Human layer
What this is
Every control in this list assumes a person will not hand over the thing it protects. The human layer is the work of making that assumption safer. Simulation to find out where the organisation actually stands, training assigned where the weakness is, and a route for a user to report something and get an answer.
Why it matters
Phishing does not defeat a control. It borrows a person's authority and then uses the controls exactly as designed, which is why nothing downstream of the user sees anything wrong. The defence cannot be a product the user never meets. It has to change what the user does, and the evidence that it has is behaviour measured before and after.
There is a second mechanism, and it is the one most programmes lose. Training a user to report creates a queue. If that queue arrives in a mailbox with no owner, the user reports twice and then stops, and the budget has been spent teaching people that reporting achieves nothing. The reporting path is part of the control, not an operational detail behind it.
Awareness is also a control an auditor can ask for evidence of and get a straight answer. Who was trained, when, and what they did next.
What it solves
- Users trained once a year and measured never
- Reported mail arriving somewhere with no owner and no response
- Sensitive files sent by ordinary email because the secure route is slower
- Audit requests for evidence that training happened and changed something
In our portfolio
Next to this
Email and file encryption touches data protection. The key custody half of that problem is a different product and a different area, and it sits with Procenne.