Security Program & Human Risk
Case StudySecurity Awareness & Human-Risk Program
A comprehensive security-awareness and human-risk program for a mid-size enterprise with a weak security posture — ten interlocking policies, a stakeholder communication plan, and a culture shift from fear to transparency.
- Role
- Security program lead / CISO capacity (engagement deliverable)
- Timeframe
- 2026
- Stack & Standards
- NIST SP 800-53 · Security awareness training · Phishing simulation · Separation of duties
The Challenge
Where things stood
A mid-size enterprise was operating with a critically low security posture: successful phishing attacks, recurring insider theft, no log collection, and vulnerability assessments run only once every three years. High turnover and low morale were fueling both unintentional errors and intentional insider threats. Acting in a CISO capacity, I designed a program to raise the posture from the human layer up.
Successful phishing and social-engineering attacks from untrained staff.
Insider theft enabled by no separation of duties and no log visibility.
Stale, three-year vulnerability assessment cycle.
High turnover and low morale eroding institutional security knowledge.
The Approach
From analysis to a delivered solution
Assessed posture and human factors
Categorized the security posture and separated the drivers into human factors (unintentional vs. intentional threats) and organizational factors (data flow, work setting, readiness).
Wrote ten interlocking policies
Mandatory awareness training and quarterly phishing simulations, separation of duties with mandatory vacation, AES-256 encryption, IDPS, centralized SIEM log management, media access control, and monthly vulnerability management — each mapped to NIST 800-53 controls with real-world use cases.
Tailored the communication plan
Distinct messaging for leadership (business enablement, click-through-rate reduction) and non-technical staff (relatable, empowering habits) to drive comprehension and buy-in.
Shifted the culture
Moved the organization from a culture of fear to one of transparency, where reporting a mistake early lets the team contain a threat in minutes.
The Outcome
What it delivered
Interlocking security policies
800-53-aligned controls
Vulnerability scanning cadence
Firewall culture established
Security awareness training with quarterly phishing simulations.
Separation of duties + mandatory vacation to surface insider fraud.
Centralized SIEM log management and daily monitoring.
Stakeholder-specific communication and culture-change plan.
Stack & Standards
Anonymized engagement deliverable. Organization details generalized; program design is my own work.
Have a problem that looks like this?
I take security, network, and data problems from analysis to a delivered, defensible solution. Let's talk about yours.