· HUMAN LAYER

Security Awareness & Human Factors in GxP

The human layer is treated as a training problem and is mostly a design problem. People are the most-attacked control in any organisation and simultaneously its fastest detector, and which of those dominates is decided by something training cannot reach: whether an employee who clicked something believes it is safe to say so immediately. An organisation that disciplines the person who clicked will learn about the next incident considerably later.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 22 LINKS

Awareness fails the same way training does: completion is measured, behaviour is not. The useful metric is whether people report the thing they are unsure about, which requires that reporting be safe.

06 · QUALITY MATURITY — SECURITY AWARENESS & HUMAN FACTORS IN GXP, REACTIVE TO ADAPTIVE

L1
Reactive

An annual module is assigned and completion is tracked. Nothing else is known about how people behave.

L2
Defined

Simulated phishing runs and click rates are reported, with the failure rate treated as the measure and the reporting rate ignored.

L3
Controlled

Content is targeted at what specific roles actually face, reporting is easy and explicitly safe, and the reporting rate is the headline measure.

L4
Predictive

Real incidents and near-misses feed the content, and a repeated human failure is examined as a design problem rather than answered with more training.

L5
Adaptive

Work is arranged so the risky action is hard and the safe action is easy, and awareness carries what design could not remove rather than compensating for it.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 4

Derived from the 4 standards SPEQ maps to this subject, across 4 regulatory bodies: EMA, ICH, IEC, ISO.

RECORDS & OBJECTIVE EVIDENCE

  • Awareness content, and how it is differentiated by role and actual exposure
  • Reporting rates alongside failure rates, over time
  • The reporting route, and evidence that using it is consequence-free
  • Incidents and near-misses traced into subsequent content
  • Analysis of repeated human failures, and any design change that followed

COMMON INSPECTION FINDINGS

  • Completion of an annual module used as the sole measure of awareness
  • Phishing simulation results reported as click rate with no reporting rate
  • Punitive handling of simulation failures, which suppresses reporting of real events
  • Identical content for roles with entirely different exposure
  • A recurring human failure answered with retraining each time and no design change
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Reporting speed beats prevention rate

Awareness programmes are measured on phishing simulation click rates, and the measure is close to useless. Click rates fall as people learn to recognise the simulation, sufficiently well-targeted phishing succeeds against trained people, and the number says nothing about what happens after a click. The measure that predicts incident severity is time-to-report: how long between someone doing something they should not have and the security team knowing.

That is a culture variable, not a knowledge variable. It responds to whether reporting is easy, whether the last person who reported was thanked or investigated, and whether managers treat a report as a failure. An organisation that shortens time-to-report from days to minutes has changed its actual exposure; one that reduced click rates by three points has changed a number.

This is the Just Culture argument, applied to security

Regulated industry already knows this. Quality culture work rejects felt-safety self-ratings in favour of observable behaviour, and the maturity model scores how problems surface — whether people raise deviations early, whether stop-the-line authority is real. Security is the same question about a different failure: whether an employee who fell for something raises it immediately or hopes it resolves itself.

Applying the existing frame is more effective than importing a separate security-culture programme. The organisation already has language for distinguishing human error from at-risk behaviour from reckless behaviour, already has a deviation system people either trust or do not, and already knows that punishing the reporter is how information stops arriving. Security should use that machinery rather than build a parallel one with different rules.

Design the process so the secure path is the easy one

Where a control makes legitimate work difficult, people route around it, and the workaround becomes the standard practice nobody documented. Shared accounts on a system that will not support enough named users, credentials written down because the rotation policy outran human memory, files emailed out because the sanctioned transfer route is unusable — each is a rational response to a control designed without the work in mind.

The diagnostic question is not "why did they violate the policy" but "what made the compliant path harder than the alternative". That reframing usually points at something fixable in the control rather than something to be trained out of the person, and it is the same human-factors reasoning that usability engineering applies to device design.

Insider risk, without treating everyone as a suspect

Most insider incidents are not malicious. They are people making mistakes under pressure, taking a shortcut to hit a deadline, or taking data with them when they leave without thinking of it as theft. The controls that address the bulk of it are the same ones that address everything else — least privilege, access review, monitoring of privileged actions, segregation of duties — rather than surveillance.

The genuinely malicious minority needs a different, narrower response, and it works better where the ordinary controls are already sound. An organisation with standing privileged access, unreviewed entitlements and no logging cannot detect an insider regardless of how much monitoring it layers on top; one with tight entitlements and reviewed privileged activity detects both the mistake and the malice from the same evidence.

SPEQ interpretation — role-based, not annual and universal

The default awareness programme is an annual module everyone completes, and its completion rate is reported as a control. A completion rate measures attendance. It does not distinguish the finance controller who will be targeted by payment fraud, the automation engineer with domain admin on the control network, the clinical operations lead handling participant data, or the QA analyst approving batch records — four people with four different threat models and one identical training course.

SPEQ’s view is that awareness should be scoped the way GxP training already is: by role, against defined competencies, with the evidence being demonstrated behaviour rather than course completion. Regulated organisations run exactly this machinery for GxP training and rarely think to point it at security, which is a capability sitting unused.

FREQUENTLY ASKED

Are phishing simulation click rates a useful measure?

Barely. Rates fall as people learn to recognise the simulation rather than the threat, well-targeted phishing defeats trained people, and the number says nothing about what happens after a click. Time-to-report — how long between the mistake and the security team knowing — predicts incident severity far better and is a culture variable rather than a knowledge one.

How does security culture relate to quality culture?

They are the same question about different failures: whether people raise a problem early or hope it resolves itself. Regulated organisations already have Just Culture language distinguishing human error from at-risk and reckless behaviour, and a deviation system people either trust or do not. Security should use that machinery rather than build a parallel programme with different rules.

What should you conclude when people work around a security control?

That the compliant path was harder than the alternative. Shared accounts, written-down credentials and unsanctioned file transfer are usually rational responses to controls designed without the work in mind. The productive question is what made the secure route harder, which typically points at something fixable in the control rather than in the person.

How should security awareness training be scoped?

By role, against defined competencies, with demonstrated behaviour as the evidence — the way GxP training is already scoped. An annual universal module treats a finance controller, an automation engineer with domain admin, and a QA analyst as having the same threat model, which they do not. Most regulated organisations already run this machinery and simply have not pointed it at security.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…