KPMG's Human Risk Management program helps to drive cyber security acceleration by focusing on a major component of quantifiable culture change; a dynamic annual change program that enables you to address human risk and drive targeted cyber capability and influence initiatives targeted training and teachable moments – making your people the first and best line of defence.
Then, keep track of progress and tell your story of risk reduction with advanced data analytics and reporting.
Download our Cyber Security Action Month Toolkit
Build cyber awareness and strengthen organisational resilience with practical training, insights and resources designed to help your people stay cyber secure.
What is Human Risk Management (HRM)?
KPMG Human Risk Management focuses on helping organisations reduce their human-related cyber risk by turning awareness into a cyber culture with measurable behaviour change. Through targeted education, gamification, immersive and innovative training, behavioural insights and risk-driven interventions, HRM helps our clients strengthen their cyber resilience, build a security-conscious workplace culture and helps prepare organisations for emerging technologies and their risks.
From work plans and communication packs to immersive escape rooms and phishing simulations – our tiered model means you can choose a program to suit your needs, no matter where you are on the cyber security journey.
We work with you on the best way to deliver the program, either on existing channels or via a seamless dynamic platform.
Tailored cyber security training
Choose the program that's right for you
Accelerate and amplify your cyber maturity capability by leveraging our ready-to-use programs and modules.
KPMG Human Risk Management will bring cyber security to the forefront of your staff and stakeholder minds, helping you reduce your cyber risk and improve the cyber culture across your organisation.
With our ready-to-deploy offerings, KPMG Human Risk Management enables you to move away from traditional security training and awareness, to a proactive human risk management and cyber behaviour change culture.
Frequently asked questions
The questions to ask yourself are:
- Is your existing program effective?
- Can you measure change in user behaviours (not just phishing)?
- Can you show data driven return on investment from your cyber engagement, change and influence program?
- Are you currently using proven ways to accelerate the consolidation of learning?
We use leading technology and a multi-faceted approach to create lasting change in your organisation. Drawing on principles in change management, learning, neuroscience, communications and marketing – our program addresses your biggest risks and facilitates lasting behaviour change. The results are measurable and can be reported to demonstrate return on investment.
KPMG HRM’s Human Risk Index uses API integration to identify risky behaviours before they cause an incident. This data can be viewed 24/7 through a dashboard and can be broken down by staff role, geography and team – or you can view the human risk index score for the whole organisation.
Once a cluster of risky staff behaviours has been identified, KPMG HRM can deliver tailored and targeted training to your user group to educate them on safe cyber security behaviours. The Human Risk Index dashboard helps you measure, quantify, track and report the change in behaviour. You can share this data with your executives and the board to show return on investment.
We start with discovery and then deliver an annual work plan that is based on your organisational key risks, priorities in your cyber security strategy and level of maturity. Not all offerings may be appropriate and we take that into consideration when designing a program that is right for you.
Cyber escape rooms are a new and immersive way to drive cyber security capability uplift in a dynamic and fun way using gamification, team work and problem solving skills. This can be organised in a virtual or in-person setting.
A phishing simulation education program provides both enterprise-wide and targeted phishing campaigns. KPMG HRM will analyse the data, provide monthly reporting, and deploy training to users who are falling victim to phishing simulations. HRM also targets repeat clickers by strategically adjusting the approach. All training is highly targeted to address the specific risks of different user groups in your organisation, such as privileged access users.
KPMG HRM has been designed with flexibility and ease in mind. To remove the burden of delivery, HRM can be executed entirely by KPMG on your behalf. If you want to retain full control, it can be executed by your organisation and supported by KPMG.
KPMG HRM gives you access to pre-packaged content, plug and play training, behaviour assessment, human risk management analytics and gamified experiences like cyber escape rooms to provide you with a hit-the-ground-running capability you can leverage and benefit from immediately.
Accelerators establish an annual cyber influence, engagement and communication program at pace to ensure all of your stakeholders are being appropriately engaged in order to keep security front of mind and ensure all employees are taken on the journey.
Amplifiers is where the capability consolidation is amplified; targeted and powerful services to drive a specific capability and behaviour change – for example, human risk index, compliance training, escape room, phishing, etc.
KPMG HRM is not a training and awareness program – it is so much more. No matter your level of cyber security maturity, HRM offers you next generation capability for engaging, motivating and changing your staff behaviours when it comes to safe online practices. HRM goes beyond conventional training and awareness to create an annual cyber behaviour change program which is steeped in human risk management and utilises globally leading capability.
Get in touch
Dominika Zerbe-Anders
Partner, Cyber & Business Resilience | Women in Cyber Global Leader
KPMG Australia
It’s easy to get started
We can help you deliver a more strategic and cost-effective cyber security program based on best-in-class change management and learning fundamentals. Get in touch and we'll help you decide on the best approach based on your risk, maturity, and the needs of your organisation.