Adaptive, engaging cybersecurity learning that builds competency over time.
Managed simulations that reveal human risk and build resilience.
Always-on campaigns and content that keep security visible.
Custom films, courses, campaigns, events, and experiences.
Measure the human factors driving risk across your workforce.
Mature, operationalize, and scale your human risk program.
Prepare your workforce for safe, successful AI adoption at scale.
Prepare people, roles, workflows, and governance for AI agents.
See what makes our approach refreshingly different.
Meet the company behind the human risk mission.
Build better human risk solutions and better business together.
Questions, ideas, partnerships, or something else? Start here.
One Person, 32,000 Employees: How a Healthcare Company Built a Human Risk Program That Could Actually Scale
Healthcare Company
Enterprise — 32,00 employees
HRM — Strategic Program Advisory
One HRM practitioner. Approximately 2,000 office employees. Another 30,000 field-based caregivers and clinical staff operating across thousands of home and community sites — high-value social engineering targets, handling sensitive health data, working under pressure in environments where urgency is the norm. Some training existed. The intent was strong. The organization's brand, built around care, trust, and human connection, was an asset the security function genuinely wanted to build on, not work against.
But good intentions don't constitute a program. There was no baseline — so no ground truth on where risk actually sat across 32,000 people. No governance model to define who owned what. No strategy connecting the program to the organization's growth and cost objectives. And no measurement infrastructure to track whether anything was working.
The weight of it — on one person, in a regulated environment, with a workforce too large and too dispersed to reach manually — was the problem. She didn't need to work harder. She needed a program built to operate at that scale without requiring her to do everything.
"I knew the risk was there. What I didn't have was any way to see it clearly or a structure to start fixing it."
HRM Lead, Healthcare Company
Cybermaniacs started with the question that had to come first: what risk do we actually have, where is it, and how much? The Human Risk Baseline produced a quantified picture of exposure across the organization — by role, by workforce type, by behavioral risk pattern. For the first time, the practitioner had ground truth to work from. Priorities stopped being guesswork.
From there, Cybermaniacs embedded as a strategic advisory partner — meeting bi-weekly to systematically build the program infrastructure she needed to operate at scale. Every session delivered something concrete: frameworks, governance documents, roadmap tools, stakeholder decks, and analysis on the why behind every recommendation.
The advisory work was structured around three objective layers — business outcomes (growth and cost reduction), risk obligations (regulated industry compliance), and program maturity (capability development across the 8 domains) — so every decision was principled and every improvement was sequenced intelligently.
A structured Champions program extended her reach across the workforce, creating an activation layer she couldn't build or run alone. An operational cadence — clear cycles, defined priorities, repeatable processes — meant the program ran consistently without requiring her to reinvent the wheel each month.

The practitioner moved from reactive to strategic. The baseline gave her the risk picture. The advisory partnership gave her the frameworks, governance, and roadmap to act on it — built around real organizational objectives, not generic best practice. The Champions program gave her reach into the workforce she couldn't achieve directly. And the operational cadence meant she was running a program, not managing a task list.
Risk priorities were visible and sequenced. Decisions had a governance structure behind them. Progress was measurable and reportable. And she had something she hadn't had before: the language, the frameworks, and the strategic positioning to take human risk to leadership as a governed function — not a one-person effort held together by effort and goodwill.
| Before | After |
|---|---|
|
No baseline — risk picture unknown |
Quantified human risk exposure across 32,000 employees |
|
No strategy, governance, or roadmap |
Program architecture aligned to business, risk, and maturity objectives |
|
Reactive — urgent tasks displacing strategic work |
Bi-weekly advisory cadence: frameworks, roadmap, and priorities always current |
|
One person doing everything, unsustainably |
Structured program that multiplied her capacity without adding headcount |
The solo practitioner problem is real — and it is getting harder. As AI-powered threats raise the stakes and boards ask sharper questions, the person responsible for human risk needs to be operating strategically. That is difficult when the foundations are missing: no baseline, no strategy, no governance, no measurement, and no Champions network to extend the program's reach.
Human risk intelligence, mature Champions programs, and culture change that lasts all depend on those foundations. They cannot be built on awareness logic, spreadsheet governance, and one person's bandwidth.
What changed was the operating model. The practitioner did not need to work harder or add headcount. She needed the capability domains, cadence, and program infrastructure to operate beyond what one person could do alone. Strategic advisory support turned a one-person function into a structured HRM program with the architecture to scale, measure progress, and keep moving forward.
A note on client confidentiality
Human risk work can reveal sensitive information about an organization, its people and its security program. We protect that information. The stories on this site are drawn from real Cybermaniacs client engagements, with names and identifying details removed or changed. Where several organizations have faced substantially similar challenges, we may combine those experiences into a representative story while preserving the substance of the problem, our approach and the outcomes achieved.
We take time to understand your needs, explore the Cybermaniacs Experience, and align on business goals to strengthen your cyber culture.
Let's Chat