Issue030 8 September 2026

The Set Point

Amy Stokes-Waters

When Nobody’s Watching episode four went out last Wednesday, and the guest has, in my very own articulate words to her face, jack shit to do with cyber security. And that’s why we invited her along.

Katie Maycock runs a business called Get Your Sh*t Together. She goes into companies and looks at what pressure does to a person, and then what it does to the team around them, then what it does to the organisation. Basically, she watches people under pressure for a living. And she’s very bloody good at it.

Her method goes like this. She has leaders fill in a behavioural profile before a session. How do you think you behaved under pressure? They write it down. Then she puts them under real pressure, observes them, and writes a profile of how they actually did.

“How they think they perform under pressure when you ask them when they’re not under pressure is so interesting,” she said. “They always say, ‘I think I do this, and I behave this way.’ And then what we actually see is it’s usually something vastly different.”

Now swap the word “leaders” for “your workforce”. Everyone in your organisation would tell you, sitting comfortably, that they would never click a phishing link. Never had over a password. Never move money on a phone call. And in a calm room, every single person is telling the truth. The profile they’d write of themselves is accurate, for the version of them that’s sitting in a calm room.

That isn’t the version that the attacker gets.

Katie told me about running leadership sessions in boardrooms. Everybody nodding, “sitting there having their tea, having their biscuits”, and taking it all in. Then real pressure lands on them and “everything they learned just went out the window and they would just go back to what their instinct was.”

And that’s what we’ve been spouting for a while now. Paraphrasing the lovely James Clear. People don’t rise to the level of their training. They fall to the level of their instinct. And Katie agreed. She’s even named it!

“We talk about your set point. So you’ve got a set point of how you behave under pressure. You’ve built habits, you’ve built behaviours, you’ve taken actions in similar situations and you’ve embedded them. So you might have learnt all these things from childhood and you’re now showing them in the workplace.”

So the behaviour that runs your incident response wasn’t installed by your security team. It was installed years ago, possibly decades ago, by every similar situation the person has ever been in. Your module is competing with somebody’s childhood, and the module is losing.

I asked Katie onto the show for exactly this reason. I’ve been making this argument from inside the industry. Based on what we’ve seen over the last few years. Katie’s arrived at the same conclusion from her work on stress and burnout, with no reason to flatter us and no idea what a phishing simulation costs. Two people walking from opposite directions and meeting at the same spot.

So, why does the calm room version of you vanish?

Katie’s answer: “If you’re learning phishing emails when you’re relaxed, just laying back on a chair having your tea and your biccies… you’re not gonna remember that. But if you learn under pressure your brain’s gonna link that into that memory.”

Your brain files the lesson with the state you were in when you learned it. Calm, mildly bored, clicking next. When the bad day arrives, nothing in that moment is going to reach for the calm-and-bored file. It reaches for whatever was filed under pressure. The set point.

And if you want proof that pressure files things properly, she has a test everyone passes. Think of a moment that made you cringe. Properly cringe. “You’ve never done it again, have you?”

Then fear, which the industry gets backwards. I asked her whether fear ever supports anything positive. She said no, and stopped. Then the mechanism: survival mode, tunnel vision, running on the limbic brain instead of the analytical one. “All you’re going to be seeing is threats.” Frightened people cut corners and rush the very thing you’re threatening them over. So the programme built on “fail the sim and you’ll be reported” isn’t building a better set point. It’s making sure the only thing filed under pressure is dread.

What do you do with this?

Stop asking people how they’d behave. Katie’s leaders were sincere and wrong, every time, and yours will be too. The only honest profile is the observed one… somebody under something close to real pressure, doing the thing, then being walked through what just happened in their own head.

That’s what the debrief is for. That’s why the room is a nuclear power plant and not an office, and why neither of us cares that the scenario is ridiculous. The scenarios “very, very rarely mimic real life”, but “the behavioural conditions that it puts you under 100% mimic exactly the things that you’re gonna do in there.”

So this week, pick one person. Not the one you’re worried about. The one who’d write the best profile of themselves. Then ask what you actually know about how they behave when the phone rings and the caller already has a problem and a rescue ready for them.

If the answer is “nothing, but they passed the module”, you don’t have a security programme for that person. You have their opinion of themselves.

Katie’s episode is live now, and she’s brilliant on the rest of it too: the five things people do under pressure and why almost nobody recognises their own, why the first sign of stress is a change of habit your boss will praise you for, and the pen tapper, who I promise you have worked with. Watch it here. Then think about what your own set point is. It’s never the way you think.

That's it for this week. Reply and tell me what you think.

Amy

Amy Stokes-Waters · Founder, The Cyber Escape Room Co.