On-demand session · 22 minutes Recorded live at HRMCon 2026

Co-designing secure work: how security teams can lead workflow redesign

Redesigning the work itself so the secure path is the easy path — and security sits with the business rather than behind it.

Aaron and Jim show how security teams can lead workflow redesign alongside the business, instead of reviewing it after the fact.

Aaron Pritz, Jim Wailes speaking at HRMCon 2026
Aaron PritzReveal Risk
Jim WailesReveal Risk
Full session · 22 min
Why watch

Fix the work, not the worker.

When the secure path is the hard path, people route around it. Training won’t change that — the workflow has to.

Aaron and Jim show how security teams can lead workflow redesign alongside the business, instead of reviewing it after the fact.

What you'll learn

In 22 minutes, you'll walk away knowing:

How process design shapes the decisions people make.

Redesign principles that remove friction.

Working with the business rather than behind it.

Speakers

Two advisors who redesign the work itself

Aaron Pritz

Aaron Pritz

Reveal Risk Follow on LinkedIn
Jim Wailes

Jim Wailes

Reveal Risk Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:09 Alright, we've got the post-gra break group, and you know, fun fact about me, I was, when I was… my youthful days, I played drums in a rock band on college campuses, so I've seen a lot of rooms like this. And typically, we'd open back up with, hope you had a good break. The more you drink, the better we sound, but I think with iced tea and Diet Coke, you're only gonna get more caffeinated, which is okay. My name's Aaron Pritz, CEO, co-founder of Reveal Risk, and, spent a long time, two decades, in the pharmaceutical side, inheriting cyber workforce awareness. Before, HRM was a cool thing, right after an insider threat arrest of two of the scientists at our company. So, awareness in this whole field became a passion for mine. Excited to share some stories, as well as some tips on, things that we're seeing evolve in the HRM market. So, my name's Jim Wales. As I said, I'm a senior consultant with Reveal Risk. Come from kind of a non-traditional background, got a background in military intelligence and law enforcement, and through that career path, I got pretty good at Being kind of a translator for some highly technical concepts and, making those understandable for non-technical audiences.

1:22 Like juries and judges and, attorneys, things like that. And, I… took that experience, and now I lead the Human Risk Management Service at Reveal Risk. Awesome. And I told Jim 5 minutes before we went on stage here that I'm gonna go off of the script a little bit, which I saw him visibly gulp. But two things. We have the benefit of being closer to the end of the day, and hearing a lot of the great speakers, and I put some notes together to draw some insights. to kind of open up the fourth topic of… really, we talked about four topics, and I think this last one's a little bit different. And then second, guys, we are at a Human Risk Management Workforce Awareness Conference, and no one has gamified their presentation. So, we are going to try to gamify a little bit of our talk today. Some of it's planned, some of it's not. We didn't bring prizes, but I did find that I have two, socks, they're brand new, branded socks, in my bag. And then, if there's a third prize, we'll let somebody do the claw and get one of Kevin's, magical balls of, prisery, so… You're welcome, Kevin. Alright, so let's open up with some comments. So, I wrote a blog article probably a week and a half ago, some of the Libyan security team commented on it. I believe there's four action-oriented, results or actions that we can take from human risk management.

2:41 Before, and then we'll go into a little bit of detail, risk intelligence. That is Living Security and what the data's coming together. Tailored education and interventions, again, a lot coming out of Living Security, a lot of you probably have custom interventions or training or things that you do specific or bespoke to your program. Technical control changes, I have a couple comments on that, and then Jim and I are going to be focused on business process, remediation, and re-engineering. So a couple of thoughts from earlier talks. Intelligence. One, it was great to see Semano's MindShield product. That's a whole different level of intelligence from a psychological standpoint. that I hadn't thought about yet, and how that can intersect. I have questions on how to get that through the GDPR Council… Works Councils that we struggle with, but I think there's an option… option there. And then Alfonso said in his talk, workarounds by the business are signals, not failures. And to me, that really underscores the reason for why you might roll up your sleeves and get involved from a process change standpoint with the business partners that you support, versus sending things from on high, from what we kind of always did, the training awareness.

3:51 Second, training… tailored education and interventions, definitely nudges, targeted cohorts, all of those things, both powered through Living Security and the programs that you likely have in place, or expanding. And then a lot of good, the last few topics were all about technical changes. Ashley and Alfonso talking about, fishing resilient MFA and how to bridge all that stuff to data, and have data help open up the buy-in and sponsorship for that, and then Geneti from Stuart Title talking about how to add specific tech controls for high-risk users. I really liked kind of hearing, okay, here's different groupings that people are in, and we're able to block or enable or change the, kind of, the controls around that. And then, I'll let Jim kind of… we'll open it up into the process side, but with business process remediation. Actually, Ashley shared the quote with me prior, but it sunk in even more the second time from Labcorp that 72% of employees were knowingly bypassing security policy on purpose.

4:50 And it's probably not because you didn't send them training, or there wasn't a policy, it was probably because they had a business process documented or tribal knowledge that they were just doing it the way they always did. So… I want to really push us to change the convention of we have to stay in awareness and our mindset, and really, if we're pushing HRM into more of the risk management. We need to be out there assessing, we need to be out there driving controls, we need to be out there driving mediation, and doing it as a partner to the business, not an inflicter to the business. 100%, yeah. Alright. So, next up, this is part of the gamification, and we saw some deepfake stuff from Ashley this morning. Everything in this session is real, except for the part that isn't. Little bit of a spoiler, we will have a little bit of a deepfake into one of the processes that we're gonna ask you guys to dissect and help us figure out what's wrong with it, so… Know that going into it. Disclosure, so nobody's tricked, even though… That's the goal with Deep Tech.

5:50 All right, so, like Aaron, I'm going to riff just a little bit off of what I had originally planned. I think that's the benefit of coming in a little bit later in the day, get the benefit of hearing everybody else's talks and kind of getting some additional ideas on top of that. So, I want to throw out what I feel like is kind of a little bit of a provocative question. I, I met, the, Ashley and the Lumi Security team, like, 3 years ago, at a different conference, and, kind of, synced with them really early on with the whole idea that, I didn't… I've never been a fan of humans being the weakest link, right? So, I think that there's a lot to be said about, when they're the weakest link and when they're our greatest asset, but when they're not our greatest asset, when they're causing us problems, the provocative question I want you maybe to consider is, whose fault is that? Is it their fault? I mean, that's an easy… that's an easy out, right? It's their fault they're being lazy, or they're indifferent, maybe they're malicious. You know, that's not very often, but sometimes that happens, right? Is it security's fault? Are we giving them bad advice? Are we not giving them good directions that they can use? Sometimes, yeah, that happens.

6:55 Maybe it's the process owner's fault. That works in the department that they work in. Maybe it's the leader's fault in that department who's never taken a look at those processes and found out, is this a process that works for them? Is this secure? Why are we always getting nastygrams from security when we can't do what they're asking us to do, because our process tells us that we can't. But this is the way we've always done it, right? So, this is just our process. It is the way it is. Well, processes can change. Yeah, and Jim, maybe I'd challenge you. Not only their fault, their opportunity. Let's do the feedback as a gift thing, and swap it into an opportunity. Exactly right. Alright, so this is gonna start the interactive part, so a little bit of background, we're gonna walk through, kind of, where processes can bleed, and if you guys have been… how many of you, show of hands, have you been in, like, a risk management role, done risk assessments? Third-party risk, I know I was talking to a few, so 30% or so have some crossover skills, that's awesome, because I think that can help you. So what we're going to do is we're gonna walk through a common process And it's one that we already know there is risk, because there's a lot of targeted attacks, and it's accounts payable just to seed the clouds a little bit. But regardless if it's an accounts payable process that we're analyzing, or a research and development.

8:13 candidate selection process for advancing advanced molecules, now I'm talking about my old role, in pharmaceutical, into the clinical study pipeline. Crown jewels. Those are two very different processes, but they all break in the same spots. So, five things. This may not be fully inclusive, but it's where we've seen most of the process gaps and the workarounds. One, the process steps. Are they undocumented? You'd inherited it from Joe, who you took over from the job. You're kind of winging it. It's different every time, there's nothing down on paper. That's the easy one, right? Like, helping to get that cradle to grave, where does the data go, and how does this process work? That is the starting point to working and partnering with your business partners to help them understand what's going on in the context of how they might get social engineered. Secondly, approvals. So, I think in the Ashley video, for the deepfake, it was kind of pushing, like, hey, I need this approval, there's no time, it's urgent, you know, classic techniques, but that deadline under pressure, and trying to trick the person into maybe skipping some of the steps that they might do, or the hesitance and double-checking something, because it's, it's the CEO. Handoffs, cross-functionally, going between departments.

9:27 big… if you're part of a big company, I know we have several big companies here, very little business processes happen within one group. There's a lot of… you know, big processes that have small little working pieces and lots of handoffs. Handoffs can result in oversharing, that kind of translates into access issues. How many teams have had SharePoint sites owned by the business that it's pretty open access because there's so many people coming and going? And before you know it, you've got all your crown jewels there. And then lastly, third parties, because a lot of our companies outsource specific pieces or steps. you've got to worry about third parties and identities and how you're interacting with those as the process is going. So that's the setup. Those are the clues that you're looking through. Jim's going to walk us through the process, and we'll do a little live Q&A of where you guys think some of the breakpoints are. Alright, so here's our process. We've got 5 steps. This is an accounts payable, kind of scenario that we're working through with this process.

10:25 So, what we would like, is, if you see a part of this process that stands out to you as one where there is an opportunity for an attack to be leveraged against this, if there's a vulnerability here, Call it out. Don't be shy. I mean, it's, it's, it's, you know, everybody can… there's… nobody needs to raise a hand. This is where you might win the prizes. Yes, yeah. Alright. So the first step, in the process, the, request arrives, it's an email. It's marked urgent, of course. Arrives, from the CEO to accounts payable. Alright? That's what gets the ball rolling. Step 2, the requester is verified. The CEO calls and leaves a voicemail for accounts payable, requesting the same payment. Now, you already got an email. It's urgent. And then you get a follow-up voicemail.

11:22 Okay? Anybody see any issues yet? Oh, yep? Classic fishing plus deepfake combo is what he said, so, yes. Okay. So step 3, request approved. The approver, the, the accounts payable analyst, signs off and adds the new vendor. well, they got the email from the CEO, right? It's urgent, it's gotta happen fast, and then you gotta follow a voicemail that it sounds like your CEO. Better do it. Okay, payment gets released in step 4, approver releases a payment, and then step 5, reconciliation. Okay? Any… raise your hands if you… we don't have to talk about them now, a few more holes in the process? Any other gaps? On Step 3, you have a single unit to approve that is already deceived by Steps 1 and 2, then step 3 is autonomously doing a foolish thing that a two-person system… The lack of a segregation of duties on that vendor ad, yep, vendor master, yep.

12:27 Good, anything else? Alright, let's make it more complicated, and let's assume we were analyzing this 10 years ago. The deepfake comment probably wouldn't have been front of mind, because that wasn't really legit. And how many of you… we do a lot of deepfake end-to-end with real executive simulations. How many people have had the… opportunity to train their employees that deepfake, both voice and video, can be live in real time, in Teams. no out-of-band videos sent. Does that, like… We still are seeing about 50% of even cyber people that are seeing that, and I know we chatted earlier, you're doing some of that advanced training, which is awesome. But there's still, you know, a catching up knowledge. A lot of people were stuck on Deepfake being for political campaigns, and it's a video created in some lab. Post, or prior to the incident. Let's keep moving, let's, and I… here's my voice, get a good sense of it, because the next part is the, the guessing game of which is real.

13:28 Alright, so… We have a voicemail, alright? Let's take a listen to the voicemail, and see if we can figure out which one of these is real, and which one isn't. Hi, this is Aaron. I hope you saw my email. I need you to go ahead and approve the payment for the Austin, Texas project. We are looking to get that support rolling this week. I appreciate your help on this. Alright, that was voicemail number one. Hi, this is Aaron. I hope you saw my email. I need you to go ahead and approve the payment for the Austin, Texas project. We're looking to get that support rolling this week. I appreciate your help on this. Alright, any guesses? Alright. Who says… by show of hands, who thinks that voicemail 1 was real?

14:23 Okay, got a few, alright. And by show of hands, who thinks voicemail number 2 was real? Okay. Who doesn't know? Oh yeah, that's, that's, yeah, that's a great question. Right. Okay. So… For those of you who thought that voicemail number one was real. You have a very keen ear. Those of you who thought number 2 was real, you might need a stronger process. Alright, cool. A little bit of fun with this, so, this specific audio video, we've done a lot of real-time and… like this one, we wanted to… we didn't want to wing it on stage with a mic and a separate translator, but you can do that with the audio real-time fake. It was created with less than 3 minutes of video, the team ripped it off of my podcast. That's how they got my voice. And then, this one was a commercial tool, so you can get a lot of open source tools as well to do it and do scarier things with it, but this one was a less than $20 tool. And then within the process that we showed you, there was zero controls. One other sidebar, and we did a podcast on it a few weeks ago, with some of the Agentic technology, the one that I played with was VAPI, V-A-P-I, you can use a 11 Labs voice fake, and create an agent, and then with a prompt, which I use Claude, create instructions to make calls on your behalf, and do it at scale. So just as a test, I… tested it with one of our marketing people, and then Jim, and had them receive calls that came from a local area code.

15:59 As… as a person that we selected, and it went through the script, and it was basically… I programmed it, again, within… it took 20 minutes. Yep. In a morning, I'm like, hey, we should jump on a recording and film this, but basically it was, basically a very safe social engineer Using an agent to drive forward. Alright, we got 5 minutes. Yeah, we got 5 minutes. Too much audibles. So, Jim, break down the process for us. Alright, so, you guys are good, looking at the process, right? So we take a look at our process, and we find where our weak points are. The request comes in? Okay, fine. They're number two, the request is verified. No out-of-band verification for payment requests. Right? So, there's an issue there. Number 3, the request is approved, weak vendor master file, so anyone with accounts payable control can add a new vendor. No control there. Couple of other issues that we have, no dual-channel confirmation, not even with a high dollar first-time payment.

17:01 No invoice matching steps exist, and no reconciliation checks in place to flag an incident early. So, several areas where the process breaks down, where there's an opportunity for process improvement here. So, is anybody here an accounts payable expert? Now, was it fun and helpful to kind of break this down? I think one thing that I'll say, and I don't know if we'll get to the slide. doing this exercise and having the process owner grab the pin from you and say, okay, let me start drawing, that is the sign of a win. That is the workshops that we feel go the best, and they start seeing the problems. You give them some scenarios, like the deepfake one, and they start to think about their world differently. Let's skip that one, that's a little bit of a redundant. Yep. Go quick on this one. This is a story before Living Security and HRM data existed, and I'm so excited that now, you know, 10 years ago, when I was on the corporate side, we were using DLP on the R&D Secrets post the insider threat FBI arrest.

18:01 to look at other signs of exfiltration where individuals were taking intellectual property of scientific value. Very hard for DLP. It sucked at it. 10 years ago, it probably still sucks at it now. But at the end of the day. we, with DLP, we identified key areas and key processes that were lighting up, and we were able to go through and find overprivileged situations, too many handoffs, third parties that didn't need to be involved, and literally, in this case that I'm talking about, go from 21 touchpoints to 5. And that actually provided business value, and that they… their process went faster, and security took the win. So there's a lot of examples like this. Now, with living security and the data, we're able to say, okay, now we're not just tackling the known high-risk areas that we know have things that we need to address with this. We're able to see some other pockets, or say, you know what, this… Group over here was interacting with this high-risk function that we had no idea, so we're super bullish on that.

18:58 Alright, I'm going to cover this one quickly, but I don't want to skip it, because this is where I get really passionate about this. As we build these programs, we talk very often about building a security culture. And with the advent of human resource management platforms like Living Security, bringing the information to our attention and letting us focus on some of these areas where these processes may be breaking down, and we have an opportunity to go and interact with those other areas of the business, we have the opportunity to build relationships with other areas of the business and get out of our security silo, get into those other business functions, and really start to build that security culture. And the whole organization. And that's a huge step if you can get out of that kind of security silo and start to build those bridges with other areas of the business. And this is not fixing it for them, it's fixing them with them, and taking the data that's 100%. You might have an opportunity here, not a problem, to make this better, and by the way, let's get in there and make it better for your business as well. All right, real quick on this one, this is not saying you don't need training. This is still important for the masses, I think that's been consistent with other messages. Still important with training if there are one-time behavior shifts, new tools, things you need to get out, but if you're seeing the same thing recurring over and over.

20:08 bypasses are happening, that's when, really, this technique can happen. And we do have a job aid giveaway here, so two last slides. One, this was an account… this was a payroll process that I did, I think it was, like. a year after COVID, when things were just starting to open up. It was a smaller company, but working with the CEO, driving out. I started with the marker, you can see my sloppy handwriting. He took it, drove it out, had a bunch of changes, he was like, this is literally the best. use of time from a cyber standpoint that we have talked about, and we talked about no cyber controls. It was all what my employees can do, and how we can shift the process to be better. Alright, as promised, last slide. QR code. We don't have any salespeople, so I'll promise that no one will be hounding you. We're all word of mouth and a boutique, but if you want to grab our Secure Process Design Worksheet, it's just two pages. Doesn't give you everything, but it's really a way to think about this, it's a good starting point. And then, yeah, if you have any questions, Jim and my email is here.

21:10 We like talking about this stuff, we think there's a lot of missing opportunity in the HRM programs and field to drive this action that gets you credible experience hands-on with the business. Yeah, the last thing I would like to say is, if we really want to make the human element, that human part of our security stack. the… our front line and as capable as possible. We have to take care of them, we have to set them up for success, and they can't do what we're asking them to do if they're stuck in a broken process. Awesome. Thanks, everyone. Thank you, Aaron and Jim.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.