The Wallpaper Effect

“Man is a creature that can get used to anything, and I think that is the best definition of him.” (Dostoevsky, 1862)
Bad Habits
A habit is a learned behaviour, something we do repeatedly until it runs on autopilot, and we complete tasks with little recollection of actually doing them. Habituation is a well-established finding in behavioural science that describes a decreased response an organism has to a stimulus that repeats without consequence.
Habits lead to habituation, and when repeated in a pattern, it creates the Wallpaper Effect.
When studying how the brain responds to repeated security warnings, Anderson et al. (2015) found a direct drop-off in activity in the brain’s processing centres after the second exposure to a warning with no consequence. In other words, if I receive an email with a banner warning that it has come from outside my environment, and nothing happens as a result, the part of my brain responsible for attending to that warning becomes less active the more often I see it, and before I have even evaluated if there actually is any danger.
This behaviour then becomes the habit the more often it happens, which in your average corporate environment is rather quickly. The brain isn’t telling me the warning is safe; it is simply switching off the part that pays attention to it because it wants to conserve ‘processing power,’ and the result is that I no longer notice the warning.
The Wallpaper Effect is an area of Cybersecurity awareness that many of us feel needs to be addressed because the standard response to an ignored warning is to add another warning, which only exacerbates the very problem in the first place.
To bring this home, how many snooze alarms do you have along with your regular alarm in the mornings?
The Neuroscience of Not Noticing
Habituation is one side of the coin; the flip side is the “orienting reflex,” which is the brain’s automatic shift in attention towards anything new and novel. One half governs what we notice, the other what we tune out (Barry, 2009).
This pairing likely exists because attention is expensive; a brain that reacts to repeated stimuli would be exhausted in a short space of time. Research using fMRI showed that the visual processing areas of the brain showed a dramatic drop in activity when comparing the first exposure to a security warning to the second, with further decline thereafter with each subsequent viewing (Anderson et al., 2015). The study was repeated using eye tracking and actual behaviour in the work environment and was successfully repeated with overwhelming confirmation of the same outcome (Anderson et al., 2018).
Bravo-Lillo’s (2014) doctoral thesis found that even carefully engineered designs and attention-grabbing elements termed ‘Attractors’ lose their effect once a user has seen them enough times.
Cognitive Overload and Heuristics
Habituation explains why a specific, repeated pattern is ignored, and cognitive load theory explains why the brain reaches for this shortcut. Daniel Kahneman’s (2011) dual-process thinking provides the perfect explanation for this process.
System 1 is fast, automatic, and likes to match patterns, while System 2 is slow, effortful, and prefers to evaluate against deliberate, analytical criteria. Under normal circumstances, people can rely on System 2 when something looks off, but under cognitive duress, people tend to look for a shortcut. Multiple research papers confirm this pattern (Zhuo et al., 2024), finding that people under high cognitive load are more susceptible to phishing attempts compared to those under low cognitive load. The reason for this is that in these scenarios, System 1 took over processing decisions.
The terms associated with this range from Cognitive Overload to Decision Fatigue, but at the heart of it, thinking and critical analysis are finite resources that the brain hoards like a miser. Under strain, the brain will default to whichever shortcut requires the least amount of effort, and attackers understand this all too well.
Reducing risk and creating more noise
Studies we have already discussed point to the reason why these activities backfire: repetition is the mechanism that causes habituation. Frequent repetition of these warnings in different formats will only lead to the same result, albeit slightly faster each time, until it becomes a habit and part of the office wallpaper that nobody realises is there anymore.
The more durable solutions work by disrupting pattern recognition rather than adding to them. Bravo-Lillo’s attractor designs took an approach requiring a break in attention, a swipe, an action, or behaviour on the part of the viewer at the interaction level, allowing for a brief moment where System 2 could “take the wheel” from System 1, essentially interrupting the habituation process by forcing renewed attention rather than relying on the user noticing anything unprompted.
The Attackers Know
(Böhme & and Köpsell, (2010) ran a consent dialogue experiment across 80,000 users. In this experiment, they used a program to insert consent dialogue (resembling the standard end-user license agreements everyone clicks past without reading, but in various forms) randomly during the use of the anonymous application. The findings showed that the more the consent dialogue looked like standard end-user licence agreements, the more reflexively people scrolled to the bottom and clicked (without reading), even though some of the text had serious privacy implications.
This shows that the Wallpaper Effect doesn’t need to be repetitive to be effective; it only needs to resemble something that users have encountered before elsewhere to have the same effect the very first time it is viewed. Years of habituation to online consent forms and cookies have created a reflex that activates as soon as the familiar format is encountered, regardless of its content.
None of what we are discussing is lost on the professionals out there who plan and create their attacks. Every well-run phishing campaign is built on the assumption that a target will be operating in System 1. Every message is then created to keep them there, through urgency, authority, or scarcity (there are many to choose from), but these are all cues that short-circuit System 2 thinking and hinder critical thinking.
Volume and repetition are part of their toolkit when considering authentication fatigue attacks, which play on the same habituation curve each time a prompt is sent. This logic also drives high-volume phishing attacks aimed at security teams, as they are designed to exhaust staff to the point where one genuine attack slips through, buried in the noise of routine (Lakshmanan, 2026).
Attackers love to time campaigns around the moments where people have the least cognitive bandwidth left, such as at the end of the day (especially Fridays), end of the month (accounting, invoicing, rentals), the quarter (finance and business) or upon a staff members return from annual leave, because this is when the brain drowns in the demand for attention and reaches for that shortcut.
The Simplest of Conclusions
Our training is built on this principle. Our instructional designers and content creators design with cognitive load in mind from the outset, rather than treating it as an afterthought once the content is finished. There is nothing worse than generic training, pushed onto people who are already operating under heavy cognitive loads, built with no purpose beyond ticking a compliance checkbox. Building awareness programmes as a genuine behavioural experience, rather than a transfer of information, is what we specialise in, and it is how we foster cultural environments where staff have a high cyber posture and awareness. It is also how the habituation we have been discussing in this article is reduced, rather than reinforced as a habit.
You cannot train a brain out of habituation by giving it more of the stimulus it has already learned to ignore. You can only change what the stimulus looks like, when it appears, and what it costs to click through.
The Wallpaper Effect is not a training failure, nor a compliance failure, or evidence that your HR or security teams are not taking security seriously. It is a predictable, demonstrable, and well-documented effect of our biology and neurology operating exactly as it should in an over-stimulating environment. Attackers understand this and use it regularly, but organisations that don’t, will continue to spend money on over-priced phishing simulations with poorly made training supplements and software that patches the problem with another pop-up or banner, leaving the underlying cause of the problem unaddressed.
The organisations that understand the mechanisms, the biology, and cyberpsychology behind the behaviour are the ones with the power to change it, reshape the surrounding culture, and bring down click and phishing misuse that still remains the easiest way into an organisation (Verizon DBIR Team, 2024) no matter how much has been spent hardening everything else.
Basil Polydorou – Head of Learning Solutions | BsC Cyber Psychology Candidate
References
Cerullo, M. 2024, January 16.
Anderson, B. B., Bjornn, D., Jenkins, J., Kirwan, B., & Vance, A. (2018). Improving Security Message Adherence through Improved Comprehension: Neural and Behavioral Insights. AMCIS 2018 Proceedings. https://aisel.aisnet.org/amcis2018/Security/Presentations/34
Anderson, B. B., Kirwan, C. B., Jenkins, J. L., Eargle, D., Howard, S., & Vance, A. (2015). How Polymorphic Warnings Reduce Habituation in the Brain: Insights from an fMRI Study. Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems, CHI ’15, 2883–2892. https://doi.org/10.1145/2702123.2702322
Barry, R. J. (2009). Habituation of the orienting reflex and the development of Preliminary Process Theory. Neurobiology of Learning and Memory, Special Issue: Neurobiology of Habituation, 92(2), 235–242. https://doi.org/10.1016/j.nlm.2008.07.007
Böhme, R., & Köpsell, S. (2010). Trained to accept? A field experiment on consent dialogs. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI ’10, 2403–2406. https://doi.org/10.1145/1753326.1753689
Bravo-Lillo, C. (2014). Improving Computer Security Dialogs: An Exploration of Attention and Habituation – ProQuest [Doctoral, Carnegie Mellon University]. https://www.proquest.com/openview/23428c21761e0a56dbbfaf40652527c2/1?pq-origsite=gscholar&cbl=18750
Dostoevsky, F. (1862). The House of the Dead (C. Garnett, Trans.). Standard Ebooks. https://standardebooks.org/ebooks/fyodor-dostoevsky/the-house-of-the-dead/constance-garnett
Kahneman, D. (2011). Thinking, fast and slow. Penguin.
Lakshmanan, R. (2026, September 4). Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters. The Hacker News. https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
Verizon DBIR Team. (2024). 2024 data breach investigations report (p. 100) [Annual]. Verizon Business. https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf
Zhuo, S., Biddle, R., Betts, L., Arachchilage, N. A. G., Koh, Y. S., Russello, G., Lottridge, D., & Biddle, R. (2024). The Impact of Workload on Phishing Susceptibility: An Experiment. Proceedings 2024 Symposium on Usable Security. Symposium on Usable Security. https://doi.org/10.14722/usec.2024.23024