Next-Generation Security Awareness & Human Risk Management Programme
Designed and delivered a next-generation awareness program addressing deepfakes and AI-era threats - achieving 97% completion, 100% board participation, and reducing phishing click rate from 34% to 6%.
The institution's existing security awareness program was generic, compliance-driven, and not addressing the threat landscape staff actually faced. Phishing simulation click rates were at 34% - nearly one in three employees was clicking on simulated phishing emails. The reporting rate for suspicious emails was 8% - most staff who recognized a threat were not reporting it. The program did not address AI-generated phishing, deepfake social engineering, or the data privacy obligations under NDPA 2023 and PIPEDA that were increasingly relevant to staff handling customer data.
I rebuilt the program from the curriculum up. I designed six role-specific training modules covering AI-era threats, deepfake recognition, BEC and financial fraud, data privacy obligations (NDPA/PIPEDA), social engineering, and incident reporting. I implemented a phishing simulation programme using AI-quality templates that matched the sophistication of current threat actor campaigns - not the obvious stock phishing templates most platforms use. I built an 8-KPI human risk framework tracking click rate, reporting rate, training completion, repeat clickers, time-to-report, manager completion, board completion, and privacy incident rate. I designed a board-level human risk dashboard presenting behavioural metrics alongside program KPIs.