Cybersecurity / Human Risk Management

Human Risk Management Programme for Malaysian Organisations

A single campaign gives you a data point. A programme gives you a trend line, and a trend line is what a board can govern. We run continuous simulation, monthly awareness campaigns and a live risk dashboard across a twelve-month cycle, with quarterly reviews that keep the number moving in the right direction.

Twelve-month managed cycle, renewed annually Live human risk dashboard with quarterly trend reporting HRD Corp claimable training built into the calendar
Overview

Human risk, managed continuously rather than annually

What it is

Human risk management is a managed programme rather than a project. Instead of one assessment and one training day per year, the programme runs a continuous cycle: simulations release monthly or quarterly, awareness content lands on a published calendar, results feed a live risk dashboard, and every quarter we sit down with your leadership team to review the trend and adjust the plan.

The programme opens with a baseline, usually a human risk assessment and an initial phishing simulation, which establishes the starting position and identifies the highest-risk groups. From there the calendar is built: which campaigns run when, which departments receive intensive attention, what the awareness themes are month by month, and what the target score is at each quarterly checkpoint.

Orbix runs the operational load. We design and release the campaigns, produce the awareness material, maintain the dashboard, chase the completion data and write the reports. Your team gets the results and the decisions, not the administration, which is what makes the difference between a programme that survives its first year and one that quietly lapses in month four.

Why organisations need it

Awareness decays. Measured behaviour improves sharply after an intervention and then drifts back, usually within three to six months. An annual training day therefore produces a sawtooth pattern in which the organisation is well protected for one quarter and progressively less so for the other three. Continuous programmes hold the improvement instead of repeatedly rebuilding it.

Populations change too. New joiners arrive without the context everyone else received, people move into roles with greater access, and departments restructure. A static annual measurement is out of date within weeks of being taken, which is why the number needs maintaining rather than sampling.

There is also a reporting argument. Boards and audit committees want risk categories that behave like every other risk on the register: a current value, a trend, an owner and a target. Human risk only fits that shape if it is measured continuously. Under the amended PDPA, where breach notification and demonstrable safeguards are now firm expectations, a continuous record of measurement and remediation is materially stronger evidence than an annual attendance sheet.

Key features

What the programme includes

Everything below is delivered as a managed service across the twelve-month cycle. The mix is agreed at the start of each year and adjusted at the quarterly reviews.

Continuous phishing simulations

Campaigns released on a rolling schedule, monthly for high-risk functions and quarterly for the wider workforce, with difficulty escalating as performance improves. Templates rotate so nobody learns the pattern instead of learning the principle.

Human risk dashboard

A live view of the organisational risk score and its components, broken down by department, branch, role and tenure, with trend lines against target. Department heads see their own position, which is usually the single most effective motivator in the programme.

Monthly awareness campaigns

A published annual calendar of themes delivered through short content: a two-minute video, a poster, an intranet piece, a briefing note. Timed to the year, so payment fraud content runs before the festive rush and travel security before the long holiday periods.

Targeted remediation

Staff and teams whose behaviour indicates elevated risk receive additional, proportionate support rather than a company-wide repeat of the same session. Repeat clickers get a short guided module; a struggling department gets a facilitated workshop.

Executive reporting

Monthly one-page updates and a quarterly board-ready report covering the current score, movement against target, the drivers behind the movement and the actions planned for the next quarter.

Quarterly programme reviews

A working session with your stakeholders every quarter: what worked, what did not, what changed in the business, and what the next quarter's plan should be. This is where the programme stays relevant rather than becoming a subscription nobody looks at.

Benefits

What the business gets out of it

The programme converts an annual compliance chore into a governed risk with an owner, a target and a visible trend.

The improvement actually holds

Continuous reinforcement prevents the decay that follows a single annual session. Organisations that sustain a programme through a full cycle typically see click rates fall and, more importantly, reporting rates rise and stay risen.

Human risk gets governed like every other risk

A quarterly number with a trend, a target and an owner is something a risk committee can manage. An annual training completion percentage is not, which is why it has never worked as a governance measure.

Your internal team is freed up

Running a credible programme takes real administrative effort: designing campaigns, producing content, chasing completions, compiling reports. We carry that load, which is usually the reason internal programmes stall.

New joiners are covered automatically

Onboarding is built into the cycle, so someone who joins in March receives the same grounding as someone who joined in January instead of waiting for next year's session.

A continuous evidence trail

Twelve months of campaign records, completion data, remediation actions and quarterly reports form a substantial body of evidence for a Commissioner enquiry, an ISO 27001 audit, a client vendor assessment or an insurance renewal.

Predictable, claimable budget

An annual programme fee is easier to plan than a series of ad hoc engagements, and the training components can be structured as HRD Corp claimable programmes for levy-contributing employers.

Process

How the programme runs across a year

A twelve-month cycle with a defined rhythm. Most clients renew and raise the target rather than stepping back to ad hoc activity.

01

Month 1: Baseline and programme design

We establish the starting position through a human risk assessment and an unannounced phishing campaign, agree the twelve-month targets with your stakeholders, and publish the campaign and awareness calendar so the whole year is visible from the start.

02

Month 2: Dashboard and communication launch

The dashboard goes live with baseline data and department views. We run the internal communication that explains the programme to staff, which is the step that determines whether people engage with it or resent it.

03

Months 2 to 12: Continuous delivery

Simulations release on schedule, awareness content lands monthly, targeted remediation runs for elevated-risk groups, and results flow into the dashboard automatically. Monthly one-page updates go to the programme sponsor.

04

Quarterly: Review and adjust

Each quarter we present the trend to your leadership team, examine what moved and what did not, and adjust the next quarter's plan. Business changes such as a new acquisition, a restructure or an emerging threat pattern get absorbed here.

05

Mid-year: Deep-dive assessment

At month six we run a fuller reassessment, including a repeat human risk assessment and a dark web exposure recheck, to verify that the score movement reflects genuine improvement rather than familiarity with our campaign style.

06

Month 12: Annual report and renewal planning

A full-year report covering the movement, what drove it, the evidence trail and the recommended focus for the next cycle. Targets are reset upward and the calendar is rebuilt around the year ahead.

Deliverables

What you receive

Deliverables arrive continuously through the year rather than as a single report at the end of it.

Live human risk dashboard

Continuous access to the organisational score, department breakdowns, campaign results and trend against target, with views appropriate to each level of management.

Monthly executive updates

A one-page update covering what ran, what the results were, what changed and what is coming next month.

Quarterly board reports

A board-ready report for each quarter with the risk position, trend, drivers and planned actions, formatted for the board pack.

Annual programme report

The full-year account: baseline to closing position, every campaign and intervention, the evidence trail and recommendations for the following cycle.

Awareness content library

The videos, posters, briefing notes and intranet content produced during the year, yours to retain and reuse.

Training records and certificates

Attendance and completion records for every training component, with participant certificates verifiable through our certificate verification page.

Suitable for

Who the programme is built for

It suits organisations that have already run a one-off campaign or assessment, seen the value, and concluded that doing it once a year is not enough.

Industries

Regulated sectors and organisations facing regular client security assessments get the strongest return, because the continuous evidence trail has value beyond the risk reduction itself.

Banking and financial services Insurance and takaful Healthcare groups Telecommunications Technology and SaaS Manufacturing Government-linked companies Professional services Education Logistics and supply chain

Company sizes

Below about a hundred staff a lighter quarterly cycle usually makes more sense than a full monthly programme. We will tell you if that is the case for you.

100 to 500 employees 500 to 2,000 employees 2,000+ employees Multi-branch and regional operations Groups with several subsidiaries

Departments

The programme covers the whole workforce, with intensity weighted towards the functions carrying the most risk.

Finance and accounts payable Human resources IT and information security Customer service Procurement Sales and business development Operations Executive leadership
Why choose Orbix

Why organisations choose Orbix for human risk management

The hard part of a continuous programme is not the first quarter. It is keeping it credible and relevant through the fourth.

A governance approach, not a tool sale

The programme is designed around your governance cycle. Quarterly reporting aligns to risk committee dates, the score sits on the risk register with an owner and a target, and the evidence trail is built to satisfy an auditor. Human risk becomes a governed risk category rather than a training line item.

Recommendations you can actually implement

We adjust the programme to what your organisation can absorb. If the quarterly review shows a department is saturated, we ease off rather than pushing content nobody reads. A programme that people quietly tune out is worse than no programme, because it produces evidence of activity without producing any change.

Consultants who have sat on your side of the table

Our consultants have run compliance, data protection and security functions inside Malaysian organisations, not only advised on them from outside. That shows up in the advice: we know what a lean IT team can absorb in a quarter, and we know which recommendations get quietly shelved.

Built for the Malaysian operating context

Scenarios use Malaysian references your staff will recognise, from DuitNow payment requests and e-invoice notices to LHDN and EPF correspondence. Reporting is framed against the obligations your regulators and auditors actually cite, including the 72-hour personal data breach notification duty introduced by the 2024 amendments to the PDPA.

HRD Corp expertise where it applies

Training components across the year can be structured as HRD Corp claimable programmes under SBL-Khas for levy-contributing employers, which makes a meaningful part of the annual programme cost recoverable. We plan the calendar around grant application timing so approvals are in place before delivery. See HRD Corp claimable cybersecurity training.

FAQ

Human risk management questions we get asked

A platform gives you tooling and leaves the programme to you. In practice that means someone internal has to design campaigns, produce content, interpret results, chase completions and write board reports on top of their existing job, which is why so many platform subscriptions go unused after the first quarter. We run the programme and deliver the outcomes; the tooling is our problem, not yours.

It combines four weighted components: knowledge from assessment and training data, behaviour from simulation results and reporting rates, access based on what each role can reach, and exposure including credential leakage and external-facing contact. Every component is visible in the dashboard, so you can always see what is driving a movement rather than trusting a single opaque number.

Minimally. We need a recipient list and your IT team to allowlist our sending infrastructure. Optional integrations with your directory or learning platform reduce administration and improve the accuracy of role and department mapping, but the programme runs perfectly well without them, which suits organisations with restrictive change processes.

We treat that as our problem to diagnose. Flat scores usually indicate one of three things: content that is not landing, a structural process issue that no amount of awareness will fix, or a department where the manager has not engaged. The quarterly review exists precisely to identify which and to change the approach. A programme that reports the same number for three quarters without adjusting is not being run properly.

Yes, and many clients do. A common path is a single phishing simulation first, then a human risk assessment to establish a proper baseline, then the full programme once leadership has seen the numbers. Starting with the whole programme before anyone believes there is a problem tends to lead to weak internal sponsorship.

The training and awareness components can be structured as HRD Corp claimable programmes under SBL-Khas for levy-contributing employers, subject to grant approval before each delivery. The simulation, dashboard, reporting and consulting elements are professional services and are not claimable. We break the proposal down so you can see exactly which portion is claimable before you commit.

Twelve months. Shorter periods do not produce a meaningful trend, and a programme judged on one quarter's movement will be judged on noise. If you are not ready for a twelve-month commitment we would rather sell you a single assessment or campaign now and revisit the programme when the case is clearer.
Get started

Move human risk from an annual chore to a managed number

Tell us your headcount, your industry and what triggered the interest, whether that is an audit finding, a near miss, a board question or a regulator letter. We will come back with scope, timeline and a fixed quotation. No obligation, and we will say so if you do not need us yet.