Adaptive, engaging cybersecurity learning that builds competency over time.
Managed simulations that reveal human risk and build resilience.
Always-on campaigns and content that keep security visible.
Custom films, courses, campaigns, events, and experiences.
Measure the human factors driving risk across your workforce.
Mature, operationalize, and scale your human risk program.
Prepare your workforce for safe, successful AI adoption at scale.
Prepare people, roles, workflows, and governance for AI agents.
See what makes our approach refreshingly different.
Meet the company behind the human risk mission.
Build better human risk solutions and better business together.
Questions, ideas, partnerships, or something else? Start here.
A 20,000-employee financial services firm needed to understand why risk was surfacing differently across regions, teams, and workflows.
Global Financial Company
Enterprise — 20k employees
Human Risk Baseline Service
For this 20,000-employee global financial services firm, human risk was becoming harder to understand at exactly the moment the organization needed greater visibility. Employees operated across three major regions in a highly distributed working environment, handling significant volumes of personally identifiable information, customer transactions, call-center activity, data processing, and complex operational workflows.
The organization had already experienced significant incidents and close calls. At the same time, new policies were being introduced, employees were adopting new AI use cases, and a major organizational redesign was changing how people worked, communicated, and made decisions. Each change created new opportunities for risk — but the existing awareness program could not explain where those risks were emerging or why.
Leadership needed to understand more than whether employees knew the rules. They wanted to know how risk was experienced across different cultures and working environments. Did people feel safe raising concerns? Were policies understood consistently? Did employees challenge risky decisions or defer to hierarchy? How did attitudes toward rules, change, communication, and authority influence security behavior?
The organization had global policies. What it did not have was a clear view of how those policies translated into human behavior across the enterprise.
“For the first time, we could see where our human risk actually was — and why.”
Cybermaniacs deployed a Human Risk Baseline designed to examine the workforce across multiple dimensions of human risk — including knowledge, behavior, psychology, organizational culture, policy understanding, and the conditions influencing whether people could act securely in practice.
Particular attention was given to factors conventional security awareness metrics rarely expose: risk transparency, respect for risk, change agility, rule understanding and tolerance, communication preferences, and power distance. These measures helped examine not simply what employees knew, but how organizational and cultural conditions shaped the way they responded when something felt wrong.
More than 5,000 employees participated across the firm's three major regions. The resulting dataset was segmented into meaningful cohorts and analyzed alongside functional business lines, data-handling responsibilities, third-party relationships, supply-chain exposure, and other characteristics influencing human risk.
The correlations surfaced patterns the organization had never been able to see. In some groups, risk was being transferred between teams because ownership assumptions were unclear. In others, employees understood that something was wrong but hesitated to speak up. High power-distance environments created different reporting dynamics from more direct cultures. Elsewhere, assumptions about policy, process, technology, or basic cybersecurity practices were creating gaps that traditional training results had masked.
Open-text analysis added another dimension. Employees did not simply answer questions — they described friction, uncertainty, concerns, and practical barriers that had rarely had a structured route back to the security team.
For the first time, the organization could see both the risk signals and the organizational conditions producing them.

The Baseline gave Information Security and GRC a far more detailed picture of human risk across the enterprise. Instead of treating the workforce as one global population, the organization could distinguish between different risk conditions by region, function, workforce cohort, data exposure, and operating environment. That changed how mitigation was designed.
Where reporting barriers were identified, the response focused on psychological safety, communication, escalation, and leadership behavior rather than simply delivering more awareness content. Where policy understanding was weak, teams could address the specific rules and assumptions causing confusion. Where functional groups faced distinct social-engineering, authentication, data-handling, or third-party risks, generic training was replaced with targeted campaigns grounded in the situations those employees actually encountered.
Business leaders were able to see their own risk picture rather than receiving an enterprise-wide awareness score that told them little about their teams. Security could explain not only where exposure existed, but which human and organizational factors were contributing to it.
The open-text findings were equally valuable. Employees had been carrying observations about processes, communication, controls, and working practices that had not previously reached the people capable of acting on them. The Baseline gave those signals somewhere to go.
The result was a more targeted engagement, training, and risk-mitigation strategy — built around what employees and business units actually needed rather than what a generic global program assumed they needed.
Human risk does not exist independently of organizational culture. Two employees can receive the same policy, complete the same training, and work with the same technology while operating under very different assumptions about authority, responsibility, communication, escalation, and acceptable risk. Those differences matter — particularly in global organizations.
The Human Risk Baseline allowed this organization to see where risk was not merely present, but where it was being hidden, transferred, tolerated, or prevented from surfacing. Cultural and organizational factors that had previously been invisible became measurable signals the security team could investigate and act upon.
Just as importantly, the organization created a structured way to listen. More than 5,000 employees were given the opportunity to explain how security, policy, process, and risk actually worked in their part of the business. That turned the Baseline from an assessment into something more valuable: an enterprise-wide source of evidence about the gap between how risk was designed to be managed and how work was really getting done.
Once that gap became visible, the organization could start fixing the right problems.
A note on client confidentiality
Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.
We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.
Let's Chat