Most companies discover a breach weeks or months after it happened. Do you know where yours stands?
L1Layer one of nine

Human Layer

Most incidents start with someone clicking. We measure that risk person by person and bring it down with practice, not an annual talk.

  • Phishing simulation
  • Ongoing training
  • Per-person risk score
  • Leadership reporting
Young woman seated at her desk, both hands on the keyboard and her face turned three-quarters toward the camera in a brief pause, beside a large window.
How it gets in

Email arrives before any technical control does.

A well-crafted message gets past filters because it carries nothing malicious: it asks for a transfer, a password, or a signature. There, the defense isn't a tool, it's the person who receives it. What we do is turn that into something measurable: who's exposed, who's already improved, and which areas need attention before the rest.

Signs you're missing this layer
  • No one knows what percentage of your people would fall for a fake email.
  • Security training was a single session that never happened again.
  • Fraud attempts get mentioned in passing, never logged.
Scope

What the layer includes

Every component is implemented, configured, and left under SOC watch. We don't hand over bare licenses.

Periodic simulations

Controlled phishing campaigns with real scenarios from your industry, unannounced and without exposing anyone in front of coworkers.

Outcome-based training

Whoever falls for it gets the short module that matches that mistake, on the spot. Whoever doesn't loses no time.

Risk score by person and area

An indicator that rises and falls with behavior, comparable across areas and over time.

Reporting channel

A button for people to report anything suspicious, with a SOC response. Reporting stops being a chore.

Operations

The layer isn't installed and forgotten.

Everything this layer generates flows into the SIEM, gets correlated with the rest of the stack, and is reviewed by an analyst on shift. What follows is the same across all nine layers.

Classified in under a minute

The Triage Agent reviews every event that comes in, at any hour, and discards the noise before it reaches a person.

Confirmed by an analyst

The decision to contain, isolate, or escalate is made by a person with context on your operation, not an automation.

It gets logged

Every action on this layer enters the period's report, with time, owner, and outcome.

Two Lynxsource SOC analysts, one seated and one standing beside her, looking together at a status dashboard on the monitor.
What you receive
  • Monthly report with Risk Score trends by area.
  • One-page executive summary for the board or leadership.
  • Log of reported emails and what was done about each.
FAQ

What people ask about this layer

Are people who fall for the simulation exposed?

No. Individual results are only seen by the person you designate, and what's shared with the rest is aggregate data.

How often do campaigns run?

Monthly by default. It can be adjusted based on organization size and what the Risk Score shows.

Does it count toward a certification?

The training and simulation record covers the awareness requirement in ISO 27001 and most equivalent frameworks.

What if we already have a training platform?

We integrate it and add the operations and measurement. You don't need to switch tools to start.

Let's see how this layer stands in your operation.

A free review, no strings attached. We'll tell you what we found, what to fix first, and what to expect.

Request a free assessment

We respond within one business day. Ecuador, Colombia, Bolivia, the United States, and Canada.

WhatsApp