Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Human factor

Reducing human risk

The vast majority of attacks begin with an approach made to a person. Rather than blaming employees, we turn that fact into a measurable process: establish a baseline, train where the need is real, then check that the reflex has taken hold.

The challenge

A starting figure, then progress you can prove

Many organisations run awareness "just in case": one annual session, generic material, no measurement. As a result nobody knows whether vigilance is improving, or where to put the effort. Conversely, a phishing campaign run without teaching or framing creates mistrust and changes nothing lasting.

Our approach ties the two together: a realistic campaign provides a measured starting point (opening, clicking, credential entry and — above all — reporting), awareness is then calibrated on what the data shows, and a second campaign measures the ground covered.

Everything takes place within a strictly framed setting: objectives defined with you, employment law and privacy respected, results used in aggregate and never by name. The aim is to move a collective forward, not to catch individuals out.

What is at stake
  • Targeted phishing leading to credential theft
  • CEO fraud and payment diversion
  • Incidents not reported, and therefore detected too late
  • Generic awareness, with no measurable effect
  • Badly framed campaigns, damaging the climate of trust
Diagram

A cycle that measures, trains, then verifies

Cycle for reducing human risk 1Scoping &legal frame2Baselinecampaign3Measure& analyse4Targetedtraining5Newcampaign6ProgressprovenContinuous improvement
The campaign provides the starting point, awareness targets the real needs, the next campaign measures the progress.
Our approach

How we proceed

A gradual process, designed to bring teams along rather than to catch them out.

01

Scoping and legal framework

Definition of the objectives, the populations, the scenarios and the rules of engagement, together with HR and management. We set what will be measured, what will not, and how the results will be communicated.

02

Baseline campaign

Realistic, proportionate scenarios (targeted or broad phishing, QR codes, phone approaches where relevant), calibrated on your sector and your actual practices.

03

Measurement and analysis

Working through the indicators — opening, clicking, credential entry and reporting rate — by population and by scenario, to identify real rather than assumed needs.

04

Targeted awareness

Sessions adapted to each audience: users, exposed populations (management, finance, executive assistants), IT teams. The cases presented are the ones that worked on you, which makes the message concrete.

05

Fresh campaign and follow-up

A second campaign measures the progress and embeds the reporting reflex. The exercise can then be repeated periodically to hold the level over time.

Services involved

Several disciplines, a single point of contact

The same point of contact designs the campaign, the analysis and the training that follows — which is what makes measurement and remediation coherent.

Deliverables
  • Campaign scenarios agreed with you
  • Campaign report: opening, click and reporting rates
  • Analysis by population and prioritised recommendations
  • Awareness sessions adapted to each audience
  • Comparative measurement after the awareness work
Frequently asked questions

Frequently asked questions

Yes, provided it is properly framed. We define with you — and where applicable with HR and employee representatives — the objectives, the scope and the terms. Results are used in aggregate and never serve to sanction an individual.

A general prior notice ("security exercises will take place") is good practice: it preserves trust without distorting the measurement, since neither the date nor the scenarios are disclosed. We adapt the arrangement to your company culture.

The reporting rate, more than the click rate. Someone clicking is human and will always happen; what changes the outcome is that an incident is raised quickly, because that allows a reaction before the attacker uses the access.

Every six months or every year is enough in most cases, varying the scenarios. The aim is to keep a reflex alive, not to multiply exercises: too many campaigns close together tire the teams and lose their value.

What if you measured your human risk?

A first campaign is enough to know where you stand. We frame it with you, with respect for your teams.