Security Awareness
Building a Human-Risk Program
Training alone isn't enough. Here's the system that makes people your last line — not your only line.
Most organizations still treat phishing defense as an annual training video and a hope. In 25 years running LANStatus, I've watched that approach fail the same way every time: the training fades in a week, one convincing email lands, and a single click turns into a wire transfer or a breach-notification letter. Training alone was never a control. A human-risk program is — and building one is a system, not a slideshow.
Here's the framework we implement for regulated clients, and what actually makes each piece work.
1. Make the login phishing-resistant
The fastest way to shrink your attack surface is to make stolen passwords worthless. That means phishing-resistant MFA: number-matching prompts at minimum, FIDO2 security keys for admins and finance. Push-approval fatigue is a real failure mode — attackers spam prompts until someone taps "approve" at 6 a.m. Number matching and origin-bound keys close that door. Both NIST SP 800-63B and CISA now treat phishing-resistant methods as the standard, and Microsoft defaults to number matching for exactly this reason.
2. Prove your own email is real
Attackers impersonate your domain because they can. SPF, DKIM, and a DMARC policy set to reject stop look-alike mail from reaching your people and stop your brand from being spoofed at your customers. This is a weekend of work with outsized payoff — and it's the control most of the mid-market skips.
3. Make reporting the easy path
The Verizon DBIR keeps confirming what we see in the field: the human element drives most breaches, and the difference between an incident and a near-miss is often how fast someone speaks up. Give every employee one-click "Report Phish" in their mail client, respond to every report — even the false alarms — and enforce a genuine no-blame culture. The moment reporting feels like a confession, silence wins, and silence is the enemy. Pull a suspicious message early, no shame attached.
4. Simulate on a cadence, not once a year
Quarterly phishing simulations tuned to the lures your sector actually sees — BEC and gift-card fraud, vendor bank-change wire fraud, and in healthcare, PHI-harvesting portal lures — turn awareness into reflex. The goal isn't a "gotcha" click rate; it's a rising report rate over time. That's the number that predicts real-world resilience.
5. Rehearse the incident path
When someone does click, the clock starts. A written, rehearsed path — who's called, what's isolated, when counsel and your cyber-insurer are looped in — is the difference between a contained event and a regulatory notification. In healthcare and financial services, the notification and downtime costs dwarf the prevention spend. If your team can't say who they call in the first ten minutes, that's the gap to close first.
What this looks like in the first 90 days
- Days 1–30: enforce number-matching MFA, deploy FIDO2 keys to admins and finance, publish DMARC (start at
p=quarantine, move toreject). - Days 31–60: roll out one-click reporting, stand up the no-blame policy, run the first baseline simulation.
- Days 61–90: document and tabletop the incident path, brief leadership on the report-rate trend, set the quarterly cadence.
Why we can say this works
LANStatus has run infrastructure and security for 70+ healthcare organizations and 50+ financial and insurance firms across our 25 years — sectors where a single successful phish carries the highest regulatory and downtime cost. The pattern above is what separates the clients who absorb an attempted attack from the ones who spend a quarter cleaning one up.
Want to know your current exposure before you build the program? Quantify it with the Downtime Cost Calculator — or schedule a free lunch-and-learn and we'll walk your leadership team through the five pillars against your real environment.
Read our guidance on ransomware resilience in healthcare, identity as the new perimeter, and the AI failure playbook for how modern attacks chain phishing with automation and AI-assisted social engineering.
Learn more about LANStatus and our 25 years defending regulated infrastructure, or read more about Brian Diamond.
We'll run a free lunch-and-learn for your team and assess your human-risk posture — phishing-resistant MFA, email authentication, reporting culture, and incident readiness.
Schedule a free lunch-and-learn
