{"id":15404,"date":"2026-09-21T14:46:50","date_gmt":"2026-09-21T09:16:50","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15404"},"modified":"2026-09-21T14:46:52","modified_gmt":"2026-09-21T09:16:52","slug":"human-centric-security-strategy","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/","title":{"rendered":"Human-Centric Security Strategy: Designing for the People You Actually Have"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A human-centric security strategy puts the individual at the centre of control design, rather than the technology or the threat. Gartner&#8217;s research explains why. More than 90% of employees who admitted taking unsafe actions at work already knew those actions raised risk. They did them anyway.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#What_a_Human-Centric_Security_Strategy_Means\" >What a Human-Centric Security Strategy Means<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#The_Number_That_Breaks_the_Awareness_Model\" >The Number That Breaks the Awareness Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Why_the_Awareness-Action_Gap_Is_a_Design_Problem\" >Why the Awareness-Action Gap Is a Design Problem<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Where_the_Friction_Actually_Sits\" >Where the Friction Actually Sits<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#What_Changes_When_You_Design_for_the_People_You_Have\" >What Changes When You Design for the People You Have<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#The_Shift_in_What_a_CISO_Is_For\" >The Shift in What a CISO Is For<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#A_Sequence_for_Building_the_Programme\" >A Sequence for Building the Programme<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Metrics_a_Board_Will_Accept\" >Metrics a Board Will Accept<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Time_One_Secure_Path_This_Week\" >Time One Secure Path This Week<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#What_is_a_human-centric_security_strategy\" >What is a human-centric security strategy?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Why_does_security_awareness_training_alone_not_change_behaviour\" >Why does security awareness training alone not change behaviour?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#What_is_the_awareness-action_gap\" >What is the awareness-action gap?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#How_do_you_measure_a_human-centric_security_programme\" >How do you measure a human-centric security programme?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#Is_human_risk_management_replacing_security_awareness_training\" >Is human risk management replacing security awareness training?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_a_Human-Centric_Security_Strategy_Means\"><\/span>What a Human-Centric Security Strategy Means<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The term gets used loosely, so it is worth pinning down. Human-centric security design models controls around the individual rather than around the technology, the threat, or the location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is a design principle, not a training programme. It asks a different question when a control is built. What will this cost the person using it forty times a day? And will they route around it?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gartner predicted in 2023 that through 2027, half of CISOs would formally adopt human-centric design practices to minimise operational friction and maximise control adoption. By 2030, it projected, 80% of enterprises would run a formally defined and staffed human risk management programme. In 2022 that figure was 20%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither prediction is about awareness content. Both are about how security is built. Related ground appears in <a href=\"https:\/\/threatcop.com\/blog\/human-risk-is-the-biggest-attack-surface\/\">why people remain the largest attack surface<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Number_That_Breaks_the_Awareness_Model\"><\/span>The Number That Breaks the Awareness Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One Gartner finding should reshape most security budgets, and it rarely gets quoted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of employees who admitted undertaking a range of unsecure actions during work activities, more than 90% knew those actions would increase risk to the organisation. They did them anyway.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sit with that. The gap is not a knowledge gap. Nine out of ten people who did the risky thing understood it was risky at the time they chose it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the instinctive response, more training, addresses a constraint that was not binding. You can raise knowledge from 90% to 95% and change almost nothing, because knowledge was never what stopped them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The situation stopped them, or failed to. A deadline. A broken process. A secure path that took eleven minutes when the insecure one took ten seconds. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/human-centric-security-model-meets-people-where-they-are\" rel=\"nofollow noopener\" target=\"_blank\">Dark Reading&#8217;s summary of the human-centric model<\/a> makes the same point about meeting people where they are.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_the_Awareness-Action_Gap_Is_a_Design_Problem\"><\/span>Why the Awareness-Action Gap Is a Design Problem<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The distance between what employees know and what they do has a name and, now, a number. It also has a cause that most programmes misdiagnose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Treat it as an education failure and you buy more content. Call it a motivation failure and you add consequences, which suppresses reporting. Diagnose it as a design failure, however, and you start asking why the secure option loses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third diagnosis fits the evidence. When someone who knows better still takes the shortcut, the shortcut was winning on something they were measured against, usually speed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That reframing has a practical edge. Security teams control the friction in their own processes far more directly than they control anyone&#8217;s diligence at 3 pm on a Friday.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_the_Friction_Actually_Sits\"><\/span>Where the Friction Actually Sits<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most organisations have never inventoried this, and the exercise is cheap.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Secure path<\/strong><\/th><th><strong>Common friction<\/strong><\/th><th><strong>What people do instead<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Reporting a suspicious email<\/td><td>Multiple clicks, no feedback, fear of wasting analyst time<\/td><td>Delete it and move on<\/td><\/tr><tr><td>Requesting access properly<\/td><td>Ticket queue measured in days<\/td><td>Borrow a colleague&#8217;s credentials<\/td><\/tr><tr><td>Using the approved file transfer<\/td><td>Size limits, external recipients blocked<\/td><td>Personal cloud drive<\/td><\/tr><tr><td>Verifying an unusual payment request<\/td><td>No defined callback procedure<\/td><td>Act on the email<\/td><\/tr><tr><td>Getting a tool approved<\/td><td>Procurement cycle longer than the project<\/td><td>Install it anyway<\/td><\/tr><tr><td>Reporting their own mistake<\/td><td>Unclear whether it triggers discipline<\/td><td>Say nothing and hope<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Scoring approaches for spotting these patterns appear in <a href=\"https:\/\/threatcop.com\/blog\/employee-risk\/\">why an employee risk score matters<\/a>. Every row is a place where the organisation made the safe option expensive. None is fixed by a module.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The last row deserves separate attention, because it is the one that compounds. An employee who stays quiet about a mistake removes the organisation&#8217;s cheapest source of early detection, and they do it for a rational reason.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Changes_When_You_Design_for_the_People_You_Have\"><\/span>What Changes When You Design for the People You Have<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Three shifts follow, and all are operational rather than cultural.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Measure friction alongside compliance. If you track how many people completed training, also track how long it takes to report a suspicious message and how many clicks it costs. The second number predicts behaviour better than the first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remove controls that no longer earn their place. Every control has an ongoing cost paid in attention, and controls accumulate faster than they get retired. An annual cull is a security measure, not an administrative one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Design the reporting path to be faster than the alternative. When reporting takes one click and ignoring takes zero, you have roughly parity. When reporting takes four clicks, you have chosen the outcome. Mechanics appear in <a href=\"https:\/\/threatcop.com\/blog\/what-is-incident-reporting-culture\/\">why employees stay silent about mistakes<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Shift_in_What_a_CISO_Is_For\"><\/span>The Shift in What a CISO Is For<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Gartner framed a related change: the CISO moving from control owner to risk-decision facilitator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reasoning is unavoidable. Gartner also expected three-quarters of employees to acquire, modify, or create technology beyond IT&#8217;s visibility by 2027, up from 41% in 2022. A function that owns every control cannot hold that line, because most technology decisions now happen outside it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Facilitating risk decisions means something specific. The business unit chooses, with the security consequences made legible, and the choice is recorded. Security stops being the department that says no and becomes the one that makes the trade-off visible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is a harder job, not an easier one. It requires the security team to quantify what a decision costs, which is the work most programmes skip.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_Sequence_for_Building_the_Programme\"><\/span>A Sequence for Building the Programme<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Order matters, because each step makes the next cheaper.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Baseline behaviour, not knowledge.<\/strong> Run multi-vector simulations and measure what people do, since knowledge surveys will tell you what the Gartner figure already did.<\/li>\n\n\n\n<li><strong>Inventory the friction<\/strong> in your six most-used secure paths, and time each one.<\/li>\n\n\n\n<li><strong>Fix the two worst<\/strong> before commissioning any new content. Reporting is usually one of them.<\/li>\n\n\n\n<li><strong>Make disclosure explicitly safe<\/strong>, in writing, and demonstrate it once visibly.<\/li>\n\n\n\n<li><strong>Target training at the roles the baseline surfaced<\/strong>, rather than the whole workforce.<\/li>\n\n\n\n<li><strong>Retire controls<\/strong> that generate friction without proportionate risk reduction.<\/li>\n\n\n\n<li><strong>Re-baseline<\/strong> and compare, because the only honest measure of the programme is whether behaviour moved.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Step 3 is the one that gets skipped, and skipping it means the training competes against the same broken process that produced the behaviour.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TSAT covers step 1, scoring exposure per employee across email, voice, SMS, and QR vectors. The population you train is then the population the evidence names. Measurement approaches sit in <a href=\"https:\/\/threatcop.com\/blog\/how-do-phishing-simulations-contribute-to-enterprise-security\/\">what simulation results actually tell you<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Metrics_a_Board_Will_Accept\"><\/span>Metrics a Board Will Accept<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Completion rate describes administration. These describe the strategy.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Time and clicks to report<\/strong> a suspicious message, measured rather than assumed<\/li>\n\n\n\n<li><strong>Reporting rate<\/strong>, trending across quarters, including self-reported mistakes<\/li>\n\n\n\n<li><strong>Exposure score distribution<\/strong>, watching whether the high-risk tail shrinks<\/li>\n\n\n\n<li><strong>Friction backlog<\/strong>, meaning secure paths identified as slower than their insecure alternative<\/li>\n\n\n\n<li><strong>Controls retired per year<\/strong>, as a check that the estate is being pruned<\/li>\n\n\n\n<li><strong>Time from finding to intervention<\/strong>, which shows whether the loop closes<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The fourth is unusual and worth adopting. A friction backlog makes visible the work that human-centric design actually consists of, and it gives a board something to fund that is not another content library.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Time_One_Secure_Path_This_Week\"><\/span>Time One Secure Path This Week<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pick the process you most want employees to follow, and time it end to end as an ordinary employee experiences it. Count the clicks. Then time the insecure alternative.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the second is faster, you have found the reason your training is not landing, and no amount of additional content will close that gap.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fix that one path first. Then <a href=\"https:\/\/threatcop.com\/threatcop-security-awareness-training\">train the population your measurements name<\/a> rather than the whole workforce, because targeting only works once the secure route is worth taking.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-571f334fae25\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-d8f29caf1ca0\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-4fae25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-4fae25'\n\t\t\t\t\t\t><span class=\"ez-toc-section\" id=\"What_is_a_human-centric_security_strategy\"><\/span>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is a human-centric security strategy?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-4fae25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">A human-centric security strategy designs controls around the individual rather than around the technology, threat, or location, with the aim of minimising operational friction and maximising control adoption. Gartner predicted in 2023 that through 2027, 50% of CISOs would formally adopt these practices. It is a design approach rather than a training programme.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-10b64fe03b9c\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-4fae25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-4fae25'\n\t\t\t\t\t\t><span class=\"ez-toc-section\" id=\"Why_does_security_awareness_training_alone_not_change_behaviour\"><\/span>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhy does security awareness training alone not change behaviour?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-4fae25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Because knowledge is usually not the binding constraint. Gartner research found that more than 90% of employees who admitted taking unsecure actions at work knew those actions increased organisational risk and took them anyway. Where people already know and still choose the shortcut, additional content addresses a gap that was not causing the behaviour.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-d421d2f2cece\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-4fae25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-4fae25'\n\t\t\t\t\t\t><span class=\"ez-toc-section\" id=\"What_is_the_awareness-action_gap\"><\/span>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is the awareness-action gap?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-4fae25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">The awareness-action gap is the distance between what employees know they should do and what they actually do under time pressure. Evidence suggests it is primarily a design problem: the secure path costs more time or effort than the insecure one, so people route around it. Reducing that cost changes behaviour more reliably than raising awareness further.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-c73d9e150851\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-4fae25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-4fae25'\n\t\t\t\t\t\t><span class=\"ez-toc-section\" id=\"How_do_you_measure_a_human-centric_security_programme\"><\/span>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow do you measure a human-centric security programme?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-4fae25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Measure behaviour and friction rather than completion. Useful metrics include time and clicks required to report a suspicious message, and reporting rate including self-reported mistakes. Track exposure score distribution across the workforce too. Add the backlog of secure paths slower than their insecure alternatives, and controls retired per year.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-51aa337ff9ca\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-4fae25\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-4fae25'\n\t\t\t\t\t\t><span class=\"ez-toc-section\" id=\"Is_human_risk_management_replacing_security_awareness_training\"><\/span>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tIs human risk management replacing security awareness training?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-4fae25'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Human risk management absorbs it. Training remains one component, alongside behavioural measurement, friction reduction, reporting design, and control retirement. Gartner projected that by 2030, 80% of enterprises would have a formally defined and staffed human risk management programme, up from 20% in 2022, which implies a function rather than a course.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.<\/p>\n","protected":false},"author":15,"featured_media":15407,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[329],"tags":[],"class_list":["post-15404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-human-risk-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Human-Centric Security Strategy: Design for Real People<\/title>\n<meta name=\"description\" content=\"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Human-Centric Security Strategy: Design for Real People\" \/>\n<meta property=\"og:description\" content=\"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-21T09:16:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T09:16:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nikunj Rakesh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nikunj Rakesh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/\"},\"author\":{\"name\":\"Nikunj Rakesh\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\"},\"headline\":\"Human-Centric Security Strategy: Designing for the People You Actually Have\",\"datePublished\":\"2026-09-21T09:16:50+00:00\",\"dateModified\":\"2026-09-21T09:16:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/\"},\"wordCount\":1552,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Human-Centric-Security-Strategy-blog-banner.png\",\"articleSection\":[\"Human Risk Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/\",\"name\":\"Human-Centric Security Strategy: Design for Real People\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Human-Centric-Security-Strategy-blog-banner.png\",\"datePublished\":\"2026-09-21T09:16:50+00:00\",\"dateModified\":\"2026-09-21T09:16:52+00:00\",\"description\":\"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Human-Centric-Security-Strategy-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Human-Centric-Security-Strategy-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Human-Centric Security Strategy, Designing for Real People, over an abstract stacked bar graphic on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/human-centric-security-strategy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Human-Centric Security Strategy: Designing for the People You Actually Have\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\",\"name\":\"Nikunj Rakesh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"caption\":\"Nikunj Rakesh\"},\"description\":\"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nikunj-rakesh-579a87129\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Human-Centric Security Strategy: Design for Real People","description":"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/","og_locale":"en_US","og_type":"article","og_title":"Human-Centric Security Strategy: Design for Real People","og_description":"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.","og_url":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-21T09:16:50+00:00","article_modified_time":"2026-09-21T09:16:52+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png","type":"image\/png"}],"author":"Nikunj Rakesh","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Nikunj Rakesh","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/"},"author":{"name":"Nikunj Rakesh","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db"},"headline":"Human-Centric Security Strategy: Designing for the People You Actually Have","datePublished":"2026-09-21T09:16:50+00:00","dateModified":"2026-09-21T09:16:52+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/"},"wordCount":1552,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png","articleSection":["Human Risk Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/","url":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/","name":"Human-Centric Security Strategy: Design for Real People","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png","datePublished":"2026-09-21T09:16:50+00:00","dateModified":"2026-09-21T09:16:52+00:00","description":"Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Human-Centric-Security-Strategy-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Human-Centric Security Strategy, Designing for Real People, over an abstract stacked bar graphic on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/human-centric-security-strategy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Human-Centric Security Strategy: Designing for the People You Actually Have"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db","name":"Nikunj Rakesh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","url":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","caption":"Nikunj Rakesh"},"description":"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.","sameAs":["https:\/\/threatcop.com\/","https:\/\/www.linkedin.com\/in\/nikunj-rakesh-579a87129"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15404"}],"version-history":[{"count":1,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15404\/revisions"}],"predecessor-version":[{"id":15411,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15404\/revisions\/15411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15407"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}