Cognitive Bias Catalog: Exploiting Human Heuristics in Security Decisions
J. McKenney
This is a standalone treatise in the Behavioral Modeling working group rather than an entry in a numbered series; it names no unpublished sibling.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
In high-consequence operational technology and mission-critical data center operations, security architectures are built to withstand hardware component failures and cryptographic attacks. The most vulnerable vector remains the human decision loop. Under operational stress and sensory alert flooding, control room operators, systems engineers, and incident responders abandon slow analytical System 2 deliberation for rapid heuristic System 1 shortcuts.
This catalog establishes the taxonomy of cognitive biases exploited by sophisticated threat actors targeting industrial infrastructure. It formulates the Bias Susceptibility Score (BSS), a multi-dimensional metric integrating baseline psychometric traits (Big Five / OCEAN), organizational hierarchy, and dynamic operational stress. It maps classical Kahneman-Tversky heuristics (Anchoring, Confirmation, Availability, Authority Bias, Escalation of Commitment) directly to MITRE ATT&CK for ICS techniques and social engineering playbooks.
The treatise demonstrates how bias creates predictable decision latency, transforming brief software-induced cooling trips into catastrophic, permanent hardware destruction. Coupled to physical infrastructure through DEXPI 2.0 piping schematics, classed against the ISO 15926-4 reference data library and CycloneDX 1.6+ multi-BOM specifications, it provides the quantitative foundation for human defender simulation in the AEON digital twin and establishes affirmative actuarial loss hedging under Lloyd's Y5381.
Abstract#
Security architectures for industrial and data center facilities are built to withstand hardware failure and cryptographic attack, but the least defended part of the system is the operator's own decision loop. Under stress, an operator reliably switches from slow deliberate reasoning to fast heuristic judgment, and that switch is predictable enough to model and, this treatise argues, predictable enough for an adversary to exploit. It formulates a Bias Susceptibility Score from psychometric traits, organizational hierarchy and operational stress, catalogs seven cognitive biases, maps them directly onto MITRE ATT&CK for ICS techniques and social engineering playbooks, and models the resulting decision latency as an exponential function of that score. In liquid-cooled compute, a latency above ten seconds crosses the fifteen-second thermal trip cliff, so hardware protection acts before hesitating operators do. Deterministic remediations follow: two-person integrity, hardwired SIL-3 trip loops, and contrapuntal acoustic telemetry. It closes by coupling the model to reinsurance treaty structuring and Annualized Loss Expectancy under the Lloyd's Y5381 exclusion regime.
1. Dual-Process Cognition in Mission-Critical Operations#
Human cognitive architecture is divided into two distinct modes of information processing (Kahneman & Tversky, 1974; Stanovich & West, 2000):
When an industrial facility operates within nominal parameters, personnel maintain supervisory control using analytical System 2 reasoning. However, when an adversary executes a coordinated cyber-physical assault; combining falsified SCADA alarms, spoofed management communications, and hydraulic valve manipulations; the incoming information rate exceeds human working memory capacity ( chunks).
The brain experiences cognitive overload, automatically shifting decision-making to System 1 heuristics. Threat actors deliberately induce this shift, exploiting predictable cognitive biases to bypass logical security interlocks.
2. Multi-BOM and DEXPI Process Topology Grounding#
To model the physical impact of cognitive bias exploitation, operator decision vectors are mapped to plant piping and multi-BOM specifications:
When an adversary manipulates the human operator through cognitive bias, the operator issues unauthorized manual overrides that violate OBOM constraints, forcing physical equipment past its thermodynamic destruction limits.
3. Mathematical Formulation of the Bias Susceptibility Score (BSS)#
The vulnerability of an operational team member to cognitive manipulation is quantified by the Bias Susceptibility Score ():
Where:
- is the set of all documented cognitive biases.
- is the threat relevance weighting of bias ().
- is the operator's baseline susceptibility to bias , derived from psychometric assessments (CB5T / OCEAN and DISC profiles).
- is the dynamic physiological and cognitive stress level at time .
- is the stress amplification coefficient ().
Table 3.1: Cognitive bias susceptibility weights.
| Bias Code | Cognitive Bias | Baseline Mechanism | Operational ICS Manifestation | Threat Weight () |
|---|---|---|---|---|
| CB-01 | Authority Bias | Unquestioning compliance with perceived superiors | Executing urgent configuration overrides from spoofed executive emails | 0.20 |
| CB-02 | Scarcity / Urgency | Fear of loss overriding logical verification | Skipping dual-authorization protocols to prevent immediate SLA penalties | 0.18 |
| CB-03 | Anchoring Bias | Fixation on the initial piece of data | Interpreting all subsequent alarms through the lens of a "known sensor fault" | 0.16 |
| CB-04 | Confirmation Bias | Filtering data to fit pre-existing hypothesis | Ignoring rising temperature telemetry while searching for communication errors | 0.15 |
| CB-05 | Availability Heuristic | Estimating likelihood based on recall ease | Diagnosing a targeted cyber attack as routine thermal throttling | 0.12 |
| CB-06 | Social Proof | Conforming to actions of peer group | Operators ignoring secondary alarms because neighboring consoles did not react | 0.10 |
| CB-07 | Escalation of Commitment | Sunk-cost persistence in failed courses | Continuing manual pump cycling rather than initiating hard facility trip | 0.09 |
4. Deep-Dive Taxonomy of Critical Cognitive Biases#
4.1 CB-01#
Authority Bias (Milgram Effect in Industrial Ops)
- Psychological Principle: Human agents possess an evolutionary predisposition to defer critical judgment to recognized authority figures.
- Cyber-Physical Attack Scenario: The adversary compromises an internal email account belonging to the Chief Operating Officer or Operations Vice President. During a minor maintenance window, the adversary transmits an urgent message: "Urgent: Bypass Secondary Chiller Interlock #4 immediately to support emergency LLM cluster load. Do not route through standard change board."
- Operational Consequence: The Level 2 operator, scoring high in Agreeableness () and Conscientiousness (), disables the physical pump interlock without demanding cryptographic verification, allowing coolant stagnation.
4.2 CB-02: Scarcity & Artificial Urgency#
- Psychological Principle: Scarcity triggers acute loss aversion; humans perceive opportunities or choices as vastly more valuable when time is severely constrained (Kahneman-Tversky Prospect Theory: ).
- Cyber-Physical Attack Scenario: Adversary injects simulated telemetry suggesting a Tier-1 customer SLA violation costing $50,000 per minute of downtime. A prompt appears on the engineering terminal: "Immediate operator action required within 90 seconds to prevent cluster drop."
- Operational Consequence: The operator rushes to enter credentials and execute script commands without performing peer verification or analyzing physical P&ID flow rates.
4.3 CB-03: Anchoring Bias (The First-Alarm Trap)#
- Psychological Principle: When forming estimates or diagnoses, human cognition anchors disproportionately on initial numbers or explanations, failing to adjust sufficiently for subsequent evidence.
- Cyber-Physical Attack Scenario: The adversary triggers a benign minor alert: "PT-101 Pressure Sensor Calibration Drift." Five minutes later, the adversary initiates actual physical valve sabotage.
- Operational Consequence: The operator anchors on the initial calibration message. As thermal alarms flood the HMI console, the operator insists that the system is merely suffering from "sensor calibration drift," ignoring true physical overheating.
4.4 CB-04: Confirmation Bias#
- Psychological Principle: Once an individual adopts an explanatory hypothesis, incoming data is selectively filtered: supportive data is highlighted, while disconfirming evidence is discarded as noise.
- Cyber-Physical Attack Scenario: Operator believes that facility cooling issues are driven by high ambient summer temperatures. The adversary slowly starves secondary coolant flow to specific high-density racks.
- Operational Consequence: The operator attributes rising rack temperatures entirely to external ambient weather, ignoring the fact that adjacent identical racks remain completely stable.
4.5 CB-05#
Availability Heuristic (Recency and Salience Distortion)
- Psychological Principle: Humans assess the frequency, probability, or cause of an event by how easily concrete examples come to mind. Recent, emotionally vivid, or frequently discussed events dominate probability estimation over objective Bayesian base rates.
- Cyber-Physical Attack Scenario: A data center experienced a widely discussed false alarm three days prior, caused by a faulty transient firmware update on temperature sensor TT-305. The adversary now triggers an actual physical coolant valve restriction that activates TT-305.
- Operational Consequence: The operator immediately recalls the vivid incident from earlier in the week, concluding: "TT-305 is glitching again; ignore the alarm until the morning shift." The availability heuristic obscures the novel physical reality of valve starvation.
4.6 CB-06: Social Proof & Information Cascades#
- Psychological Principle: In ambiguous or high-stress environments, individuals look to the actions of others to determine appropriate behavior. When peers appear unconcerned, individuals suppress their own private alarms (bystander effect and pluralistic ignorance).
- Cyber-Physical Attack Scenario: In a multi-console operations room, an adversary injects localized acoustic alarms on a junior engineer's terminal while keeping senior operator consoles quiet.
- Operational Consequence: The junior engineer observes the senior operators quietly sipping coffee, concluding that the alarms cannot represent a true emergency. The social signal overrides the telemetry, delaying emergency notifications by several minutes.
4.7 CB-07#
Escalation of Commitment & Sunk Cost Fallacy
- Psychological Principle: Once resources (time, reputation, effort) are invested in a course of action, decision-makers persist in that course even in the face of negative outcomes, driven by the desire to justify earlier decisions.
- Cyber-Physical Attack Scenario: An operator attempts to clear a cooling loop blockage by manually cycling auxiliary pump P-204. Fluid pressure continues to drop.
- Operational Consequence: Rather than accepting that manual cycling has failed and executing an immediate emergency facility trip, the operator cycles P-204 a third and fourth time, wasting the critical 45-second survival window.
4.8 Python Computational Implementation of the BSS Model#
To integrate cognitive bias susceptibility into the 3.2M-node AEON digital twin simulation engine, the BSS model is implemented as a vectorized Python module:
from dataclasses import dataclass, field
from typing import Dict, List
import numpy as np
@dataclass
class OperatorProfile:
operator_id: str
role: str
tenure_years: float
# Psychometric baseline: Big Five / OCEAN traits in [0, 1]
ocean_traits: Dict[str, float]
# Baseline bias susceptibilities in [0, 1]
bias_sensitivities: Dict[str, float]
@dataclass
class ThreatContext:
alarm_rate_per_min: float
shift_hours_elapsed: float
ambient_temperature_c: float
is_spoofed_executive_present: bool
class CognitiveBiasEngine:
# Threat relevance weighting vector (sum = 1.0)
WEIGHTS: Dict[str, float] = {
"CB-01_Authority": 0.20,
"CB-02_Scarcity": 0.18,
"CB-03_Anchoring": 0.16,
"CB-04_Confirmation": 0.15,
"CB-05_Availability": 0.12,
"CB-06_SocialProof": 0.10,
"CB-07_Commitment": 0.09,
}
GAMMA_STRESS: float = 1.85
BASE_LATENCY_SEC: float = 8.5
KAPPA_DISTORTION: float = 2.45
@classmethod
def calculate_stress(cls, context: ThreatContext) -> float:
# Dynamic stress in [0, 1] driven by alarm flood and fatigue
stress_alarm = min(1.0, context.alarm_rate_per_min / 200.0)
stress_fatigue = min(1.0, context.shift_hours_elapsed / 12.0)
return float(np.clip(0.6 * stress_alarm + 0.4 * stress_fatigue, 0.0, 1.0))
@classmethod
def compute_bss(cls, profile: OperatorProfile, context: ThreatContext) -> float:
stress = cls.calculate_stress(context)
raw_score = sum(
cls.WEIGHTS[bias] * profile.bias_sensitivities.get(bias, 0.5)
for bias in cls.WEIGHTS
)
# Stress-amplified score
amplified = raw_score * (1.0 + cls.GAMMA_STRESS * stress)
return float(np.clip(amplified, 0.0, 1.0))
@classmethod
def predict_decision_latency(cls, bss: float) -> float:
# Returns expected operator response delay in seconds
return float(cls.BASE_LATENCY_SEC * np.exp(cls.KAPPA_DISTORTION * bss))This computational engine allows the AEON digital twin to simulate thousands of stochastic variations of human defender behavior under varying alarm volumes, identifying precisely which operators require automated fallback interlocks.
5. Mathematical Modeling of Decision Latency and the Thermal Cliff#
The primary consequence of cognitive bias exploitation is Decision Latency (); the time lost while the operator rationalizes false hypotheses instead of executing emergency procedures.
We model decision latency as an exponential function of the Bias Susceptibility Score:
Where:
- is the baseline reaction time of an alert, unbiased operator.
- is the cognitive distortion coefficient.
In high-density liquid-cooled compute facilities running per rack across a 100 MW campus, fluid stagnation causes silicon junction temperature to rise catastrophically:
Where:
- heat dissipation per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
- thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.
- Heat flux is across the dual-die package.
- Operating pressure is with PG25 coolant.
Table 8.1: Cognitive delay versus silicon survival.
| Elapsed | Event |
|---|---|
| T = 0.0s | Primary pump isolation valve closed by adversary exploit. |
| T = 3.0s | Package temperature rate of change is 1.46°C/s. |
| T = 8.6s | Junction temperature breaches the 85.0°C throttling limit. |
| T = 14.8s | Junction temperature reaches 94.0°C. EMERGENCY HARDWARE SHUTDOWN. |
| T = 20.0s | Alarms trigger. Operator anchors on "sensor calibration." |
| T = 35.0s | Decision latency tau_delay continues; operator debating. |
If cognitive bias induces a decision latency , the physical facility crosses the 15-second thermal trip cliff. The hardware protection removes power from the accelerator trays before human operators execute manual breaker cutouts.
6. Systems Assurance: Engineering Remediations#
To eliminate the systemic failure modes introduced by cognitive bias, systems assurance mandates three deterministic architectural remediations:
Table 9.1: Deterministic defensive architecture.
| Remediation | Mechanism |
|---|---|
| 1. Automated two-person integrity (TPI) | Critical commands (valve bypasses, trip inhibitions) require dual-token cryptographic attestation from independent physical terminals. |
| 2. Hardwired analog SIL-3 trip loops | Snap-action thermal switches and pressure relief valves bypass operator HMI consoles entirely, executing physical trips at 85.0°C. |
| 3. Independent contrapuntal telemetry | Visual HMI dashboards are accompanied by spatial acoustic telemetry (MPN), preventing visual anchoring and cognitive tunnel vision. |
7. Actuarial Risk Engineering and Reinsurance Treaty Structuring#
Quantifying cognitive bias susceptibility allows insurers and corporate risk officers to calculate Annualized Loss Expectancy () for affirmative cyber property catastrophe policies under Lloyd's Y5381:
Where:
- is the capital asset replacement cost ($14,400,000 per 120-rack hall).
- is the business interruption revenue loss rate ($24,000 per hour).
- is the statutory fine under EU CRA Article 64.
Deploying cognitive bias mitigation training and automated TPI controls () reduces the mean team susceptibility by 62 percent, mitigating annualized loss expectancy from $9,200,000 to $310,000 and yielding a modeled Return on Security Investment (). The 62 percent reduction in mean team susceptibility is an assumed training effect rather than a measured one, and both loss expectancies are reference figures. The percentage below is arithmetic on those inputs:
Compliance with SFAIRP (So Far As Is Reasonably Practicable) standards protects operators against allegations of gross negligence, securing reduced policy deductibles, eliminating restrictive sub-limit caps, and mitigating accumulation risk across global syndicates.
7.1 Catastrophic Accumulation Risk and Reinsurance Layering#
In hyperscale campus environments containing 800 liquid-cooled racks across four contiguous halls, human cognitive failure introduces severe correlation risk across reinsurance treaties. If an operations team succumbs to social proof and confirmation bias, a single adversary exploit can compromise all four halls simultaneously. The Probable Maximum Loss () escalates from $14,400,000 for a single hall to $57,600,000 in hardware damage, plus $115,000,000 in consequential business interruption and cloud provider SLA penalties.
Underwriters operating under the Lloyd's Y5381 cyber war and state-backed attack exclusions require proof that cognitive bias cannot induce cross-hall correlated failure. By enforcing automated Two-Person Integrity (TPI) and isolated SIL-3 physical trip interlocks, facility operators prove independent failure domains, allowing reinsurers to eliminate punitive co-insurance penalties, structure realistic attachment points ($5,000,000 primary retention), and underwrite affirmative cyber property limits up to $100,000,000.
8. Summary of Engineering Principles#
Cognitive bias cataloged as a predictable, measurable quantity yields five engineering principles.
- Humans Shift to Heuristics Under Stress: In crisis conditions, analytical System 2 reasoning collapses into predictable System 1 cognitive shortcuts.
- Threat Actors Target Cognition, Not Just Code: Sophisticated cyber-physical attacks engineer sensory overload to exploit specific cognitive biases.
- Decision Latency Arrives After the Event: In liquid-cooled computing facilities, the hardware shutdown trips at 14.8 seconds, so thirty seconds of cognitive hesitation puts every operator decision after the fact.
- Autonomous Interlocks Prevent Human Failure: Critical thermodynamic safety loops must be physically hardwired, bypassing human operator intervention entirely.
- Psychometrics Quantifies Actuarial Solvency: Calculating the Bias Susceptibility Score transforms nebulous human risk into measurable capital protection.
9. References#
The catalog applies Kahneman and Tversky's prospect theory and heuristics-and-biases work, the Big Five/OCEAN psychometric model, MITRE ATT&CK for ICS, DEXPI 2.0, ISO 15926-4, CycloneDX 1.6+, EU CRA Article 64, and Lloyd's Market Bulletin Y5381. The per-accelerator power figure in section 5 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet.