Human Risk Baseline & Gap Analysis
Establish a measurable baseline of employee cyber behavior, awareness maturity, exposure and organizational control gaps.
What this capability solves
Annual completion rates do not show whether people are becoming safer. A useful baseline combines knowledge, behavior, exposure, policy and organizational context so interventions can be prioritized.
Technology is implemented as an operating capability: architecture, integration, governance, assurance, people, procedures and measurable outcomes are designed together.
Capability model
Modular building blocks allow the scope to start with a focused pilot and expand into an enterprise operating model.
Population Segmentation
Map workforce by role, department, privilege, external exposure and business criticality.
Awareness Assessment
Measure knowledge and confidence on phishing, credentials, data handling, AI use and incident reporting.
Behavior Signals
Use approved simulation, training and policy interaction data to identify repeat-risk patterns.
Exposure Signals
Identify exposed corporate identities/credentials through authorized breach-exposure monitoring.
Control Gap Review
Assess programme governance, training cadence, phishing, reporting, policy, leadership and integration maturity.
Risk Baseline
Create individual/group risk bands with governance to avoid overinterpretation or punitive misuse.
How the capability fits together
Final topology, control placement and deployment model are validated during discovery and detailed design.
Controls & governance
- Data minimization and role-based access
- Transparent purpose and acceptable monitoring boundaries
- No punitive use of risk scores without governance
- False-positive and contextual review for behavioral indicators
- Controlled phishing rules and safe landing pages
- Policy/e-sign evidence integrity
- Retention limits for learning and simulation records
- Escalation for exposed credentials or high-risk patterns
- Management reporting focused on risk reduction, not surveillance
Priority use cases
- New human-risk programme
- Security culture transformation
- Post-incident improvement
- Merger/new workforce
- Regulatory awareness requirement
- High-risk department intervention
Key deliverables
- Human-risk maturity report
- Population segmentation
- Risk baseline dashboard
- Gap heatmap
- Priority intervention plan
- 90/180/365-day roadmap
Integration considerations
- HRIS / employee directory
- Google Workspace / Microsoft 365
- SSO / identity provider
- E-mail and approved chat channels
- SIEM/SOC or security operations
- GRC/policy repository
- Ticketing/workflow platform
- API/MCP integration layer
Phased delivery
Each phase ends with evidence, acceptance criteria and a decision gate before broader scale-out.
