Introduction: The People, Process, Technology Framework

In Lessons 1.1 through 1.5, we established the foundational concepts of cybersecurity for financial institutions. We explored the threat landscape, the regulatory framework, cyber threat intelligence, risk assessment, and security frameworks and controls. However, technology alone is not sufficient for effective cybersecurity. The human element—people and processes—is equally critical.

Cyber Governance is the framework of policies, processes, and structures that guide and control cybersecurity activities. It answers critical questions such as:

  • “Who is responsible for cybersecurity?”

  • “What are the roles and responsibilities?”

  • “How are cybersecurity decisions made?”

  • “How is cybersecurity performance measured?”

The Human Element is the greatest cybersecurity risk factor. Employees can be the weakest link or the strongest defense. Human error is involved in over 80% of cyber incidents.

This lesson provides the complete framework for cyber governance and the human element in financial institutions. We derive the People, Process, Technology (PPT) framework: Security=People+Process+Technology. We formalize the Governance Structure: Board → Executive → CISO → Security Team → All Employees. We derive the Security Culture ScoreCculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.

We also derive the Human Risk ScoreHrisk=Eexposure×Vvulnerability×Iimpact, where Eexposure is the employee’s exposure to risk, Vvulnerability is their vulnerability to attacks, and Iimpact is the potential impact of a compromise.

By the end, you will have a complete understanding of cyber governance and the human element in financial institutions.


Learning Objectives

Upon completion of this lesson, you will be able to:

  1. Define the People, Process, Technology (PPT) framework: Security=People+Process+Technology.

  2. Formalize the Governance Structure: Board → Executive → CISO → Security Team → All Employees.

  3. Derive the Security Culture ScoreCculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.

  4. Derive the Human Risk ScoreHrisk=Eexposure×Vvulnerability×Iimpact.

  5. Apply the Security Awareness Training framework for financial institutions.

  6. Design a Security Culture Program for financial institutions.


Part 1: The People, Process, Technology (PPT) Framework

1.1 The Model

The PPT framework states that effective security requires three components:

Security=People+Process+Technology

1.2 The Three Components

 
 
Component Description Examples
People Employees, contractors, stakeholders Awareness, training, culture
Process Policies, procedures, workflows Incident response, risk management
Technology Tools, systems, controls Firewalls, encryption, SIEM

1.3 The PPT Framework Diagram

text
PPT Framework (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|                         ┌───────────────────┐                          |
|                         │      People       │                          |
|                         │  Awareness        │                          |
|                         │  Training         │                          |
|                         │  Culture          │                          |
|                         └────────┬──────────┘                          |
|                                  │                                     |
|                                  ▼                                     |
|                         ┌───────────────────┐                          |
|                         │     Process        │                          |
|                         │  Policies          │                          |
|                         │  Procedures        │                          |
|                         │  Workflows         │                          |
|                         └────────┬──────────┘                          |
|                                  │                                     |
|                                  ▼                                     |
|                         ┌───────────────────┐                          |
|                         │    Technology      │                          |
|                         │  Tools             │                          |
|                         │  Systems           │                          |
|                         │  Controls          │                          |
|                         └───────────────────┘                          |
|                                                                         |
|  Interaction:                                                          │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • People implement processes using technology.                │  │
|  │  • Processes guide people in using technology.                │  │
|  │  • Technology enables people to follow processes.            │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
└─────────────────────────────────────────────────────────────────────────┘

Part 2: The Governance Structure

2.1 The Model

The Governance Structure defines roles and responsibilities for cybersecurity:

Governance=Board→Executive→CISO→Security Team→All Employees

2.2 The Five Levels

 
 
Level Role Responsibilities
1. Board Ultimate accountability Oversight, risk appetite, resource allocation
2. Executive Strategic leadership Strategy, policy approval, reporting
3. CISO Operational leadership Program management, risk assessment, incident response
4. Security Team Technical execution Implementation, monitoring, response
5. All Employees Security awareness Compliance, vigilance, reporting

2.3 The Governance Structure Diagram

text
Governance Structure (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Level 1: Board of Directors                                          │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Ultimate accountability for cybersecurity                  │  │
|  │  • Approves risk appetite and resource allocation              │  │
|  │  • Reviews security reports                                    │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Level 2: Executive Team                                             │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Strategic leadership for cybersecurity                     │  │
|  │  • Approves security policies and strategies                   │  │
|  │  • Reports to the board                                        │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Level 3: CISO (Chief Information Security Officer)                 │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Operational leadership for cybersecurity                   │  │
|  │  • Manages the security program                                │  │
|  │  • Reports to the executive team                               │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Level 4: Security Team                                              │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Technical execution of security controls                   │  │
|  │  • Monitoring and incident response                            │  │
|  │  • Reports to the CISO                                         │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Level 5: All Employees                                              │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Security awareness and compliance                          │  │
|  │  • Vigilance and reporting                                    │  │
|  │  • First line of defense                                       │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
└─────────────────────────────────────────────────────────────────────────┘

Part 3: Security Culture

3.1 Definition

Security Culture is the set of shared beliefs, attitudes, and behaviors regarding cybersecurity:

Security Culture=Beliefs+Attitudes+Behaviors

3.2 The Security Culture Score

The Security Culture Score quantifies the maturity of security culture:

Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction

Where:

  • Aawareness is the Awareness Score (0-1)

  • Bbehavior is the Behavior Score (0-1)

  • Ssatisfaction is the Satisfaction Score (0-1)

  • α,β,γ are weights (typically α=0.4,β=0.3,γ=0.3)

3.3 Components

 
 
Component Description Key Indicators
Awareness Employees know the risks Training completion, quiz scores
Behavior Employees act securely Reporting incidents, following policies
Satisfaction Employees feel supported Survey responses, engagement metrics
text
Security Culture Score (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|  Awareness Score: 0.85                                              │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Training Completion: 0.90                                  │  │
|  │  • Quiz Scores: 0.80                                          │  │
|  │  • Knowledge Retention: 0.85                                  │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Behavior Score: 0.78                                               │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Incident Reporting: 0.75                                   │  │
|  │  • Policy Compliance: 0.80                                    │  │
|  │  • Security Vigilance: 0.78                                   │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Satisfaction Score: 0.82                                          │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Survey Responses: 0.85                                     │  │
|  │  • Engagement Metrics: 0.80                                   │  │
|  │  • Support Satisfaction: 0.82                                 │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Security Culture Score:                                              │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  C_culture = 0.4 * 0.85 + 0.3 * 0.78 + 0.3 * 0.82 = 0.82    │  │
|  │  Status: Good                                                  │  │
|  └─────────────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────────────┘

Part 4: The Human Risk Score

4.1 Definition

The Human Risk Score quantifies the risk posed by human factors:

Hrisk=Eexposure×Vvulnerability×Iimpact

Where:

  • Eexposure is the Employee Exposure Score (0-1)

  • Vvulnerability is the Vulnerability Score (0-1)

  • Iimpact is the Potential Impact Score (0-1)

4.2 Components

 
 
Component Description Key Indicators
Exposure Employee’s access to sensitive data Role, access level, data classification
Vulnerability Employee’s susceptibility to attacks Training, phishing susceptibility
Impact Potential damage from compromise Financial impact, regulatory impact

4.3 Interpretation

 
 
Score Risk Level Action
≥0.50 High Immediate intervention required
0.25−0.49 Medium Additional training and monitoring
<0.25 Low Acceptable risk
text
Human Risk Score (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|  Employee: John Doe (Senior Trader)                                   │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  Exposure Score: 0.85                                         │  │
|  │  • Role: High-access                                         │  │
|  │  • Data: Highly sensitive                                     │  │
|  │  • Access: Broad                                              │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Vulnerability Score: 0.60                                          │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Phishing Susceptibility: 0.65                              │  │
|  │  • Training Completion: 0.55                                  │  │
|  │  • Security Awareness: 0.60                                   │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Impact Score: 0.90                                                 │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Financial Impact: 0.90                                     │  │
|  │  • Regulatory Impact: 0.85                                    │  │
|  │  • Reputational Impact: 0.95                                  │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Human Risk Score:                                                   │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  H_risk = 0.85 × 0.60 × 0.90 = 0.46                         │  │
|  │  Status: Medium Risk (Additional training required)           │  │
|  └─────────────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────────────┘

Part 5: Security Awareness Training Framework

5.1 The Framework

The Security Awareness Training Framework consists of four stages:

Awareness Training=Assess→Educate→Reinforce→Measure

5.2 The Four Stages

 
 
Stage Description Key Activities
1. Assess Understand current awareness levels Baseline assessments, phishing simulations
2. Educate Provide training and awareness Online training, workshops, communications
3. Reinforce Sustain awareness Regular communications, reminders, refreshers
4. Measure Evaluate effectiveness Metrics, surveys, assessments

5.3 Key Training Topics

 
 
Topic Description Frequency
Phishing Awareness Recognizing and reporting phishing Quarterly
Password Security Strong passwords, MFA Annual
Social Engineering Recognizing manipulation Annual
Data Protection Handling sensitive data Annual
Incident Reporting When and how to report Annual
Remote Work Security Securing remote access Annual
Physical Security Securing physical assets Annual
text
Awareness Training Framework (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Stage 1: Assess                                                      │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Baseline Assessments                                       │  │
|  │  • Phishing Simulations                                       │  │
|  │  • Knowledge Surveys                                          │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Stage 2: Educate                                                    │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Online Training                                            │  │
|  │  • Workshops                                                  │  │
|  │  • Communications                                             │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Stage 3: Reinforce                                                  │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Regular Communications                                     │  │
|  │  • Reminders                                                  │  │
|  │  • Refresher Training                                         │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Stage 4: Measure                                                    │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Metrics                                                    │  │
|  │  • Surveys                                                    │  │
|  │  • Assessments                                                │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
└─────────────────────────────────────────────────────────────────────────┘

Summary and Bridge to Lesson 1.7

We have now completed the Cyber Governance and Human Element framework. You have learned:

  1. PPT Framework: Security=People+Process+Technology.

  2. Governance Structure: Board → Executive → CISO → Security Team → All Employees.

  3. Security Culture Score: Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.

  4. Human Risk Score: Hrisk=Eexposure×Vvulnerability×Iimpact.

  5. Awareness Training Framework: Assess → Educate → Reinforce → Measure.

In Lesson 1.7, we will explore Cybersecurity Metrics and Performance Measurement for Financial Institutions.