Enter your keyword

← All Projects  ›  Next-Generation Security Awareness & Human Risk Management Programme
Project 09 - Human Risk Management

Next-Generation Security Awareness & Human Risk Management Programme

AI-Era Threats · 8-KPI Framework · NDPA/PIPEDA

Designed and delivered a next-generation awareness program addressing deepfakes and AI-era threats - achieving 97% completion, 100% board participation, and reducing phishing click rate from 34% to 6%.

34% → 6% click rate97% completion100% board8% → 41% reportingAI-era threatsDeepfake awarenessNDPA/PIPEDA
34%→6%
Phishing click rate
97%
Staff completion
100%
Board completion
41%
Reporting rate
The Challenge
Problem Statement

The institution's existing security awareness program was generic, compliance-driven, and not addressing the threat landscape staff actually faced. Phishing simulation click rates were at 34% - nearly one in three employees was clicking on simulated phishing emails. The reporting rate for suspicious emails was 8% - most staff who recognized a threat were not reporting it. The program did not address AI-generated phishing, deepfake social engineering, or the data privacy obligations under NDPA 2023 and PIPEDA that were increasingly relevant to staff handling customer data.

The Approach
How I Solved It

I rebuilt the program from the curriculum up. I designed six role-specific training modules covering AI-era threats, deepfake recognition, BEC and financial fraud, data privacy obligations (NDPA/PIPEDA), social engineering, and incident reporting. I implemented a phishing simulation programme using AI-quality templates that matched the sophistication of current threat actor campaigns - not the obvious stock phishing templates most platforms use. I built an 8-KPI human risk framework tracking click rate, reporting rate, training completion, repeat clickers, time-to-report, manager completion, board completion, and privacy incident rate. I designed a board-level human risk dashboard presenting behavioural metrics alongside program KPIs.

Frameworks & Standards
NDPA 2023
PIPEDA
NIST CSF PR.AT
ISO 27001 A.6.3
NIST AI RMF (AI threat literacy)
Tools & Platforms
KnowBe4 · LMS platform · 8-KPI dashboard · Board reporting · Phishing simulation
Category
Security Awareness · Human Risk · AI Threats
What Was Delivered
Outcomes & Results
Phishing simulation click rate reduced from 34% to under 6% within two simulation cycles
Suspicious email reporting rate increased from 8% to 41% - staff became active defenders, not passive bystanders
97% staff training completion rate achieved - exceeding the 95% target
100% Board and C-suite completion - first time the board fully engaged with security awareness as governance
8-KPI human risk framework designed and implemented - reported to Board Risk Committee quarterly
Six role-specific training modules built addressing AI-era threats including deepfake social engineering
NDPA 2023 and PIPEDA data privacy compliance integrated into the curriculum
Key Lesson
The reporting rate metric - going from 8% to 41% - matters more than the click rate. A low click rate means your simulations are working. A high reporting rate means your culture is working. The goal is not employees who avoid clicking; it is employees who actively report. Those are different programs with different designs, and most awareness programs only optimize for the former.
// Evidence vault
All project artifacts are available in the Evidence Vault.
Policies, playbooks, workbooks, and dashboards - downloadable evidence from real programs.