| Verification Resilience | Assesses how reliably sensitive actions require independent validation regardless of how convincing, familiar, or authoritative the request appears. | Verification is informal, optional, or based on individual judgement. | Verification procedures exist but can be bypassed under urgency, hierarchy, or familiarity. | Verification is embedded into high-risk workflows, exceptions require approval, and procedures function independently of how the request is presented. | Verification is layered across channels, roles, and sensitive workflows, with step-up requirements for high-risk contexts. | Verification models adapt to threat activity, lessons learned, and changing adversarial conditions, and do not depend on any channel-borne indicator of identity remaining trustworthy. Synthetic voice, video, and generated text are the current instance, making a familiar voice, face, or writing style unreliable as proof of identity. |
|---|
| Workflow Integrity | Assesses how resistant workflows are to manipulation, bypass, or informal exception handling. | Sensitive actions can occur through informal requests or undocumented processes. | Approval paths exist but exception handling is weak or socially negotiable. | Critical workflows include enforced approval gates, independent verification, and reviewable decisions. | Workflow integrity is coordinated across relevant functions, dependencies, controls, and evidence sources so that verification, approval, exception handling, and review remain consistent across the full decision path. | Workflows are continuously tested and refined against emerging manipulation patterns. |
|---|
| Trust Boundary Management | Assesses how identity, authority, supplier, visitor, and contractor trust relationships are established, maintained, and periodically revalidated. | Identity, authority, supplier, visitor, and contractor trust is largely assumed. | Some trust relationships are checked, but controls vary by team or scenario. | Trust relationships are validated through defined processes and trusted sources independent of the requester. | Trust boundaries are mapped and managed across internal, external, supplier, contractor, and physical environments so that validation and revalidation remain consistent across connected relationships. | Trust assumptions are continuously reviewed as roles, suppliers, threat activity, and business processes change, including reassessment of which indicators of identity (voice, video, email style, caller ID) remain trustworthy as forgery capability advances, synthetic media being the current driver. |
|---|
| Human-Layer Visibility | Assesses how behavioural indicators, suspicious interactions, and escalation activity are captured, retained, and reviewed. | Suspicious behaviour is rarely captured, retained, or escalated. | Reporting channels exist, but visibility is limited and inconsistent. | Suspicious activity is reported, triaged, and retained as reviewable evidence. | Behavioural patterns are analysed across incidents, reports, exercises, and control failures. | Human-layer indicators inform proactive warnings, control changes, and strategic risk decisions. |
|---|
| Cross-Channel Coordination | Assesses how effectively physical, digital, supplier, and communication-channel indicators are connected operationally. | Email, phone, chat, supplier, and physical security events are handled separately. | Some coordination occurs after incidents, but channels remain siloed in normal operations. | Multi-channel scenarios are recognised and escalated through defined pathways. | Cyber, physical security, HR, finance, legal, and operations coordinate on human-layer threats. | Cross-channel activity is continuously correlated to detect complex campaigns and manipulation patterns, with correlation methods and coordination arrangements adjusted in response to emerging campaign behaviour and lessons learned. |
|---|
| Challenge & Escalation Culture | Assesses whether staff are operationally supported when questioning, verifying, or escalating suspicious behaviour regardless of the apparent authority or familiarity of the requester. | Staff avoid challenging suspicious requests due to hierarchy, fear, or social discomfort. | Staff know where to report, but escalation is inconsistent or culturally uncomfortable. | Staff are supported when pausing, challenging, or escalating suspicious requests, including requests from known or senior individuals. | Challenge and escalation expectations are reinforced consistently through leadership, exercises, incident review, and the workflows in which staff are expected to act. | Challenge culture is normalised as an organisational resilience behaviour — verification is treated as professional conduct, not suspicion, and a person who was manipulated is treated as a sensor that surfaced a control gap, not as the point of failure. Leadership support, escalation arrangements, and reinforcement practices are adjusted in response to incidents, exercises, staff feedback, and changing operational pressures. |
|---|
| Physical Interaction Security | Assesses resilience against adversarial activity involving physical presence, access, removable media, or onsite interaction. | Tailgating, visitor trust, rogue media, and informal access are unmanaged or normalised. | Visitor and access procedures exist but are inconsistently enforced. | Physical access controls, escort rules, removable media controls, and challenge expectations are operationalised. | Physical and cyber indicators are jointly reviewed for social engineering patterns. | Physical, digital, and behavioural indicators are integrated into adaptive defensive operations. |
|---|
| Operational Friction Design | Assesses how verification and approval friction is intentionally introduced and maintained in sensitive workflows. Distinct from Workflow Integrity: this domain assesses the deliberate calibration of friction itself, not the presence of approval paths. | Speed and convenience consistently override verification. | Friction exists in policy but is removed during pressure or exceptions. | Intentional friction protects sensitive actions without fully blocking operations. | Operational friction is coordinated across sensitive workflows and adjusted according to workflow sensitivity, consequence, and threat context. | Friction is continuously tuned to balance operational speed, user experience, and adversarial resistance. |
|---|
| Exposure Management | Assesses how effectively the organisation identifies and reduces what an adversary can learn before contact — from public content, personnel profiles, digital artefacts, and physical observation — and convert into targeting or pretext material. | Organisational and personnel exposure is unmanaged; content and operational details are published without consideration of their reconnaissance value. | Exposure risks are recognised and general guidance exists, but publication, profile, and workspace practices vary and are reviewed only after a concern arises. | Material exposure sources are identified and managed through defined publication review, profile guidance, metadata handling, and disposal controls, with targeted measures for high-exposure roles. | Exposure is assessed in aggregate across organisational, personnel, supplier, and physical environments, and reconnaissance findings are connected to the techniques and decision paths they would support. | Attacker-observable context is reassessed continuously as platforms, operating patterns, and threat activity change, and exposure-reduction measures adapt ahead of confirmed targeting. |
|---|
| Response & Trust Recovery | Assesses how the organisation mobilises after manipulation is identified, interrupts active interactions, manages trust in affected identities, counterparties, channels, and workflows, and restores reliance on evidence rather than operational pressure. | Confirmed manipulation produces improvised action; mobilisation, interruption, and restoration decisions are made during the incident. | Escalation usually reaches relevant personnel through informal routes, response quality depends on availability, and compromised trust returns to use under operational pressure rather than evidentiary clearance. | Response procedures and decision authority are defined for material incident classes, active interactions can be interrupted before harm occurs, and restoration of suspended trust requires a named decision. These arrangements are demonstrated through incidents, exercises, or other operational evidence. | Trust in affected identities, counterparties, channels, and workflows is formally suspended and restored against evidence specific to the compromise, while plausible related targets are protected before further compliance occurs. | Response and restoration adapt to campaign behaviour in progress; measured recovery performance drives changes to mobilisation, interruption, suspension, and restoration capability, and restoration criteria evolve with threat conditions. |
|---|
| Adaptive Improvement | Assesses how effectively incidents, exercises, and emerging threats drive operational uplift, including whether human-layer risk has clear ownership and accountability rather than falling between security, HR, and fraud functions. | Incidents are treated as one-off events or individual user mistakes. | Lessons are discussed but not reliably translated into control or workflow uplift. | Incidents and exercises produce documented improvement actions that are tracked to closure. | Lessons learned are mapped to controls, owners, evidence sources, and governance reporting. | Emerging threats, incidents, and exercises continuously reshape controls, workflows, and assurance activity. |
|---|