Think Like a Bad Guy
Why defenders need permission to break the mental model.
A conversation about adversarial imagination, psychological safety and the conditions that help good people spot what attackers see.
Behavioural scientist · Human-risk strategist · Professional social engineer
Security improves when people are safe enough to think dangerously.
Si turns attacker thinking, behavioural science and original research into provocative talks that help organisations make better security decisions.
Currently leading human risk management in UK critical national infrastructure and advising UK Defence on behavioural science.

Seen and heard at
Recurring themes / built around the room
These are starting points, not scripts. Every session is shaped around the audience, the format and the question worth putting under pressure.
Why defenders need permission to break the mental model.
A conversation about adversarial imagination, psychological safety and the conditions that help good people spot what attackers see.
Why annual training and phishing tests keep failing.
A threat-led alternative to the train, test and blame loop. Diagnose the behaviour, design the intervention and measure what changes.
How blame changes the choices people make.
How blame, militarised metaphors and the way security talks about people shape behaviour, responsibility and outcomes.
Why points and badges rarely create learning.
Use narrative, tension and meaningful choices to create learning people remember and decisions they can actually rehearse.
What control culture hides from leaders.
Why rigid security cultures block adaptation, silence weak signals and make it harder for good people to do the right thing.
How to move from content calendars to targeted intervention.
A practical operating model for connecting threat intelligence, behavioural diagnosis and interventions that can be observed.
Start with the brief, not the title.Tell Si who is in the room, what they care about and what you want them debating afterwards.
Discuss the briefWhy Si is worth the microphone
Strong views are useful only when they survive contact with real work, real research and a curious interviewer.
Defence, critical national infrastructure and global organisations. Si brings situations he has handled, not borrowed case studies.
Doctoral and peer-reviewed research grounds the provocation, without turning the session into an academic lecture.
Professional social engineering brings the choices, pressure and human detail that make an audience lean in.
Speaker reel
A short look at Si on stage, building an argument and bringing the audience into the conversation.
Watch on YouTubeMore listening and evidence
Practitioner / researcher / useful bad influence
Si Pavitt works at the intersection of forensic psychology, professional social engineering and organisational security. He leads human risk management for SGN and serves as behavioural science advisor to the UK MOD’s Cyber Advisory Team.
Previously, he led behavioural science for UK Strategic Command’s Cyber Vulnerability Investigations and served as the Ministry of Defence’s Head of Cyber Awareness, Behaviours and Culture. He is a Royal Signals officer and an active doctoral researcher.
His work has reached UN agencies, national ministries, critical infrastructure, global industry and academic classrooms. His talks leave audiences with a better question, not another checklist.
For producers and programme teams
Si is entirely vendor agnostic. He does not represent a platform, consultancy or security product. The agenda is human risk management: making people active participants in security decisions from the start.
One sharp argument, memorable evidence and practical movement.
Generous, curious and comfortable following the difficult thread.
Research-led sessions designed around the room and its real work.
Where the perspective comes from
Si’s point of view was formed across operational security, organisational leadership, adversarial practice and research. It is broader than a conference biography.
Leading human risk management where culture, operations and consequence meet. The work has to survive contact with real systems and real constraints.
A Royal Signals officer, former MOD Head of Cyber Awareness, Behaviours and Culture, and former behavioural science lead for UK Strategic Command’s Cyber Vulnerability Investigations.
Field practice testing how people, authority, physical spaces and organisational assumptions behave under pressure. The attacker view is lived, not borrowed.
Doctoral and peer-reviewed research, with regular teaching at the Defence Academy and guest work with Cranfield University and the University of St Gallen.
Range beyond the job title.Si has brought this work to UN agencies, national ministries, global manufacturers, schools and international audiences. A team he led won an MCA Award in 2022.
Speaking enquiries
Send the audience, format, date and the question you want the room to wrestle with. Si replies directly.