Where we came from, and why it matters
Cyber Innovations Group Ltd. was founded in 2024, but the thinking behind it started years earlier, in research into why conventional cybersecurity training so often fails to change how people behave when it counts.
The problem is not awareness. Most people in most organisations know that phishing exists, that passwords matter, that they should not click suspicious links. The problem is what happens in the moment: the cognitive overload, the social pressure, the time pressure, the shame that follows a mistake, and the organisational cultures that make reporting feel more dangerous than saying nothing.
That gap, between knowing and doing, between training and response, is where Cyber Innovations operates. Our founders came to it from different directions. Professor Vasilis Katos brought deep technical expertise in cybersecurity, threat intelligence, and security operations, alongside a decade of research into how attacks actually unfold through human systems. Emily Rosenorn-Lanng brought applied psychology, behavioural research, evaluation design, and years of experience building programmes that create lasting change in how people understand and respond to risk.
Together, they developed the Human Layer Kill Chain: a published conceptual framework that maps how attackers exploit human behaviour at each stage of a campaign, and how organisations can intervene at every point. The HLKC is not just an academic model. It is the structural backbone of Cyber Self Defence, the CSD Toolkit, and the facilitated training activities that have been delivered with organisations across the South West and beyond.
Cyber Innovations is rooted in research at Bournemouth University and has been supported by Innovate UK through both the CyberASAP accelerator and the Cyber Local programme. That funding has allowed the team to validate the approach with real organisations, develop the product ecosystem, and build the evidence base that underpins everything the company does.
The goal has always been the same: to make human-layer cyber resilience practical, accessible, and lasting, for organisations that cannot afford to get it wrong.
