Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC540 Criminological and Human Factors in Cybersecurity
This unit examines why people offend, comply, fail or collude in cyberspace and how organisations can convert that knowledge into effective policy and prevention. Drawing on criminology, behavioural economics, organisational psychology and cyber-risk management, students evaluate offender pathways, victimology, social-engineering techniques and insider-threat dynamics. They then design evidence-based interventions—awareness campaigns, situational crime-prevention controls, nudges and deception technologies—while navigating legal and ethical limits.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC401 Foundations of Cybersecurity and ITC402 Cybersecurity Management
UNIT LEARNING OUTCOMES
- Critically analyse major criminological and behavioural theories to explain cyber offending, victimisation and insider threat
- Critically evaluate organisational, cultural and individual risk factors that shape security-critical behaviour
- Create and implement an evidence-based interventions including awareness, situational crime-prevention and deception controls to mitigate human-factor risk
- Integrate legal, ethical and sustainability considerations into human-centred cybersecurity strategies
- Communicate and defend criminology-informed recommendations to technical and non-technical stakeholders through professional briefs and presentations
CONTENT
- Cybercrime ecosystem and offence scripts
- Classical, rational-choice and routine-activity theories in cyberspace
- Social learning, subcultures and dark-web communities
- Victimology: fraud, romance scams & high-risk populations
- Insider threat psychology and behavioural analytics
- Social engineering and persuasion science (phishing lab)
- Organisational culture, climate and security nudges
- Situational crime prevention and deception (honeypots, honey-tokens)
- Legal-ethical boundaries: privacy, surveillance & employee monitoring
- Designing behaviour-change programs (COM-B, Nudge, SANS maturity)
- Metrics and ROI for human-factor controls; reporting to boards
- Emerging issues: AI-generated influence ops and cyber deviance futures
ASSESSMENT METHODS
- Critical Theory Brief – 20%
- Group Social Engineering Simulation Presentation and Report – 30%
- Human-Factor Intervention Proposal and Viva – 50%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












