Soru

Zorluk: Çok zorSecurity Awareness Programs and Human Risk Management

Following a six-month human risk management initiative, an enterprise CISO observes that while employee click-through rates on simulated phishing emails dropped from 24% to 3%, the Security Operations Center (SOC) still experiences severe delays in receiving user reports during live spear-phishing campaigns. An audit reveals that employees frequently delete suspicious emails without utilizing the organization's automated phishing report button because they perceive reporting as time-consuming and non-essential. Which of the following security awareness program enhancements would be MOST effective to incentivize active threat reporting and improve the organization's Mean Time to Detect (MTTD)?

  1. Integrate positive reinforcement and gamified reporting metrics into performance reviews alongside automated just-in-time micro-learning feedback when emails are reported.Cevap
  2. B
    Increase the frequency of simulated phishing campaigns to a daily schedule and implement mandatory formal disciplinary actions for users who fail to report emails within ten minutes.
  3. C
    Reconfigure the Secure Email Gateway to strip all external hyperlinks and inbound file attachments to eliminate human risk at the perimeter boundary.
  4. D
    Deploy automated Endpoint Detection and Response agents to automatically isolate host devices whenever a user executes an unknown file attachment from email.

Cevap

Integrating positive reinforcement, gamification, and instant micro-learning feedback to build an active human threat reporting culture.
Combining positive reinforcement, gamified performance incentives, and instant feedback directly addresses user motivation and reduces reporting friction. This transforms employees into active 'human sensors', significantly increasing the volume and speed of user-submitted phishing reports and reducing the Mean Time to Detect (MTTD) live attacks.

Adım Adım Çözüm

1
Analyze the core problem statement
Identified that click rates improved (avoidance behavior), but threat reporting rates remain low due to lack of employee motivation and operational friction.
Security awareness programs must address both risk avoidance (not clicking) and active defense engagement (reporting threats).
2
Evaluate behavioral mitigation strategies within Human Risk Management frameworks
Positive reinforcement, gamified recognition, and low-friction reporting mechanisms effectively drive behavioral change and lower MTTD.
Punitive policies or excessive simulations cause fatigue and resistance, whereas positive recognition builds a strong security culture.
3
Differentiate human risk awareness controls from technical controls
Administrative policy and awareness incentive programs directly target human behavior, whereas perimeter blocking disrupts business without improving human risk posture.
The objective specifically asks to optimize user reporting behavior as part of a security awareness program.

Anahtar Kavram

Human Risk Management and Threat Reporting Incentivization
Bu soruyu puanla