Introduction: The People, Process, Technology Framework
In Lessons 1.1 through 1.5, we established the foundational concepts of cybersecurity for financial institutions. We explored the threat landscape, the regulatory framework, cyber threat intelligence, risk assessment, and security frameworks and controls. However, technology alone is not sufficient for effective cybersecurity. The human element—people and processes—is equally critical.
Cyber Governance is the framework of policies, processes, and structures that guide and control cybersecurity activities. It answers critical questions such as:
-
“Who is responsible for cybersecurity?”
-
“What are the roles and responsibilities?”
-
“How are cybersecurity decisions made?”
-
“How is cybersecurity performance measured?”
The Human Element is the greatest cybersecurity risk factor. Employees can be the weakest link or the strongest defense. Human error is involved in over 80% of cyber incidents.
This lesson provides the complete framework for cyber governance and the human element in financial institutions. We derive the People, Process, Technology (PPT) framework: Security=People+Process+Technology. We formalize the Governance Structure: Board → Executive → CISO → Security Team → All Employees. We derive the Security Culture Score: Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.
We also derive the Human Risk Score: Hrisk=Eexposure×Vvulnerability×Iimpact, where Eexposure is the employee’s exposure to risk, Vvulnerability is their vulnerability to attacks, and Iimpact is the potential impact of a compromise.
By the end, you will have a complete understanding of cyber governance and the human element in financial institutions.
Learning Objectives
Upon completion of this lesson, you will be able to:
-
Define the People, Process, Technology (PPT) framework: Security=People+Process+Technology.
-
Formalize the Governance Structure: Board → Executive → CISO → Security Team → All Employees.
-
Derive the Security Culture Score: Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.
-
Derive the Human Risk Score: Hrisk=Eexposure×Vvulnerability×Iimpact.
-
Apply the Security Awareness Training framework for financial institutions.
-
Design a Security Culture Program for financial institutions.
Part 1: The People, Process, Technology (PPT) Framework
1.1 The Model
The PPT framework states that effective security requires three components:
Security=People+Process+Technology
1.2 The Three Components
| Component | Description | Examples |
|---|---|---|
| People | Employees, contractors, stakeholders | Awareness, training, culture |
| Process | Policies, procedures, workflows | Incident response, risk management |
| Technology | Tools, systems, controls | Firewalls, encryption, SIEM |
1.3 The PPT Framework Diagram
PPT Framework (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | ┌───────────────────┐ | | │ People │ | | │ Awareness │ | | │ Training │ | | │ Culture │ | | └────────┬──────────┘ | | │ | | ▼ | | ┌───────────────────┐ | | │ Process │ | | │ Policies │ | | │ Procedures │ | | │ Workflows │ | | └────────┬──────────┘ | | │ | | ▼ | | ┌───────────────────┐ | | │ Technology │ | | │ Tools │ | | │ Systems │ | | │ Controls │ | | └───────────────────┘ | | | | Interaction: │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • People implement processes using technology. │ │ | │ • Processes guide people in using technology. │ │ | │ • Technology enables people to follow processes. │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | └─────────────────────────────────────────────────────────────────────────┘
Part 2: The Governance Structure
2.1 The Model
The Governance Structure defines roles and responsibilities for cybersecurity:
Governance=Board→Executive→CISO→Security Team→All Employees
2.2 The Five Levels
| Level | Role | Responsibilities |
|---|---|---|
| 1. Board | Ultimate accountability | Oversight, risk appetite, resource allocation |
| 2. Executive | Strategic leadership | Strategy, policy approval, reporting |
| 3. CISO | Operational leadership | Program management, risk assessment, incident response |
| 4. Security Team | Technical execution | Implementation, monitoring, response |
| 5. All Employees | Security awareness | Compliance, vigilance, reporting |
2.3 The Governance Structure Diagram
Governance Structure (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Level 1: Board of Directors │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Ultimate accountability for cybersecurity │ │ | │ • Approves risk appetite and resource allocation │ │ | │ • Reviews security reports │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Level 2: Executive Team │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Strategic leadership for cybersecurity │ │ | │ • Approves security policies and strategies │ │ | │ • Reports to the board │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Level 3: CISO (Chief Information Security Officer) │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Operational leadership for cybersecurity │ │ | │ • Manages the security program │ │ | │ • Reports to the executive team │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Level 4: Security Team │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Technical execution of security controls │ │ | │ • Monitoring and incident response │ │ | │ • Reports to the CISO │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Level 5: All Employees │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Security awareness and compliance │ │ | │ • Vigilance and reporting │ │ | │ • First line of defense │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | └─────────────────────────────────────────────────────────────────────────┘
Part 3: Security Culture
3.1 Definition
Security Culture is the set of shared beliefs, attitudes, and behaviors regarding cybersecurity:
Security Culture=Beliefs+Attitudes+Behaviors
3.2 The Security Culture Score
The Security Culture Score quantifies the maturity of security culture:
Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction
Where:
-
Aawareness is the Awareness Score (0-1)
-
Bbehavior is the Behavior Score (0-1)
-
Ssatisfaction is the Satisfaction Score (0-1)
-
α,β,γ are weights (typically α=0.4,β=0.3,γ=0.3)
3.3 Components
| Component | Description | Key Indicators |
|---|---|---|
| Awareness | Employees know the risks | Training completion, quiz scores |
| Behavior | Employees act securely | Reporting incidents, following policies |
| Satisfaction | Employees feel supported | Survey responses, engagement metrics |
Security Culture Score (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | Awareness Score: 0.85 │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Training Completion: 0.90 │ │ | │ • Quiz Scores: 0.80 │ │ | │ • Knowledge Retention: 0.85 │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Behavior Score: 0.78 │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Incident Reporting: 0.75 │ │ | │ • Policy Compliance: 0.80 │ │ | │ • Security Vigilance: 0.78 │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Satisfaction Score: 0.82 │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Survey Responses: 0.85 │ │ | │ • Engagement Metrics: 0.80 │ │ | │ • Support Satisfaction: 0.82 │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Security Culture Score: │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ C_culture = 0.4 * 0.85 + 0.3 * 0.78 + 0.3 * 0.82 = 0.82 │ │ | │ Status: Good │ │ | └─────────────────────────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────────────────────────────┘
Part 4: The Human Risk Score
4.1 Definition
The Human Risk Score quantifies the risk posed by human factors:
Hrisk=Eexposure×Vvulnerability×Iimpact
Where:
-
Eexposure is the Employee Exposure Score (0-1)
-
Vvulnerability is the Vulnerability Score (0-1)
-
Iimpact is the Potential Impact Score (0-1)
4.2 Components
| Component | Description | Key Indicators |
|---|---|---|
| Exposure | Employee’s access to sensitive data | Role, access level, data classification |
| Vulnerability | Employee’s susceptibility to attacks | Training, phishing susceptibility |
| Impact | Potential damage from compromise | Financial impact, regulatory impact |
4.3 Interpretation
| Score | Risk Level | Action |
|---|---|---|
| ≥0.50 | High | Immediate intervention required |
| 0.25−0.49 | Medium | Additional training and monitoring |
| <0.25 | Low | Acceptable risk |
Human Risk Score (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | Employee: John Doe (Senior Trader) │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ Exposure Score: 0.85 │ │ | │ • Role: High-access │ │ | │ • Data: Highly sensitive │ │ | │ • Access: Broad │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Vulnerability Score: 0.60 │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Phishing Susceptibility: 0.65 │ │ | │ • Training Completion: 0.55 │ │ | │ • Security Awareness: 0.60 │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Impact Score: 0.90 │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Financial Impact: 0.90 │ │ | │ • Regulatory Impact: 0.85 │ │ | │ • Reputational Impact: 0.95 │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Human Risk Score: │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ H_risk = 0.85 × 0.60 × 0.90 = 0.46 │ │ | │ Status: Medium Risk (Additional training required) │ │ | └─────────────────────────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────────────────────────────┘
Part 5: Security Awareness Training Framework
5.1 The Framework
The Security Awareness Training Framework consists of four stages:
Awareness Training=Assess→Educate→Reinforce→Measure
5.2 The Four Stages
| Stage | Description | Key Activities |
|---|---|---|
| 1. Assess | Understand current awareness levels | Baseline assessments, phishing simulations |
| 2. Educate | Provide training and awareness | Online training, workshops, communications |
| 3. Reinforce | Sustain awareness | Regular communications, reminders, refreshers |
| 4. Measure | Evaluate effectiveness | Metrics, surveys, assessments |
5.3 Key Training Topics
| Topic | Description | Frequency |
|---|---|---|
| Phishing Awareness | Recognizing and reporting phishing | Quarterly |
| Password Security | Strong passwords, MFA | Annual |
| Social Engineering | Recognizing manipulation | Annual |
| Data Protection | Handling sensitive data | Annual |
| Incident Reporting | When and how to report | Annual |
| Remote Work Security | Securing remote access | Annual |
| Physical Security | Securing physical assets | Annual |
Awareness Training Framework (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Stage 1: Assess │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Baseline Assessments │ │ | │ • Phishing Simulations │ │ | │ • Knowledge Surveys │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Stage 2: Educate │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Online Training │ │ | │ • Workshops │ │ | │ • Communications │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Stage 3: Reinforce │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Regular Communications │ │ | │ • Reminders │ │ | │ • Refresher Training │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Stage 4: Measure │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Metrics │ │ | │ • Surveys │ │ | │ • Assessments │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | └─────────────────────────────────────────────────────────────────────────┘
Summary and Bridge to Lesson 1.7
We have now completed the Cyber Governance and Human Element framework. You have learned:
-
PPT Framework: Security=People+Process+Technology.
-
Governance Structure: Board → Executive → CISO → Security Team → All Employees.
-
Security Culture Score: Cculture=α⋅Aawareness+β⋅Bbehavior+γ⋅Ssatisfaction.
-
Human Risk Score: Hrisk=Eexposure×Vvulnerability×Iimpact.
-
Awareness Training Framework: Assess → Educate → Reinforce → Measure.
In Lesson 1.7, we will explore Cybersecurity Metrics and Performance Measurement for Financial Institutions.