HomeSecurityCISO: Human-centric cybersecurity is gaining ground

CISO: Human-centric cybersecurity is gaining ground

The role of the CISO in businesses has changed significantly, from a cybersecurity specialist with a focus on technology to a manager of people and machines. These skills are particularly essential for mitigating the greatest cybersecurity. Cybercriminals are constantly using social engineering and therefore, human behavior to effectively penetrate businesses.

CISO

The usual response to this has been to increase security awareness , although this approach has not led to a significant reduction in risk over time. To ensure that employees not only gain knowledge but also implement secure behavior, CISOs must design effective training and exercises. They must promote a culture of security and mutual support within their organizations.

Technology and policies should support good security behavior, but it is even more important to take a human-centric perspective into account. Cybersecurity risks are only reduced when protective measures guide human behavior in the right direction. This is achieved by promoting positive actions, such as reporting incidents or behaviors that protect against external influences.

Cybersecurity must be aligned with values

The values ​​that support and guide a people-centered mindset are autonomy, equality, trust, and fairness. Employees expect open feedback, motivation, appreciation, and trust from their managers. CISOs should strive to empower people and set a good example. This is directly transferred to their employees.

Learning through practical scenarios

Employees can be lured by deepfake videos into participating in fake online meetings. CISOs should create a deepfake scenario and use it as a training tool to teach employees how to recognize and protect themselves from such threats – learning moments with practical application can be created in a similar way for other attack vectors and mediums. Integrated approaches address more than “just” email and phishing.

Balance between friction and flow

For well-coordinated cybersecurity, it is essential to use targeted friction points and distractions to enhance learning experiences. When CISOs start with human risk management programs, security is often seen as a secondary issue and as the responsibility of the IT department. The challenge is to make this a collective responsibility that is prioritized for all employees. Cybersecurity should not be an end in itself – the goal of risk management is not to minimize risks, but to maximize value while managing an acceptable level of risk.

CISO: Human-centric cybersecurity is gaining ground

CISOs must ensure that cybersecurity training, tools, and processes place as little burden on the user as possible, while delivering the maximum possible benefit.

How CISOs can create human risk management

A mature human resource management (HRM) program includes the following foundations:

Behavioral Risk Assessment: Security teams need data to understand which employees are clicking on phishing emails, using dangerous passwords, violating policies, or triggering security alerts. This data is aggregated into individual or departmental risk assessments, which can be tracked and trended over time.

Segmentation and risk prioritization: Once risks are identified, organizations should segment users based on their role, access level, and behavior. Segmentation helps security teams focus their efforts where they will have the greatest impact.

Targeted measures to reduce risk: Effective HRM requires more than general training. Instead, personalized measures are used to change behavior. By delivering the right message at the right time, HRM helps employees internalize good safety habits.

EDR

Continuous monitoring and feedback: A modern HRM program uses continuous monitoring and continuous feedback loops to adapt. Behavioral risk assessments should be recalculated regularly, with dashboards showing improvements or regressions over time. CISOs should also define KPIs, such as reduced click-through rates on phishing simulations, fewer policy violations or DLP alerts, or increased reports of suspicious emails. All of these metrics demonstrate value in tangible, business terms.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS