Home/Risk coverage/Human risk, awareness and phishing
Proposition
Human risk, awareness and phishing
Most successful intrusions still begin with a person. Treat that as a risk to be measured and reduced, rather than a training course to be completed.
FALCONRY360 IN PRACTICE
See the operating layer behind the service.
The platform gives the client a current view of the work, not only an end-of-month report. Scope, owners, evidence and actions remain visible between service reviews.
The measure that matters
Completion rates tell you people clicked through a module. Nothing more.
Awareness programmes are usually reported as completion percentages, which measure participation rather than susceptibility. The platform reports a human risk position by individual, team, business unit and role, built from behaviour rather than attendance — and feeds it into the same risk register as every other exposure.
Programmes are delivered in Arabic and English, with content set in the working context of the market rather than translated from elsewhere.
What runs
- Phishing simulation
- Credential harvesting, attachment, link and reply-based lures, run on a schedule with difficulty calibrated to the population. Results feed behaviour scoring, not a leaderboard.
- Advanced lure types
- QR-code lures, voice and SMS pretexting scenarios, multi-factor fatigue simulation and business email compromise sequences aimed at finance and executive assistants — the patterns actually being used against organisations in this region.
- Role-based awareness
- Distinct pathways for executives, finance, developers, privileged administrators, customer-facing staff and OT operators. A developer secure-coding module and a board-level pathway are not the same programme.
- Just-in-time coaching
- A person who interacts with a simulated lure receives short, specific coaching at that moment, when it is most likely to change behaviour.
- Reporting behaviour
- Reporting rate and reporting speed are tracked alongside click rate. A workforce that reports quickly is worth more than one that clicks rarely and says nothing.
- Human risk scoring
- A composite score per person and per unit, drawn from simulation outcomes, reporting behaviour, policy acknowledgement, training currency, access privilege and data exposure.
- Culture measurement
- Periodic culture assessment and benchmarking, so the programme is judged on whether attitudes moved, not only on whether behaviour did.
- Regulatory training obligations
- Awareness and training requirements from the national cyber controls and the privacy regimes tracked as controls with evidence, so the obligation is satisfied and provable.
- Falconry Academy pathways
- Structured capability development for the security, privacy and technology risk functions themselves — certification pathways, practitioner development and CISO-level programmes.
How it connects
- Into the risk register. Human risk becomes a quantified contribution to loss scenarios in Anticipate, not a separate report.
- Into control evidence. Awareness and training controls in the national frameworks and ISO 27001 are evidenced automatically from programme data.
- Into board reporting. A human risk index reported alongside control health and exposure, with trend rather than a single quarter's number.
- Into incident response. Simulation scenarios and real incident patterns feed each other, so exercises reflect what is actually being attempted.