KeenSec Field Notes // Human Cyber Risk Library

Empirical human cyber risk.
Better questions. Stronger programs.

Practical perspectives on human cyber risk, evidence-based simulation measurement, explainable employee threat reporting, and adaptive micro-learning. Written for the security teams who must turn security awareness into an accountable operating program.

KeenSec Shield

From vanity click rates to
behavioral evidence.

Phishing click rates measure a single interaction. They leave out recipient coverage, automated mail scanners, reporting velocity, and whether learning changed subsequent decisions.

● Bot & Link Scanner Filtering ● Protective Reporting Velocity ● Comparable Reassessment Transfer
KEENSEC RESEARCH // MEASUREMENT TELEMETRY DECONSTRUCTION FIELD NOTE 02 PREVIEW
VANITY SIMULATION METRIC 4.2% Click Rate Superficial metric, conceals active risk
BOT SCANNER NOISE REMOVED 14.8% Scanner Hits Automated mail security crawlers de-noised
MEASUREMENT PIPELINE DECONSTRUCTION FIELD NOTE 02
{
  "total_delivered_population": 4100,
  "eligible_active_recipients": 3840,
  "excluded_out_of_office": 260,
  "automated_gateway_clicks": 568,
  "verified_human_interactions": 161,
  "protective_reports_submitted": 2465,
  "first_protective_report_latency": "42s",
  "credential_compromise_rate": "1.8%"
}

Research Pillars

Three foundational shifts
for human risk leaders.

Moving away from compliance checkboxes requires restructuring how organizations measure simulation interactions, how SOC teams triage reported threats, and how awareness builds lasting defensive habits.

Interactive Research Workbench

Search, filter, and inspect
the field notes library.

Filter by research domain or keyword to preview core theses, key takeaways, implementation checklists, and connected platform modules.

Interactive field note inspector with live category filtering.
Showing 5 of 5 field notes
FIELD NOTES DIRECTORY 5 GUIDES
FIELD NOTE INSPECTION CONSOLE HUMAN RISK // EDITORIAL GUIDE
01 / PRACTICAL GUIDE

From awareness activity to an evidence-led program.

A practical definition of human risk management and a connected operating model for security teams.

EXECUTIVE THESIS

“People are the weakest link” is a poor operating model. It says nothing about the situation, the control environment, or what a person needs to do differently. Security teams need specific, testable objectives that connect evidence with targeted interventions, followed by verification of behavioral change.

PRACTICAL IMPLEMENTATION PRINCIPLES
  • ✓ Define Decisions Narrowly: Focus on concrete actions, such as verifying supplier account changes through known channels.
  • ✓ Connect Existing Workflows: Link simulation tests, employee reports, and targeted micro-learning into one operating cycle.
  • ✓ Account for Context: Evaluate departmental exposure, scenario difficulty, and coverage before assigning meaning to trends.
  • ✓ Establish Review Cycles: Record baselines, planned interventions, and reassessment conditions for each objective.
OPERATIONAL CONNECTION HUMAN RISK INTELLIGENCE

Simulation Telemetry + Protective Reporting Velocity + Targeted Learning Retention = Defensible Human Risk Model

The Complete Collection

Field notes for security practitioners.

Every guide is grounded in empirical defense operations, clear metric definitions, and zero vendor hype.

5 field notes

MEASUREMENT // PRACTICAL GUIDE 8 MIN READ · NIST ALIGNED

What click rates leave out.

How to interpret phishing simulation results with coverage, automated activity, reporting behavior and comparable reassessment.

  • Distinguish automated security scanner detonations from genuine human interactions
  • Keep denominators visible: delivered population vs eligible vs active recipients
  • Measure protective reporting latency as an early warning defense capability
THREAT ANALYSIS // PRACTICAL GUIDE 7 MIN READ

What a useful reported-email verdict should explain.

A framework for reviewing sender identity, authentication, message intent, URLs, attachments, reputation and uncertainty.

  • Preserve the employee's original concern: business context often surfaces subtle fraud
  • Separate technical RFC-822 authentication (SPF/DKIM) from actual sender trustworthiness
  • Distinguish verified observations from inferences and make evidence gaps explicit
SIMULATION // PRACTICAL GUIDE 7 MIN READ

Different channels. The same pressure on human decisions.

Connect email phishing, quishing, smishing, vishing and messaging scenarios to meaningful learning objectives.

  • Understand distinct channel dynamics: QR codes move decisions to mobile surfaces; voice introduces real-time urgency
  • Maintain stable learning objectives across vectors, such as independent out-of-band verification
  • Distinguish delivery stages: message opened, link detonated, credentials submitted
AWARENESS // PRACTICAL GUIDE 6 MIN READ

Make awareness respond to the behavior you observe.

A practical model for targeted security awareness, meaningful assessment, multilingual learning and reassessment.

  • Target narrow, observable behaviors rather than assigning broad generic annual refresher courses
  • Deliver Just-in-Time micro-learning immediately at the moment of simulated exposure
  • Assess underlying reasoning and validate habit transfer under comparable reassessment conditions

Methodological Principles

Six standards for defensible
human-security operations.

Field-tested operational guidelines that separate evidence-led risk management from vanity compliance.

01

Empirical Behavioral Transfer

Reassess defensive behavior under comparable difficulty and novel pretexts. Testing identical templates measures superficial memorization rather than transferable resilience.

02

Denominator Transparency

Always disclose total delivered populations, active recipients, and excluded leaves alongside any interaction metric. A percentage rate without a clear denominator is uninterpretable.

03

Machine Scanner De-Noising

Isolate automated link crawlers, URL sandboxes, and mail gateway detonators from human interaction events. Failure to filter bot clicks distorts risk assessments by up to 300%.

04

Explainable Verdict Triage

Deconstruct reported email analysis into verifiable observations (headers, SPF/DKIM, routing) and distinct analytical inferences. Never conceal uncertainty behind an opaque verdict.

05

Just-in-Time Micro-Learning

Deliver focused, non-punitive guidance at the exact moment of exposure. Contextual lessons anchored to the specific attack cues produce significantly higher retention than disconnected annual training.

06

Sovereign Privacy & Integrity

Enforce zero model training on customer data, ephemeral in-memory processing, and sovereign human sign-off gates. Human risk telemetry must remain cryptographically isolated and auditable.

STANDARDS & FRAMEWORKS REFERENCE

NIST SP 800-50 Rev. 1 Alignment

The National Institute of Standards and Technology emphasizes in Special Publication 800-50 Rev. 1 (Building a Cybersecurity and Privacy Learning Program) that effective security programs must progress from passive awareness to measurable behavioral change and continuous program evaluation.

Let’s connect the dots

Turn security awareness into
a measurable operating program.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo