What happens to the part of your organization that fits no plan

Nave logística de noche con tres zonas de trabajo iluminadas por haces cenitales cerrados y todo el resto del piso bajo una luz ambiente tenue y pareja.

What happens to the part of your organization that fits no plan

There is a moment in implementations where the conversation changes tone. We are reviewing segmentation with someone who runs a mature program, with separate plans for finance, for technology and for customer support, each with a well argued risk hypothesis behind it. At some point we add up the three audiences, compare them against the full headcount and the number nobody had looked at shows up. Almost half the organization is in none of the three.

There is nearly always an answer ready for that gap. That population gets the monthly newsletter.

It is a reasonable call. Someone spent their management budget where the risk justified it. The problem is not the prioritization, it is what gets declared afterwards. When the committee asks about program reach, the newsletter counts as coverage, and that is where the figure starts saying more than the data can support.

Coverage in an awareness program is the percentage of your headcount that received and completed at least one activity within a given period. It measures reach rather than learning, and it is the only figure that answers whether the program reaches the whole organization or only the part you measure.

Why do people end up outside every targeted plan?

Because targeted plans are built on a hypothesis, and the hypothesis needs an argument behind it.

Finance is in because of supplier fraud and access to payments. Technology is in because of privileges. Customer support is in because of the volume of external email it handles and its contact with personal data. Each of those decisions stands on its own in front of a committee and in front of an auditor.

Then there is everyone else. People in plants, in logistics, in maintenance, in administration, support roles that touch no critical systems and handle no payments. Nobody has a risk argument for that population that would justify designing a dedicated path, and building one anyway would mean inventing a priority you cannot defend.

That reasoning is correct right up to the last line. Where it bends is when it turns into the idea that this population needs nothing. What is missing is a hypothesis to steer the content. The exposure is still there, because these people have corporate email, credentials and network access just like everyone else.

What does receiving this month’s newsletter actually prove?

Less than it looks, and that is a measurement problem before it is a content problem.

An awareness newsletter is measured, by default, by the email open. That figure depends on the mail client loading a remote image, so an organization that blocks images by policy will see open statistics land below the real number. On our own Newsletters page we say it plainly. If all we have is the open, we have no certainty that the person read the content, and in some cases no certainty that they opened it at all.

It is the same mechanism I covered when I wrote about what has to be configured before you trust a click rate. Every email metric measures the person and the environment at the same time, and when the environment is not declared, the number gets read as if it were only about the person.

There is a way to turn that send into a reportable figure, and it is adding a validation question at the end. The campaign stops recording opens and starts recording who answered and whether the answer was correct. That gives you one completed activity per person, which is exactly the unit a coverage indicator needs.

Both setups cost the same to produce. One lets you declare reach to an auditor and the other leaves the program with no way to prove it.

Why isn’t a targeted plan for them the answer either?

Because it reproduces the cost that left them out in the first place.

A targeted plan has design work behind it. Someone decides which topics go in, in what order, how long each stretch runs and what gets assessed. That work is justified when there is a risk hypothesis to steer it. Without one, topic selection comes from the intuition of whoever builds it, and the result is a plan you cannot defend any better than the newsletter it was replacing.

Then there is the cost that shows up every month. One more plan means one more audience to review, one more list of incompletes to chase and one more exception to handle. It is the same management work that was already scarce when the decision to leave that population out was made.

The alternative of folding everyone into another group’s plan has its own cost, and it is paid in credibility. A maintenance technician who receives four modules on international transfer fraud learns something that is not about security. They learn that the program does not distinguish and that it can be ignored without consequence, which is the exact point where the wrong habit starts to hold.

What this population needs is continuity, and continuity does not come from better design.

What does a baseline layer need in order to run without management?

Four things, and all four are design conditions rather than content ones.

Run without anyone triggering it. If every send depends on someone remembering, the first busy month the layer stops existing and nobody notices, because this population does not complain either. It is the same dependency I described in what breaks when the person running the program leaves, made worse by the fact that here no department raises its hand.

Carry an explicit time ceiling. A baseline layer competes with the real work of people who were never consulted about its existence. Without a declared limit in minutes per person, the only way to find out you went too far is that someone complains.

Refresh its own population. A layer running flawlessly over last quarter’s user list covers nobody who joined since, and the indicator stays green because the denominator aged too. It is the same problem that makes new hires move compliance all year long.

Not repeat what was already completed. If the person already saw that content in an earlier campaign, assigning it again burns their time budget without adding anything and confirms that the program is not paying attention to them.

None of the four is about picking better topics. They are about the layer still being there six months from now.

A metal dial set into a wall, turned to a mark well short of the end of its travel, with the blurred glow of an ambient light strip behind it.

How is that layer configured in SMARTFENSE?

With a program format defined by criteria instead of by a fixed path. In SMARTFENSE it is called Smart Path, and it is the counterpart to the ready made awareness programs, which come with a complete one to three year path and reach everyone the same way on the same date.

The two formats solve different problems and coexist. The fixed program covers what has to be completed on a date with evidence of who did it, which is where the year’s regulatory training and onboarding live. Smart Path covers the rest of the year for each person, which is the part you cannot plan ahead because it depends on what each one already completed, how much time they have and when they joined.

What you define once is eight criteria. The topics the content comes from, the enabled components, whether the material comes from the catalog or also from your own, the difficulty, the minutes per person per month, the days and times a campaign can start, and who it reaches. From there the program builds each person’s path out of what that person already completed, runs one evaluation per day and has no end date.

The recipients criterion is what solves the third condition on the list above. The program reviews who it reaches every day rather than only on the day it was created, so anyone joining an included group starts receiving content without a manual assignment, and anyone who is deactivated stops receiving it.

It is worth saying what it does not solve. A Smart Path does not replace a targeted plan where there is a risk hypothesis to defend, it does not interpret why one area performs differently from another and it does not negotiate a quiet period with anyone. What it does is sustain a baseline over the population that has nobody to build them a plan, at a management cost that after the initial setup is zero.

What gets measured?

The percentage of that population with at least one completed activity in the last ninety days.

All three elements of that sentence are there on purpose. That population and not the full headcount, because the number has to isolate the group that fits no targeted plan. Completed and not delivered, because a delivery is not a finished activity. Ninety days because a quarterly window tolerates the month someone was on leave without writing off their coverage.

It is a coverage indicator rather than a performance one, and saying so when you present it is worth more than leaving it ambiguous. It answers whether the program reaches people, not whether behavior changed. Whoever receives it at the committee will understand the difference, and so will whoever audits it.

The platform’s program dashboard shows what share of the organization is covered, the month’s assignments and how many people are paused, and all of it exports to Excel and CSV with a date filter. For the rest of the organization, that number is usually the first one that has ever existed. Before there was a statement about a newsletter, and now there is a percentage with a cut-off date.

It is worth reading alongside the rest of the dashboard, because it separates two things that get confused often in the debate about whether the program is measuring what matters. An organization can have very good behavioral results and low coverage at the same time. They are two different questions, and the second one is what this number answers.

If you want to see how that layer looks over a real population, the Smart Path page has the detail of the criteria and of what the dashboard shows.

Mauro Sánchez

CTO de SMARTFENSE, lidera los equipos de ingeniería y desarrollo. Especialista en materia de ciberseguridad e infraestructura, siendo el encargado de definir y concretar las integraciones y alianzas tecnológicas estratégicas de SMARTFENSE con diferentes soluciones. Más de 20 años avalan su experiencia en la toma de decisión e implementación de medidas de seguridad y tecnología.

Leave a Reply