All case studies

Security Program & Human Risk

Case Study

Security Awareness & Human-Risk Program

A comprehensive security-awareness and human-risk program for a mid-size enterprise with a weak security posture — ten interlocking policies, a stakeholder communication plan, and a culture shift from fear to transparency.

Role
Security program lead / CISO capacity (engagement deliverable)
Timeframe
2026
Stack & Standards
NIST SP 800-53 · Security awareness training · Phishing simulation · Separation of duties

The Challenge

Where things stood

A mid-size enterprise was operating with a critically low security posture: successful phishing attacks, recurring insider theft, no log collection, and vulnerability assessments run only once every three years. High turnover and low morale were fueling both unintentional errors and intentional insider threats. Acting in a CISO capacity, I designed a program to raise the posture from the human layer up.

Successful phishing and social-engineering attacks from untrained staff.

Insider theft enabled by no separation of duties and no log visibility.

Stale, three-year vulnerability assessment cycle.

High turnover and low morale eroding institutional security knowledge.

The Approach

From analysis to a delivered solution

01

Assessed posture and human factors

Categorized the security posture and separated the drivers into human factors (unintentional vs. intentional threats) and organizational factors (data flow, work setting, readiness).

02

Wrote ten interlocking policies

Mandatory awareness training and quarterly phishing simulations, separation of duties with mandatory vacation, AES-256 encryption, IDPS, centralized SIEM log management, media access control, and monthly vulnerability management — each mapped to NIST 800-53 controls with real-world use cases.

03

Tailored the communication plan

Distinct messaging for leadership (business enablement, click-through-rate reduction) and non-technical staff (relatable, empowering habits) to drive comprehension and buy-in.

04

Shifted the culture

Moved the organization from a culture of fear to one of transparency, where reporting a mistake early lets the team contain a threat in minutes.

The Outcome

What it delivered

10

Interlocking security policies

NIST

800-53-aligned controls

Monthly

Vulnerability scanning cadence

Human

Firewall culture established

Security awareness training with quarterly phishing simulations.

Separation of duties + mandatory vacation to surface insider fraud.

Centralized SIEM log management and daily monitoring.

Stakeholder-specific communication and culture-change plan.

Stack & Standards

NIST SP 800-53Security awareness trainingPhishing simulationSeparation of dutiesIDPS / SIEMVulnerability managementInsider-threat controls

Anonymized engagement deliverable. Organization details generalized; program design is my own work.

Have a problem that looks like this?

I take security, network, and data problems from analysis to a delivered, defensible solution. Let's talk about yours.