MANUFACTURING

CASE STUDY

A global manufacturer used a Human Risk Baseline to uncover knowledge, behavior, culture, and policy risk across its workforce.

1-3

hrm-engage-icon-1
Key Stats

National Insurance Company

Midsize — 1,200 employees

PaaS — Managed Phishing Services

 

The Challenge

How do you manage human risk across 50,000 employees when you don't know what they know, believe, or do?

For this global manufacturer, scale had made the workforce almost impossible to read. More than 50,000 employees operated across 50+ countries, with headquarters in Asia, Information Security and GRC leadership based in Europe, and teams working across an extraordinary range of languages, cultures, operating environments, and levels of digital maturity.

Security awareness training existed. What the organization did not have was evidence that it was working. Completion data could show that a course had been delivered, but not whether employees understood the policies behind it, recognized the risks that mattered to their roles, felt confident taking secure action, or worked in environments where good security behavior was actually expected and supported.

The questions were becoming more important than the training metrics. Did employees understand what secure behavior looked like? Were policies making sense in local contexts? Which regions had knowledge gaps, which had behavioral risk, and which had cultural or organizational conditions making secure action harder? Were people reporting concerns? Did they believe cybersecurity was relevant to them at all? Across a workforce this large and diverse, the organization did not need another completion report. It needed a defensible picture of human risk.


“For the first time, we could see where our human risk actually was — and why.”

 

The Approach

What can a Human Risk Baseline reveal that training data cannot?

Cybermaniacs deployed a Human Risk Baseline designed to measure the workforce from multiple dimensions rather than treating awareness as a single training outcome. The assessment examined knowledge, reported behavior, psychological factors, organizational culture, policy understanding and concordance, alongside Cybermaniacs' broader human risk measures.

Global accessibility was essential. The Baseline was translated into more than 23 languages so employees could respond in the language most likely to produce meaningful understanding rather than forcing the entire organization through an English-first assessment. A supporting communications campaign helped explain why the organization was asking the questions and why participation mattered.

More than 16,000 employees responded, representing markets across the global organization. The scale of the dataset changed what analysis was possible. Instead of producing one enterprise score, Cybermaniacs could segment the findings by geography, workforce group, function, risk factor, behavioral pattern, policy understanding, cultural condition, and other relevant organizational characteristics.

Patterns emerged that had never been visible in the organization's training data. Some populations understood the security requirement but were not consistently acting on it. Others showed gaps in foundational knowledge or policy comprehension. In some markets, behavioral norms and organizational conditions were influencing risk in ways that a global training completion percentage could never expose.

For the first time, the security team could distinguish between where risk existed and why it existed.


Midsize Use Case

The Results

What changes when human risk becomes visible by country, function, behavior, and culture?

The Baseline gave the CISO and GRC team an evidence base they had never previously had. Human risk could now be discussed by market, workforce population, behavioral factor, competency, and organizational condition rather than through a single global training metric.

Country-level segmentation brought regional leadership into the security conversation in a new way. Instead of asking local leaders to reinforce another annual compliance requirement, the security team could show them what the data said about their own workforce. Functional groups could see how social engineering, authentication, reporting behavior, policy understanding, and other human factors appeared in the context of their actual operating environment.

High-priority populations received deeper analysis, allowing the organization to identify specific human risk factors in areas with greater exposure and develop interventions around the conditions actually present rather than applying the same response everywhere.

The findings changed the standing of the program internally. The security awareness team received increased budget and an expanded remit, supported by evidence showing that human risk was broader than training delivery alone. The Baseline data continued to inform competency priorities, regional planning, leadership conversations, and program decisions throughout the following year.

The organization had moved from asking whether employees had completed security awareness training to understanding where its people-related exposure was concentrated, what was driving it, and what needed to change.

badge-icon

What Changed & Why It Matters

For a global organization, workforce size is not the hardest measurement problem. Diversity is. Fifty thousand employees operating across dozens of countries do not experience policy, technology, management expectations, social engineering, or security culture in exactly the same way. A single completion percentage can hide enormous differences underneath it.

A Human Risk Baseline makes those differences visible. By combining measures of knowledge, behavior, psychology, organizational culture, policy understanding, and other human risk factors, the organization gained evidence about not only who might be exposed, but why. That distinction made segmentation and targeted intervention possible.

More importantly, the data changed the conversation around the program. Human risk stopped being something the awareness team reported through course completions and became something regional leaders, GRC, Information Security, and the CISO could examine together as an enterprise risk issue. The Baseline did more than establish a starting score. It gave the organization a common evidence base for deciding what mattered next.

A note on client confidentiality

Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.

Schedule a Demo

We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.

Let's Chat