Cybersecurity / Human Risk Assessment

Human Risk Assessment for Malaysian Organisations

Your technical controls are measured, tested and reported on every month. The people using them usually are not. A human risk assessment gives you a defensible score for employee cyber risk, broken down by department, role and behaviour, plus a roadmap that says exactly what to fix first.

A single organisational risk score, and the workings behind it Department, role and seniority benchmarking Twelve-month prioritised improvement roadmap
Overview

A measured view of the risk your workforce carries

What it is

A human risk assessment is a structured review of how your employees actually behave around information, systems and access, rather than how your policies say they should. It combines several evidence sources into a single picture: a knowledge and attitude survey across the workforce, observed behaviour from simulated attacks, access and privilege data from your systems, and structured interviews with the departments that handle the most sensitive information.

Those inputs produce a human risk score for the organisation, and the same score broken down by department, location, role type and seniority. Alongside the score sits the reasoning, so you can see whether a high score is being driven by weak knowledge, poor process, excessive access, unrealistic workload, or simply nobody having told people what good looks like.

The assessment runs over four to six weeks and is deliberately non-invasive. We do not read employee email, monitor keystrokes or track individuals. Reporting is aggregated to group level, which keeps the exercise proportionate under the PDPA and keeps staff cooperating with it.

Why organisations need it

Most organisations can tell you their patch compliance percentage to one decimal place and have no idea whether their finance team would wire money on the strength of a WhatsApp message from someone claiming to be the managing director. That asymmetry is where the losses come from.

Boards and audit committees are increasingly asking for human risk to be reported the same way as any other risk category: quantified, trended, owned and mitigated. Under the amended PDPA, an organisation that suffers a personal data breach has to notify the Commissioner and, in serious cases, the affected individuals. The question that follows is always whether the organisation had taken reasonable steps. A documented human risk assessment is a direct answer to that question.

There is also a budget argument. Human risk assessment usually shows that the workforce is not uniformly risky. Once you know which three departments carry most of the exposure, you can spend intensively where it matters rather than thinly everywhere.

Key features

What the assessment covers

Six evidence streams feed the score. Each one is weighted, documented and repeatable, so a reassessment twelve months later is genuinely comparable.

Employee cyber risk assessment

A structured survey across the workforce covering password practice, device handling, data sharing habits, use of personal cloud accounts, remote working patterns and confidence in recognising an attack. Short enough that people finish it, long enough to be meaningful.

Behavioural analysis

What people do, not what they say they do. We correlate survey responses against observed behaviour from phishing simulation results and, where available, from your existing security tooling. The gap between stated confidence and actual behaviour is often the single most useful finding.

Human risk scoring

A composite score built from knowledge, behaviour, access sensitivity and exposure. Each component is visible, so nobody has to take the headline number on trust, and you can see which lever moves it.

Department benchmarking

Scores are compared across departments, branches, seniority bands and tenure groups, and set against anonymised context from organisations of similar size and sector. Managers respond very differently to a number when they can see where they sit relative to their peers.

Access and privilege review

Risk is behaviour multiplied by access. We map which roles can reach personal data, financial systems and privileged accounts, so a moderately risky behaviour in a highly privileged role is scored as the serious issue it is.

Improvement roadmap

The assessment ends with a sequenced twelve-month plan: what to do in the first ninety days, what follows, who owns each item, and the expected effect on the score. Not a list of good ideas, a plan with dates.

Benefits

What the business gets out of it

The assessment turns an uncomfortable unknown into a managed risk with an owner, a number and a direction of travel.

Human risk becomes reportable alongside every other risk

A single score with a documented method means human risk can sit on the risk register and in board papers next to credit, operational and regulatory risk, instead of being a topic nobody knows how to quantify.

You stop spending awareness budget evenly

When the assessment shows procurement and accounts payable carrying three times the risk of engineering, the training plan and the budget can reflect that instead of treating all departments the same.

You find the process problems, not just the people problems

A high score in one team often turns out to be a broken approval workflow or an impossible turnaround expectation rather than careless staff. Those findings are usually the cheapest and fastest to fix.

Evidence for regulators, auditors and clients

A dated, methodical assessment demonstrates that the organisation identified and acted on human risk. That is exactly the evidence sought during a Commissioner enquiry, an ISO 27001 certification audit or an enterprise client's vendor due diligence questionnaire.

A baseline you can be measured against

The first assessment is the reference point. Every subsequent campaign, training session and policy change can be judged on whether it actually moved the number.

Better conversations with your insurer

Cyber insurers increasingly price on demonstrated control maturity. Documented human risk measurement and remediation is a stronger position at renewal than an assertion that staff receive annual training.

Process

How Orbix runs a human risk assessment

Four to six weeks from kickoff to board presentation, with roughly two hours of time required from each participating department.

01

Scoping and stakeholder alignment

We agree the population, the departments in scope, the data sources available and how findings will be handled. We also agree the privacy position up front: what is collected, how it is aggregated, how long it is retained and what individuals will be told. Getting this right is what makes the rest of the exercise run smoothly.

02

Baseline data collection

The workforce survey goes out, typically taking staff eight to twelve minutes. In parallel we gather access and role data from your systems and, where relevant, run a short simulated phishing campaign to capture observed behaviour rather than self-reported behaviour.

03

Structured interviews

We sit with department heads and a sample of frontline staff in the highest-exposure functions. This is where the reasons emerge: the workaround everyone uses, the shared login nobody has mentioned, the approval step that gets skipped when a deal is closing.

04

Scoring and analysis

Inputs are weighted and scored against our framework, then cross-checked for anomalies. Where a department scores unexpectedly well or badly we go back and verify before it reaches a report, because a wrong number destroys the credibility of the whole exercise.

05

Reporting and debrief

We produce the full assessment report, the department benchmark pack and a board summary, then present them. The debrief is a working session, not a handover: department heads should leave knowing what their number means and what they own.

06

Roadmap and reassessment

We agree the twelve-month improvement roadmap and set a reassessment date. Organisations that want the score tracked continuously rather than annually move onto our human risk management programme.

Deliverables

What you receive

Six documents, each written for a specific audience, because the report that persuades a board is not the report that helps an IT manager plan a quarter.

Human risk assessment report

The full document: methodology, evidence sources, organisational score, component breakdown, findings and supporting data.

Department benchmark pack

One page per department showing its score, its position relative to the rest of the organisation, the specific behaviours driving it and the two or three actions that would help most.

Human risk scorecard

A single-sheet scorecard suitable for the risk register, with the score, its components, the owner and the target for the next assessment.

Executive and board summary

Two pages for directors and the audit committee: where the organisation stands, what the exposure means in business terms, and what is being done about it.

Twelve-month improvement roadmap

Sequenced actions across training, policy, process and technical controls, with owners, effort estimates and expected score impact.

Reassessment methodology pack

The scoring framework and survey instruments documented so the assessment can be repeated consistently, whether by us or by your own team.

Suitable for

Who a human risk assessment is built for

It suits organisations that already have technical controls in reasonable shape and have realised the remaining exposure is behavioural.

Industries

Sectors handling volumes of personal or financial data get the most from it, particularly where a regulator or a major client audits their controls.

Banking and financial services Insurance and takaful Healthcare providers Government-linked companies Professional and legal services Technology and software Manufacturing Education Telecommunications Property and construction

Company sizes

Below about fifty staff the assessment is usually run as a single cohort. Above five hundred it is segmented so each business unit gets its own actionable view.

50 to 200 employees 200 to 1,000 employees 1,000+ employees Group structures with subsidiaries Organisations with regional offices

Departments

The assessment covers the whole workforce, but these functions carry the concentrated exposure and receive the deepest analysis.

Finance and treasury Human resources Legal and compliance IT and infrastructure Procurement and vendor management Customer service and call centres Sales and marketing Executive leadership and board
Why choose Orbix

Why organisations choose Orbix for human risk assessment

A risk score is only useful if the people it describes trust the method and the people who have to act on it can see what to do.

A governance approach, not a tool sale

We assess human risk as a governance problem: it belongs on the risk register, with an owner, a target and a review cycle, and our reporting is built to slot straight into that structure. The assessment is designed to be defensible in front of an auditor or a regulator, not just persuasive in a sales meeting.

Recommendations you can actually implement

Findings are written as actions somebody can take next quarter, with the effort honestly estimated. Where the right answer is a process change rather than more training, we say so, even though process changes are not something we sell.

Consultants who have sat on your side of the table

Our consultants have run compliance, data protection and security functions inside Malaysian organisations, not only advised on them from outside. That shows up in the advice: we know what a lean IT team can absorb in a quarter, and we know which recommendations get quietly shelved.

Built for the Malaysian operating context

Scenarios use Malaysian references your staff will recognise, from DuitNow payment requests and e-invoice notices to LHDN and EPF correspondence. Reporting is framed against the obligations your regulators and auditors actually cite, including the 72-hour personal data breach notification duty introduced by the 2024 amendments to the PDPA.

HRD Corp expertise where it applies

Where the roadmap calls for structured training, it can be delivered as an HRD Corp claimable programme through our registered training arm, so levy-contributing employers can fund the remediation as well as the diagnosis. See HRD Corp claimable cybersecurity training.

FAQ

Human risk assessment questions we get asked

The score combines four weighted components: knowledge, measured by survey; behaviour, measured by observed response to simulated attacks and existing security telemetry; access, measured by what systems and data each role can reach; and exposure, measured by how much external contact and transaction authority a role carries. Each component is scored separately and visible in the report, so you can see exactly what is driving the headline number and what would move it.

No. We do not read email, log keystrokes, inspect browsing history or profile named individuals. Data is collected at role and group level and reported in aggregate, with a minimum group size below which results are not broken out so individuals cannot be identified by inference. We agree the privacy handling in writing before collection starts, which also keeps the exercise proportionate under the PDPA.

Four to six weeks for most organisations. The survey window is usually two weeks, interviews take one week, and analysis and reporting take another two. The time asked of your teams is modest: about ten minutes per employee for the survey and around an hour for each department head interview.

It gets attention and support, not a disciplinary process. In our experience a badly scoring department almost always has a structural reason behind it, such as high turnover, an unrealistic service level, or a process that makes the secure route slower than the insecure one. We frame findings that way deliberately, because a report that reads as an accusation gets buried.

Annually is the norm, which is frequent enough to show whether the roadmap worked and infrequent enough not to fatigue the workforce. Organisations undergoing rapid growth, restructuring or a merger often reassess at six months, because both the population and the access map have changed.

Yes. Scoped assessments covering finance, a call centre or a single subsidiary are common, particularly as a pilot before a group-wide rollout. You lose the internal benchmarking that makes department comparison useful, so we usually suggest at least two or three departments so there is something to compare against.

The assessment itself is a consulting engagement. Training delivered as part of the improvement roadmap can be structured as an HRD Corp claimable programme under SBL-Khas for levy-contributing employers, subject to grant approval before delivery. Details are on our HRD Corp claimable training page.
Get started

Find out what your human risk score is

Tell us your headcount, your industry and what triggered the interest, whether that is an audit finding, a near miss, a board question or a regulator letter. We will come back with scope, timeline and a fixed quotation. No obligation, and we will say so if you do not need us yet.