On-demand session · 29 minutes Recorded live at HRMCon 2026

Getting buy-in: building the business case for Human Risk Management

How a Fortune 5 security team funded and scaled HRM — the framing that worked with executives, and the numbers that carried it.

Damon shares how CVS Health built the business case for Human Risk Management — the framing that landed, and the numbers that carried it.

Damon DePaolo speaking at HRMCon 2026
Damon DePaoloCVS Health
Full session · 29 min
Why watch

The program is only as strong as the budget behind it.

Executives don’t fund activity. They fund reduced risk, protected revenue and fewer incidents.

Damon shares how CVS Health built the business case for Human Risk Management — the framing that landed, and the numbers that carried it.

What you'll learn

In 29 minutes, you'll walk away knowing:

Positioning the program around business outcomes, not security jargon.

Which metrics earned attention — and which didn’t.

Turning an approved budget into a program that grows.

The stakeholders that make or break buy-in.

Speakers

A Fortune 5 security leader on funding HRM

Damon DePaolo

Damon DePaolo

CVS Health Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:09 Alright, so let me get this straight. It is Toothless Smile. Open posture, feet forward. You guys feel welcomed? Alright, good. I got it? I got it. Alright. So, security awareness has a crisis of credibility. For decades, we have been asked to provide compliance-centric information to our leadership. Have people taken annual training? Have people completed phishing simulations? Is our click rate kind of low? That's all that's been asked of us. But as we've been hearing throughout this morning, those questions are changing. We're being asked more. We're being asked to define and prioritize risk. To show that we can reduce risk. But we're not equipped for this. We've never been equipped for it, because we've never been asked to do it before. In order to do it, we need things that we've never had to have. And that's where our credibility crisis comes in, because when we go and ask for those things.

1:06 We're asking for things that people don't necessarily believe we need when you compare us to other traditional technical security functions. So what I'm going to talk about today. My name is… Damon DePaolo is my monitor up. Okay, there we go. My name is Damon DePaolo, I work at CVS Health. I have had the opportunity to build two human risk management programs, one at a large financial services company, and now the one that I'm building at CVS. And through that, I've had to navigate this credibility crisis in order to get the buy-in to move forward. I'm gonna talk about… a little bit about that experience, and then I'm gonna talk about some of the lessons I've learned along the way, so as we're all working on building out our human risk management programs, we can take some of those lessons and hopefully address them up front to get the buy-in and support we need. So I'm going to start today by talking about the human risk management moment we're living in a little bit. It's important to level set. This is gonna be something that comes back time and time again while I'm talking to you today. It's really important to make sure we're all coming from the same page.

2:05 Then I'll jump right into those five realities that I've learned through my two experiences building out human risk management programs. That I would really want to make sure I addressed up front if I were to start building a third. I'm gonna lay out a high-level roadmap, again, if I was starting on Monday at a new company, from a new compliance program, trying to build it out into HRM, these are the things I would start with, and this is the flow I would go with, and then I'll leave you with some small takeaways that you can work on. So let's get that level setting underway. As we all know. We've traditionally been asked for those compliance-centric metrics. Has your training been completed? Are you running simulations? What's that look like? Are people clicking? Are people reporting? I mean, we do those really well. That's been established, it's foundational, it's important. Even when we start to move, you have to have those foundational elements, if for no other reason, than to fulfill regulatory compliance. But we've seen increasingly recently, over the past two to four years, I'd say, leaders are coming to us with completely different questions.

3:08 They want to know, did that annual training actually address the risks that we face in our company? And… Did it help? They might come to us about our phishing program and say, well, are the phishing simulations you sent, are those relevant? Are those really addressing the things that people are experiencing day in and day out? And the fact that people are reporting it, does that mean that they're less likely to click on something real? Or they might come back to you and say, alright, outside of phishing, like, where's our highest risk? What are people doing that's problematic? Are we leaking a lot of data to free mail accounts? And how are we training people not to do that? Well, that question is one we can't answer. We can come up with answers for the other stuff. probably stretching a little bit. Like, yeah, our annual training is aligned to our most important risks. We think. But until we can really aggregate data together and look at the behaviors across our organization in a meaningful way, we can't answer those questions, and that's what human risk management has grown up to fill, that gap.

4:11 So, like most people, when I was asked those questions, or many people these days, I should say, when I was asked those questions, I decided, I'm gonna go out and I'm gonna find a platform that's gonna help me build HRM functionality into my program, and it's gonna be great. And this is what I thought it was gonna look like, because I have about 7-8 years in security awareness and human risk management. I have 26 years in aggregate in technology. I've went through a lot of technology implementations over my time. And those go pretty straightforward. I'm gonna find a platform, you know, maybe do some RFPs, do some POCs, grab a platform that I love, gonna bring it in, I'm gonna connect data up, I'm gonna surface whatever that data tells me, gonna throw it in a dashboard to show to leadership, and say, this is what I'm gonna impact, this is what I'm gonna make better, train some people, and I'll show them trends. That's what I expected was gonna happen, especially the first time I went into this. Sounds really simple, right? Finding a platform partner was not that hard. We have a really great one here that many of us have talked to in the past.

5:06 And that did not end up being, by any means, the critical path of my program builds, either time. What the critical path surfaced as being was… alignment. Right? Alignment on what human risk means. Because let's be very honest, and we've heard people talk about this a little bit today. If I ask my CISO what human risk is, and I ask my insider threat team what human risk is, and I ask my privacy team, my legal compliance team, my HR team, what's human risk, every single one of them is going to come back with a different answer, and it's probably going to be different from mine. And then when I go out for those RFPs. All the vendors that come back to me are also going to define it differently, because there's no common understanding in our discipline on what human risk management really means. So it's important when you start out on this journey. That you look into defining that, right? So that was big, getting alignment there. Getting alignment on what we can have access to, getting alignment from our key stakeholders, getting alignment on what insights people wanted really ended up being the largest critical path in both of the projects as I went through.

6:14 And a lot of that doesn't show up when you're getting those upfront vendor demos. People aren't pointing you in that direction when you say, this is what I want out of an HRM platform, you know, they just sell you their enhanced fishing platform, and you're good to go. So you have to cover these bases before you get going, so that you know what it is you're looking for. So that surfaced my five hard realities, as I'm gonna call them, of implementing a human risk management platform. And that's what we're gonna spend most of our time right now talking about. I'm gonna start with the first three together, because there's a lot of continuity here, and I did start to talk about that shared definition already. It is really important that before you take a step towards building out a program, you have this common understanding. Start with your security leadership. Make sure that the questions they're asking you align with how you're going to define human risk management in your strategy. in your proposals, in all the language that you're using. Once security leadership is on board, start to go out to those other stakeholders. Privacy team, this is what we want to do, this is how we define security human risk management.

7:17 Do you agree? Do you see any challenges there? Is there anything that you think I'm not allowed to do because of where we sit in the organization? Get through those conversations. Once you have that shared definition within your organization. Then you go out to those stakeholders and a broader level. and start to really say, this is what we're doing, this is what leadership has agreed we're authorized to do, this is how we're going to move forward in building out our human risk management discipline. And this is what I need to eat from you. Are you on board? Right, so that's getting that privacy team, the legal team, the compliance team, the other security organizations to say, yes. We agree this is your responsibility. And we are going to support it. And then, expanding out into your… further into your security organization, going to the owners of the data that you're going to want to aggregate in order to do this, and saying, hey. I've never asked him for data before.

8:13 I just want to remind you, like, we're brothers. I'm security, too. So, I'm gonna need this. Do you support that? Do you recognize that it's okay for me to access this data in order to achieve this responsibility that we've all agreed to across the security organization? Make sure that you get them bought in. You go through the due diligence of letting them understand what you're going to do with that data, building trust in your ability to utilize that data. So that when it comes time to really lay it down and ask for it. They're there for you, and they're not going to be a blocker. Once you've started to have those conversations, and you get those people bought in. I want you to go back to him again. and say, okay, now that you say I can have your data, what's that look like? What behaviors are really surfaced from the data that you own? If you're talking to your DLP team. What can I actually find from the tools that you have? Is the data noisy? Do you get alerts, disposition it, and put it back into that system so that when I consume it, it's the final understanding of what that data is?

9:16 It doesn't mean you may or may not want to take it, but you have to know it. You have to be very clear on what data you're going to bring into your future state. So that, when you bring it in, you know exactly what insights you can surface, and how you're going to act with them. We know, right, across security, we have no lack of data. There's a lot. It's noisy, it's busy, it's confusing. So getting this clarity up front is gonna make sure that When you take that next step. into finding vendors, finding partners, building something internally, whatever it is you're gonna do. You're focused on the things that you can actually influence. Okay, reality number 4. You may be asked for a human risk score, or you may be asked for where your highest areas of risk are, but I promise you, your CISO didn't just wake up one day and think, I want another number to put on a dashboard.

10:11 Because they have enough numbers on dashboards. And they want anything they put on there to be meaningful. So, when you're looking for what you're going to do, how you're going to build, where you're going to bring it forward, it is critically important That the number you present is one that you can action upon. And that you have every intention to action upon it, so that when you give your security leadership that number back, whatever it looks like, a human risk score, a specific behavior score. You can also say, this is what I'm going to do about it. This is my baseline. These are the actions I intend to take. And I'm going to come back and prove that my actions are reducing this risk. If you can't do that, and you're not ready to do that. you're not necessarily ready to move forward into human risk management. So you have to figure that out in advance, make sure that you're clear on what's going to comprise any risk scoring that you're going to do, what's going to go into those dashboards, and are these things that you have the capability to action upon in order to reduce the risk?

11:15 And finally… Reality number 5. Year one is all about small, proven wins. This one, I learned the very, very hard way the first time I built out a human risk management program. I… this was early on when this was… this discipline was really start… starting just to kind of gain traction. happily early adopter, and said, I'm going to connect every data source I possibly can right now. And back then, I was in a company I'd been in for a very long time, I had lots of personal credibility, so people said yes a lot more easily than if you're starting this from scratch. So we connected a whole bunch of data inputs into my platform, and my goal was not to worry about those other things that I just said, rules 1 through 4, My goal was, I'll connect all this data, and then I will be really forward-thinking. I'm gonna let the data tell me what the problem is. I'm not gonna go in with any preconceived notion.

12:11 It sounds really wonderful, and the data will tell me what's wrong, and then I'll be like, hey guys, this is what we see as a problem, so, like, aren't you proud of me? I've identified new stuff, it's not phishing! Okay, so we did that, we tried that. The data showed us a problem. It was all about, you know. Website visits, blocked website visits, was what kept coming back, time and time and time and time and time and time again, because that's a really noisy system. So, even if we weighted that problem low in the system, in our aggregator. what it surfaced was always a high risk in that space, right? There's so much action happening here. So we kept trying to figure out ways that we could influence it, and having conversations, and saying, this is what the data's showing us, and it ended up just being a rabbit hole that we did not need to go down. So… when I went through this again a second time, the first lesson. that I worked on was my fifth one, right? I came into it with the new knowledge of, okay, year one's about small wins. Let's be really purposeful about what data we bring on. Let's have some of those conversations up front, see what we can get access to, inventory all the signals that we have available, and say, what are the ones that are really sort of important?

13:21 That we can really confidently say provide us meaningful insight into something that people are doing. And we'll just bring those ones on. We'll leave the other stuff until we've established a really good process, we've established that credibility that we've been lacking, we won't be going to people saying things are a problem that won't, because we'll know it's with nice, clean data sources, so then the next time we come to them, they'll have trust in us, our platform, and the data we're presenting out. So it's really important, moving into your program, to think about small, proven wins. This is when you start to reach out for vendor demos and RFPs and making sure, because now you have a shared understanding of what human risk is, you need to share that with the people that you're going to look at to help you solve this problem. you have… Stakeholders that are on board, so they're not gonna block you when you get to that point where you're starting to connect data sources. You have a clear understanding of what data you have available, and you know that you're going to take intervention on it. Now I can talk to people, because you want to tell that story in your RFPs, right? When you go to a vendor, you want to say, this is my expectation of a human rights management platform and program.

14:27 And I need you to be able to support this, because I promise you, if you don't, what you're gonna get is a half a dozen really fancy phishing platforms that call themselves human risk management, trying to solve problems that you're not interested in. You being clear before you take that step, before you reach out. It's going to really make sure that you get aligned with the right partner, the people that understand How to categorize the risk in your organization. How to surface that top 10% risky population that's causing the most problems. And how to intervene with them. Potentially, not through phishing simulations. Okay, after you've… built that trust by doing a couple small wins, partnering with an organization within your group to do something that's really great, you're gonna move on to demonstrating the value. So. It's really important, again, especially when you look at the first elements that you're going to want to go after, to find an organization within your security team that has a problem that can be solved with people.

15:25 Okay, what this might look like, and this is an example that isn't actually going to get back necessarily to a direct tie-in to risk, but it's going to show value and build credibility. So what this may look like is working with your security operations center and saying, what's a pain point that you have? I did this once. They came back with DLP and free mail, right, sending stuff out to free mail. And I said, okay, let's talk about this more, let's unpack it a little bit. Let's talk about what challenges you're having there, what's the baseline frequency that you see this happening? And we couldn't really come to a data picture that helped support it. It was anecdotal, they knew it was a problem, they could feel it was a problem, but they didn't have the data yet to give me. Well, that's not a good first option for me, because if you can't really categorize your issue, I might not be able to right away, and I want to make sure that we have a win together. But through conversations, what did come out was that When our security analysts logged in in the morning. They were oftentimes really frustrated by a queue full of misreported spam emails.

16:22 People using our report phishing button as a spam filter. Okay? Now, is that a risk in and of itself? Maybe not directly. I will say, when a security analyst has to go through a whole bunch of garbage in their queue to get to anything that might be real, that presents a risk. It's also a lot of wasted time, a lot of wasted brainpower on stuff that people can be focusing on real, valuable incidents for, right? So we said, let's tackle that. Let's look at what we can do about understanding the volume of misreporting that's happening, and then we can take that as an education thing, no problem. Tell people why that's not valuable for them. You don't want to use a report phishing button as a spam filter, because you're going to keep getting spam. We have other tools for that. Here's how you use them, here's how you differentiate. Let's get more precise on what you report, and increase that precision, and that becomes the metric now that we want to track with our HRM platform. How can we increase the precision of what's being reported to our SOC in this space and reduce the noise?

17:22 Once we get there, we get to demonstrate value. This is value that any leader in an organization will immediately understand, because this is dollar value. This is people hours. When we can say it takes 20 minutes to disposition a misreported spam, and we just decrease that by 60%, Like, that's money in the bank. That's people being realigned to really important work that we're wasting time. And then once you've been able to demonstrate that picture, you continue to iterate. Year one is all about iteration, growth, and building credibility. Once you've built that, then you can look at accelerating the data that you bring in, taking on data sources that might not be as clean, that have a little bit more question in them, because you have some solid foundations, you can pay attention to what you're doing, and you can start using the AI tools that are available to you to make sense of some of that noise that might be a little bit dirtier. And continue to grow your program. And I think it's also important, I put across the bottom of the slide, one thing to start talking about from day one when you're going into this is some behaviors you can move in a month, two months, a quarter. Some of them take a long time.

18:26 So, target early on the ones that you can change quick so you can demonstrate value, set the expectation that there are bigger things that are going to take longer to fix, and we'll get to them. But we need your support and your buy-in to continue doing this. Okay, so I promised a high-level roadmap. If I were to start Monday. Very high level, because we only have so much time here, and I want to make sure that we're being good about it. And I do have an appendix in these slides that you all get later on, so you can kind of dig a little bit deeper into these steps. But this is how I would do it. I would start off by defining what human risk means, get that alignment, get that agreement. I would move on to inventorying the data and signals that I have available, starting with what I own, and then moving on to what I have strong partnerships with, and what people have problems aligned to. After we've had those signals, I would move on to identifying specific populations aligned with those risk signals, and see, are those risky populations? Anecdotally, if we have to, to get started. Pick one. connect action to that insight, measure the impact, and start to grow. I know it sounds very simplified.

19:28 But it's the way that you get support and you get buy-in from your leadership by demonstrating success. Remember, this is new to them, just as new to them as it is to us. And when they're asking for things, they might not know exactly what they're asking for, so we have to help show the way to that next stage. I would be remiss to not talk about AI. So, where does AI come into play? I see 4 really great ways that it can be helpful when you're trying to build out a human risk management program from the start. One is obviously, as you're pulling these data sources together, many of them have lived in their separate worlds for a very long time. People might be adjusting access based on just what they have in their access management platform. They might be, you know, changing people's email habits based on what they have in the email platform, but they haven't been brought together necessarily to look at, from the human behavioral perspective, what to do. AI is really great at helping surface some of those patterns that would be in that disparate data as you bring it together.

20:27 Obviously, I think the one that everyone talks about in the security awareness, everyone's very comfortable talking about, is drafting things and summarizing. Why I say this is important while you're building out a human risk management platform is because I'm guessing, and feel free to raise your hand if you feel otherwise. Most security awareness programs are resource constrained. We don't get a lot of people thrown at us to do extra work, so we still have to run that compliance program And we have to build this new HRM program, and probably aren't going to get a lot of extra resources to do it right away. So… Being able to use AI to draft the trainings that you need to do, to manage the stuff that you have in your compliance queue, to build those targeted interventions that you're going to have to start building, it's still the same people that are trying to do all of this, it's just added work. So utilize AI to help maximize your efficiency in that space. And then also, as you're putting together new reports, as you're trying to summarize your insights in different new ways to be put up to leadership, it's a great tool for that as well. Just remember.

21:26 At the end of the day, you gotta review it. It's your name on it. Scaling without headcount kind of goes along with those first two, so just increasing the efficiency of your team. Most importantly, at the bottom. It's all about tuning. So, as you have approved AI tools in your system, use them to turn it upon your HRM program to make sure that you're putting in content, interventions, and activities that align with your organizational needs. We talked about it earlier this morning. Load your policies into it so that all your trainings align to your actual policy language, so that you're really teaching people not what's in a generic module you brought from some vendor. But what aligns to your company's expectations? Turn that AI product back on your program. You've implemented a couple of data sources, you have some behaviors that you're trying to track down. Have your AI analyze the signals that you're getting, and identify gaps where you might want to integrate new data to better flesh out the behavior picture for what you're trying to reduce. Utilize it as a tool to enhance your program, to grow your program, and to be that thought partner that can bounce ideas back and forth with when you might not have enough resources to do it with another member of your team.

22:37 Okay, and to wrap before we go to Q&A, Simple steps that you could take tomorrow. Now, I've been talking a lot about people who are just starting to build a human risk management program, or getting in those first steps, but I think these actually apply to anyone that has an HRM program, regardless of where it is in maturity. Because, whereas it's really smart to do these things up front, it's also a great idea to just take a step back at some point, periodically, and say, do we still have agreement on these? Do we still have these covered? So, Monday. When you go back, if you're in this boat and you're looking to build something, step one. Set up a meeting with your key stakeholders. And say, let's talk about human risk. What does that mean to you? Here's what it means to me. Come with a definition, get feedback, get people to talk about it. And go back and forth until you can agree on A real common understanding. Once you've gotten there, have the conversation around who owns what. Some of it might live with us. Some of it might live with HR. Some of it might live with insider threat.

23:35 Understand where your realm is, so that you know that you're operating within it, and partnering when stuff moves outside of it. Step 2, start mapping the ownership of the data signals that you have access to. So go out there and make a simple grid. What data do I have? Who owns it? Is it me? Is it somebody else? How clean is it? What behavior signals map to that data? Get that grid ready, get it in pocket. Identify gaps for things that you want to do, where you don't understand the answers to those questions, so that you can go chase them down. And then, step 3, find that partner that has a pain that you can address. Talk to your SOC, talk to your DLP team, talk to your GRC team, whoever. Start talking to other security teams to see who has a pain that can be fixed with human intervention. That you feel like you can make impact on. And then dive deep into what that would look like and get their buy-in to be a supporting partner, so that you can prove something out.

24:31 Provide real value, and start to scale. And with that, I'm open for questions. Thank you, David. You have quite a number of questions online, so… Oh, no, you have 2 minutes, that's all you got. Oh, wait, sorry. You're actually right, you have about 2 minutes, so… Kidding, so we've got, we'll go on for 4… 4 more minutes. So, the question is, I'm working on stakeholder alignment, but other departments like HR, are hesitant to give me their data. How do I overcome that? Well, step one is trust. Right? So, and we talked about that a little bit this morning as well. It's really important to establish trust in how you're going to utilize the data. I also recommend minimizing the data that you have to take. Sometimes, when you look at connecting with other platforms, defaults may be a little bit over-permissive for what we actually need, so refine down your ass to exactly what you need to accomplish your initial goals.

25:33 Once you've established that, re-engage the conversations and say, okay, I can do this job with just this data for now. as we expand, I may need more. If you're working with an HRM partner. you know, work with them to understand how they utilize the data, how they store the data, how they disposition the data when you're done with it, and make sure that that's all being communicated to the appropriate people, because obviously, I mean, we're in security, right? It's really important that data security is paramount in everything we do, and if we can't speak to that trust, if we can't build that trust, and try to build credibility off of it. It's hard for us to say that we're We're really good security partners. So, minimize it to just what you need. Address any fears that they have that they express specifically. And then, re-engage the conversation. Great. Kind of related, what are the signals or data sources that are most valuable to look at first? So that is a question I cannot answer for everybody.

26:32 Right? I think that every organization has different priorities. And, moving from a financial services organization to a healthcare organization, I was able to see this firsthand. Things that we thought were important here. That I thought I'd come in and say, okay, here's some really important stuff to start with, turned out to not necessarily be. So I think that's a question that you have to surface through those conversations with your key stakeholders. Have really meaningful conversations about the pain points they have. And which ones relate to human behavior. And then you can help to prioritize the data sources to go after. Awesome. Thank you for the insights, and we have one last one. Once the program was funded. How did the conversation shift from measuring risk to actively reducing risk? That is a great question. So, that comes down to the small wins, right? Once it was funded, it became incumbent upon me to then say, this is how we're going to provide value. This is how we're going to reduce risk.

27:31 So, have that ready to go. as you go into those conversations. And you have that ready to go by doing what we talked about. Getting the alignment, understanding where your pain points are, and understanding where you can have influence. come before you start implementing platforms, before you move into proof of concept, because you could use your proof of concept to show that value already, with ideas as to how you're going to actively reduce risk. I'm going to baseline this, I'm going to intervene like that. And this is how we're going to measure to prove if it's working or not, and then adjust if we have to. Not everything… the other thing I'll say is not everything is going to be successful, right? Some interventions are just not going to work how you expected them to. That's okay. We're iterative. We're… innovative people. We can adjust and change how we approach things, so be clear about that up front as well. My first intervention may not reduce risk, but that doesn't mean we're going to stop trying, it means we're going to learn why it didn't. and then try a new tact. But I think that's something that we have to drive that conversation when we have these programs being built. It is our responsibility, it's our strategy, it's our program, so we should be the ones that are saying, this is how we're going to reduce risk.

28:36 Well, thank you so much, David. Thank you.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.