A Human Risk Management Discussion- Skill Sets & Tools To Achieve Cyber Fitness

A Human Risk Management Discussion- Skill Sets & Tools To Achieve Cyber Fitness

On 6 November 2025, ISACA SG Chapter’s SheLeadsTech Programme (ISACASG SLT) and KnowBe4 organised an inaugural women-in-tech round table discussion addressingtwo rarely discussed components in building Security Culture – the People and Process components that often befuddles practitioners who would rather focus on the technology aspect. This discussion aimed to cover the tools supporting these two pillars, and the soft skills required to leverage them. The round table comprised women GRC1 leaders representing various industries from financial institutions, professional firms, transportation, real estate and business owners. The conclusion is that “Human risk management is not an optional item but an essential overarching component of enterprise risk management”.

Does culture influence corporate risk taking?

Have you ever wondered about this question? That is, does culture directly or indirectly influence corporate risk taking? There are various dimensions of looking at this question. The baseline finding is that culture does impact risk taking (Rehbein, 2014).

We now know that somehow culture i influence risk taking. But, w what is security culture and what about it?

According to Laycock

According to Laycock, Petric & Roer, 2015, “security culture depicts the human-related security elements in organizational settings, and is defined by the Security Culture Framework (Roer et. al., 2013) as “the ideas, customs, and social behaviour of a particular people or society (i.e. employees in an organization) that allow them to be free from danger or threats.

Truth is, the ideas, customs and social behaviours of any tribe (company, family, friends, etc.) is highly influenced by what individuals see, hear, say, do, know, feel within the tribe, which are based on underlying cognitive biases. And these biases are often times counterintuitive to the desired cyber safe behaviours that we want.

To change and overcome those cognitive biases would not be easy for after all;

“Comfort is the most dangerous addiction” a quote not directly from a specific text but reflects Aldous Huxley2‘s ideas about how prioritizing comfort can lead to a passive and controlled society,where people would be controlled not by force, but by an abundance of pleasure and convenience that would make them apathetic to their own subjugation.

Do you agree to get uncomfortable? And why?

With the context setting of the discussion as outlined above, the attendees were asked of this question “Do you agree to get uncomfortable, and why?”. Everyone agreed that we have to get uncomfortable and get out of our complacency. A one-size fits all kind of security awareness training is never adequate to address the issues that people face from all levels.

To get uncomfortable, firstly, the provider has to recognise this challenge and willing to take on a different approach to deliver security awareness to employees from all levels. For instance, if your organisation comprises 60% blue-collar workers, blasting of emails and requesting them to complete their online training will not be effective. Many may not even have email accounts since their jobs do not require them to do so. Hence, there should be security trainers to personally conduct face-to-face training to this group of employees, demonstrating to them what does phishing mean and how doessuch threats come about i.e. lots of show-and-tell and physical interactions. On the other hand, whitecollar workers such as developers do not read emails much too. Hence, phishing emails tests do not work effectively on developers. The so-called “good results” simply is a false positive!

Another consideration is to implement a culture metric in the organisation and report it to the Board periodically. However, w when culture becomes a measurable item, it may land itself as another tick box that Board will rely on the Management to report. And stakeholders’ management strategy may sneak in to manage Board’s expectations and again painting another false positive situation.

A real-life example of a Japanese bank going through digitalisation transformation process reinforced that getting uncomfortable is really very challenging. This is especially so when its culture is so strong and unique that changing mindsets is near impossible. At that time when this encounter was experienced, its culture d did not support remote working arrangements, hiring of talents excluded digital savvy considerations and age group matters. All these led to the transformation effort almost a failure.

So, getting uncomfortable needs a purpose-fit method to breakthrough existing work culture and a courageous, patient and competent talent to champion the change. This is essential as this is the first step towards building a resilient workplace.

Not sure where to start? Try embracing CLARITY. Ask what is the outcome desired, d, what kind of efeffort required, and what timeframe is affordable.

Caroline Soo, VP Customer Success at KnowBe4 explained that CLARITY can be achieved w when you know your boundaries i.e.

  • Outcome: What is your risk tolerance? (Business Impact)
  • Efforts: Cultural Maturity Shifts & Maintenance (In Phases)
  • Timeframe: Realistic timeline for expectations management (Tie back to business needs)

And clarity can be obtained from deploying a Program Maturity Assessment 3(PMA) tool to understand your organisation’s security culture maturity level. KnowBe4 believes that when you understand where your baseline is, you can set targets t to meet your goals. The assessment is best taken by senior leadership or business leaders who has a birds eye view across the 10 categories covered.

The attendees were requested to complete the assessment for their own organisations and gave their opinions about the assessment outcome. Most of them commented that the assessment outcome was expected with the caveat that they might not be best placed to answer the leadership and psychological safety areas where they may be out of bound for security professionals.

Having said the above, organisations management’s priorities are on business performance and often in a dilemma as the ROI from the efforts and costs required to build a good security culture is often not conveyed appropriately. Hence, the PMA itself is not a magic pill if a more personalisedorganisational business impact is iterated.

How do you define security culture? What does it cover?

The attendees were asked to define what is security culture as understood by them. Nothing surprising to note that everyone understands security culture differently. The challenge now is that when everyone has different definitions of security culture, the measures treating it will be different across organisations.

Roer et. al. (2013)4 defines security culture of having seven dimensions i.e

  • Attitudes: The feelings and beliefs that employees have toward the security protocols and issues
  • Behaviours: The actions and activities of employees that have direct or indirect impact on the security of the organization.
  • Cognition: The employees’ understanding, knowledge and awareness of security issues and activities.
  • Communication: The quality of communication channels to discuss security-related events, promote sense of belonging, and provide support for security issues and incident reporting.
  • Compliance: The knowledge of written security policies and the extent that employees follow them.
  • Norms: The knowledge of and adherence to unwritten rules of conduct in the organization, i.e. how security related b behaviours are perceived by employees as normal and accepted or unusual and unaccepted.
  • Responsibilities: How employees perceive their role as a critical factor in sustaining or endangering the security of the organization.

Some attendees provided feedback that some people, regardless the number of times they have undergone training, will not learn and keep making the same mistakes. Research has shown that p people under stress and/or having undesirable KPI5s will repeat mistakes. KPIs drive behaviour. Unfit KPIs drive wrong behaviour, leading to potential weak security culture.

Conclusion

  • Moves beyond simple awareness,
  • To systematically identify, measure,
  • And mitigate humanderived risk
  • Through a continuous, data-driven process.

Human risk management is a journey and is essential when the workforce is getting mobile and globally interconnected. It is essential when technologicalevolution is fast-paced and m moving towards optimal digitalization is unavoidable. When technology is a business enabler, it also introduces digital risks into the organization. Human risk management is the ultimate answer to ensure enterprise risk management holistically.

Author’s notes: In addition to digital track human behaviour, another aspect of human risk management is through the organizational behaviour focus. For instance, employee engagement, job satisfaction and others contribute to human risk management too. This focus was not discussed at this forum.

Author: D Dr. J Jenny Tan (ISACASG SLT)T)

This discussion was led by Ms Caroline Soo, VP Customer Success, APJ, J, KnowBe4 and facilitated by Dr. Jenny Tan, Immediate Past President & SheLeadsTech SG Founder, ISACA SG.

Round-d-table Sponsor: KnowBe4 (h(https://www.knowbe4.com/about-us)

  • Cathy Huang
  • Cynthia Cheong
  • Janice Teo
  • Jemma Renshaw
  • Karen Tiong
  • Kusum Pinto
  • Liew Shu Xian
  • Lee Tun Leng
  • Margie Pagdanganan
  • Rachel Holden
  • Sabrina Loi
  • Wendy Lim

References

1 GRC: Governance, Risk & Compliance

2 Aldous Huxley (1894–1963) was born into a prominent English intellectual family and educated at Eton and Oxford. He is a writer and a philosopher. He is most famous for his dystopian novel, Brave New World (1932), which serves as a warning about technology and social control.

3 Free assessment tool from KnowBe4 (https://www.knowbe4.com/free-cybersecurity-tools/program-maturity-assessment)

4 Aimee Laycock, Gregor Petric and Kai Roer. The seven dimensions of security culture. 2015.

5 KPIs: Key Performance Indicators

Recent Posts