEAs Study Activity Model

*KEA can deviate from the number of hours if this is justified by special circumstances