Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Human risk management for public sector teams: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Public sector organisations face phishing, business email compromise, credential theft and MFA fatigue as the human layer becomes the primary attack surface, according to Knowbe4. Fragmented tools and staffing shortages make resilience depend on unified human risk management, not isolated controls.

NHIMG editorial — based on content published by Knowbe4: Securing the Public Sector at Scale: How Unified Human Risk Management Drives Cyber Resilience

Questions worth separating out

Q: How should public sector teams reduce human-risk exposure without adding more tools?

A: Start by connecting email security, IAM and behavioural telemetry into one response workflow.

Q: Why do phishing and MFA fatigue still lead to major breaches?

A: Phishing and MFA fatigue work because they exploit trust in the authentication flow, not because the attacker has stronger technology.

Q: What breaks when human-risk signals stay split across separate security tools?

A: Investigations slow down because each tool sees only part of the story.

Practitioner guidance

  • Map human-risk telemetry to identity controls Correlate phishing, MFA fatigue, sign-in anomalies and helpdesk abuse with IAM and PAM events so high-risk accounts can be stepped up or restricted before misuse expands.
  • Unify email, identity and compliance operations Create one response path that joins email security, identity monitoring and audit reporting, especially for agencies handling citizen data or student records.
  • Prioritise privileged and high-access users Focus behavioural controls, training and step-up checks on accounts whose compromise would expose the widest operational blast radius, including administrators, finance users and service desk personnel.

What's in the full article

Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Practical guidance on operationalising Human Risk Management across agencies and schools
  • More detail on strengthening Microsoft 365 while reducing human-driven risk
  • The paper's own framing of why fragmented security tools slow response and create visibility gaps
  • The specific security and compliance outcomes the vendor associates with a unified human-centric approach

👉 Read Knowbe4's whitepaper on public sector human risk management and cyber resilience →

Human risk management for public sector teams: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Human risk management is becoming an identity governance problem, not just a security awareness problem. The article is right to centre the human layer, but the governance implication is broader than phishing training. When attackers rely on credential theft, MFA fatigue and business email compromise, the control challenge moves into authentication assurance, privileged access review and user behaviour telemetry. Practitioners should treat human risk as a measurable identity programme issue, not a soft-awareness initiative.

A question worth separating out:

Q: Who is accountable when a compromised identity system disrupts public services?

A: Accountability sits with the teams that own identity governance, incident response, and continuity planning together, because identity compromise crosses all three domains. Public sector frameworks such as Zero Trust and the NIST Cybersecurity Framework expect recovery and resilience to be part of the control design, not an afterthought.

👉 Read our full editorial: Human risk management is reshaping public sector cyber resilience



   
ReplyQuote
Share: