BLUF

Cybersecurity is not just technical—it is behavioral. In a GRC role, most risk comes from how people think, act, and make decisions. Social science concepts like human behavior, risk perception, and organizational culture directly shape how security actually works.

Introduction

Cybersecurity is often viewed as technical, but that is only part of it. The career I am focusing on is a GRC Analyst, which aligns with my goals in cybersecurity. This role focuses on managing risk, enforcing compliance, and making sure systems are secure and accountable.

From my labs and research, most security failures come from people, not systems. This paper explains how social science concepts apply to a GRC role and how they show up in real work.

Social Science Principles in Cybersecurity

The biggest factor in cybersecurity is human behavior. Research shows that “95% of all cyber incidents are human-enabled” (Nobles, 2018, p. 71) . That means users, not systems, are the main risk.

In GRC, this impacts everything. If systems are too complex, users bypass them. If training is weak, users make bad decisions. Policies must be built around how people actually behave.

Another key concept is organizational culture. If leadership does not prioritize security, employees will not either. Culture drives compliance more than tools.

There is also technological determinism—the idea that companies rely too much on tools to fix problems. Nobles (2018) makes it clear that technology alone will not solve human error . In GRC, behavior must be addressed along with technology.

Application of Key Concepts

Risk Perception

Organizations prioritize security based on risk. GRC analysts assess impact and likelihood to decide what matters most.

Human Behavior and Social Engineering

Most attacks target people. Phishing and scams rely on human psychology. GRC responds with training and policy enforcement.

Theory of Planned Behavior

People act based on what they understand and believe. Employees are not trying to cause harm—they are trying to do their jobs. Many mistakes come from normal decision-making under pressure (Nobles, 2018).

Compliance and Social Order

Frameworks like HIPAA and GDPR exist to protect people. GRC ensures organizations follow these expectations.

Human Factors

Human error is a major risk. GRC identifies these risks and builds controls to reduce them.

Marginalization

Cybersecurity affects groups differently. Some are more vulnerable than others.  Research shows that “marginalized communities are disproportionately vulnerable to cybersecurity threats” (Chattopadhyay et al., 2024, p. 1) .  One issue is limited access to secure technology. Not everyone has updated systems or strong protections.

Another issue is recovery. These groups are “less able to recover from attacks such as identity theft [and] financial loss” .  A third issue is lack of focus in research. Only about 0.2% of cybersecurity studies include marginalized groups .  In GRC, this matters because policies should protect everyone. If they do not account for different groups, they fail.

From a GRC standpoint, this means policies, training, and controls have to be designed with these gaps in mind so security is not just applied, but applied fairly.

Career Connection to Society

Cybersecurity supports critical systems like healthcare and finance. When security fails, real people are affected.  Compliance frameworks tie security to law, ethics, and trust. GRC ensures organizations meet these expectations.  Modern systems also require real-time risk management and response. This shows how the role continues to evolve.  GRC professionals help maintain stability and trust in society by keeping systems secure and accountable.  At the same time, as society becomes more digital, cybersecurity demands increase, which forces organizations to constantly adapt how they manage risk and compliance.

Conclusion

A GRC cybersecurity role is not just technical. It depends on understanding people, behavior, and decision-making.  Technology alone is not enough. Human behavior drives most risk.  Social science concepts like human factors, risk perception, and organizational culture are part of the foundation of cybersecurity. GRC connects these concepts to real-world security.

References

Chattopadhyay, A., Carvajal, R., Chaganti, V., & Venkatagiri, S. (2024). Where are marginalized communities in cybersecurity research? USENIX Symposium on Usable Privacy and Security (SOUPS).

Hasan, M., & Faruq, M. O. (2025). AI-augmented risk detection in cybersecurity compliance: A GRC-based evaluation. ASRC Procedia.

Nobles, C. (2018). Botching human factors in cybersecurity in business organizations. HOLISTICA, 9(3), 71–88. https://doi.org/10.2478/hjbpa-2018-0024

Ugoaghalam, U. J., Salami, E. O., & Enyejo, L. A. (2025). Real-time policy orchestration for cybersecurity risk management in fintech infrastructures. International Journal of Innovative Science and Research Technology.

Urhobo, B. (2024). Understanding the role of artificial intelligence in enhancing GRC practices in cybersecurity. World Journal of Advanced Research and Reviews.