On-demand session · 33 minutes Recorded live at HRMCon 2026

Define your program: naming your enemy, the incident, before you build

Three leaders on defining the measurable outcome first — the specific incident you intend to prevent — then building the program backwards from it.

Scott, Taylor and Edna share how they define the outcome first, then work backwards to the people, signals and interventions that get them there.

Scott L. Miller, Taylor Lindell, Edna Conway speaking at HRMCon 2026
Scott L. MillerNavy Federal Credit Union
Taylor Lindell
Edna ConwayEMC Advisors
Full session · 33 min
Why watch

Most programs start with content. The strong ones start with the incident they intend to stop.

If you can’t name the incident, you can’t measure whether your program prevented it.

Scott, Taylor and Edna share how they define the outcome first, then work backwards to the people, signals and interventions that get them there.

What you'll learn

In 33 minutes, you'll walk away knowing:

Defining a measurable outcome before choosing tools, content or cadence.

Turning a broad goal like “reduce risk” into something specific enough to track.

Mapping the people and behaviors that lead to the incident.

Reporting the outcome, not the activity.

Speakers

Three leaders who build programs backwards from the outcome

Scott L. Miller

Scott L. Miller

Navy Federal Credit Union Follow on LinkedIn
Taylor Lindell

Taylor Lindell

Follow on LinkedIn
Edna Conway

Edna Conway

EMC Advisors Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:10 Welcome, everybody. My name is Kevin Martin with Living Security. It's a pleasure to be talking with y'all. Please get a seat, get comfortable. Beats that are hard to get on, right? All people here. You look great, you look great. Alright, so Edna, I'm gonna come to you in a moment. So, in my role at Living Security. Without exaggeration, I've had the pleasure to speak with hundreds of enterprises over the last 4 years. Literally thousands of small conversations with people thinking about human risk management. And when you have a human risk management conversation with somebody. Thank you. Oh, I got a clicker. Alright. When you have a human risk management conversation with somebody. With today's marketing and vendors that are out there, it really varies. That conversation could be, I want to talk about advanced fishing. Two, I want to talk about orchestrations and automations and insider risk. And I often have to say to them.

1:09 What outcome are you driving for? What's the problem you're trying to solve? Do you have an enemy? Is there a risk? Is there an enemy that you're actually trying to get ahead of and preempt? And if you can share that with me. Then we can teach you how to have a strategy and use the platform to achieve that outcome. So what I'd love your insight with. And, talk to me about… when people are thinking about HRM, what should they be thinking about? Is there an enemy? What should they be focusing on? Yeah, I think they should be focusing on exactly what business exists for, right? We exist to serve X, whether we're for-profit, and it's… Our customers and our shareholders, whether we're not-for-profit, it's the constituents who we serve via our mission. Whether you're in government, it's the citizens who you share. your mission with, right, and serve. So… For me, it's about resilience.

2:07 And… I think we need to start talking more about… I love the line, the unified workforce, because that really is where we live today. And sometimes, we forget, however, that word, human. So at the end of the day, it all stops with us. And you've heard me say this more times, I think Ashley's sick of hearing it, but I'm going to keep reminding everybody The technology is here to serve who? Us, the humans, not the other way around. We invented it. We're using it, And we damn well better be able to understand what it's doing and control it. Well said, very well said. And I think, not only is the technology here to serve the human, from a business approach. you need a strategy, and then use the technology to help you get ahead of it. Scott, talk to us about, from a financial point of view, what drove you to human risk? Sure. So, it's no secret, Navy Federal is the world's largest credit union.

3:08 And our motto, some of you may have heard this, the members are the mission. And what does that mean to us? Well, our primary constituents, our primary members are active duty or retired military service. So, these are people who put their lives on the line for our country, for us, and our job is to give them peace of mind when they're off doing this, that their finances are taken care of. Being that critical infrastructure for service members, being that world's largest credit union, also paints a target on our back. You know, it's great to be that big, but it also means we deal with nations. state actors, we deal with hacktivists, we deal with AI engineered deepfakes on a regular basis. So, for us, this is a problem that we can't just have a decent phishing program, we can't just have a decent risk program. We have to be best in class, because the best in class is what's coming after us.

4:08 And what's on the line isn't just a scorecard or end-of-the-year dividends. What's on the line for us is the financial security of some of the most critical individuals in the country. So it's a problem that we have to get right. As a member of Navy Fed, I appreciate that. Very much so. Taylor, probably the most important human risk is health. So, talk to us about Abbott and your journey, and what's your enemy? What are you trying to do with your program? Absolutely. We, we certainly also work for a very mission-driven organization. Our purpose is to help people live their healthiest lives, in some cases, to… to literally save lives. So very important, that we, that we protect our, our products, our people, our customers, certainly. When we think about human risk, we… we start by… with the understanding that people are our greatest risk, and our greatest asset.

5:08 And what we exist to do is empower our people to make safe choices, to behave the safely across the board. And with every initiative that… that we take on, every initiative has its own quote-unquote enemy, has its own set of goals, but when we… when we think about the end of the day, what we really want to do, again, is empower our people To keep themselves, their families, the company, our patients, our products safe. The… so we know why you're doing it, we know the focus, again, I have the privilege of speaking to hundreds of different companies, and I attend different association meetings, and what I'm hearing on a regular basis is. Probably 90% of our industry recognizes the why, of why we need to move to human risk management, why it can't just be check-a-box compliance, where we have to see the risk, and how do we get ahead of it.

6:12 But I would say 90% of those people who understand the why Are stuck in how. how do I even start this? How do I begin this journey? How do I get leadership to understand this? It doesn't really fit in this silo. Should it be insider risk? Should it be security awareness? How do I begin? So, I'd really love to understand… Taylor, you probably have the more mature program, Scott, you have a more nascent program, so how did you begin this journey? I really like this question, and my simple answer is to start with what you have, and continue to build. We heard from Ashley earlier that a fishing simulation program doesn't cut it. I think we can all agree on that. But also, I will say that a phishing simulation program played, and continues to play, a really important part in the maturity of our HRM program. We started with a fishing simulation program and an enterprise annual training course.

7:13 Again, training completions, phishing simulation program metrics do not paint the complete story. What was helpful about those. at Abbott was that they are relatively easy to understand. They're easy to understand for our employees, also for our leadership. So by starting with those two programs and really building a story around those, we got the trust of our organization, including our senior leaders. We then found that when our team, brought requests for, for additions to our HRM program, they were, they were relatively easy approvals for us, because we had already started to build the story, and we had already built trust. As a team, with our leaders, and with our approvers. So, since we started with fishing and training, we have built on many different layers of our program, that, that go in several, different directions, which I'm sure we'll talk a little bit more about, but that's my biggest advice, to just start with what you have and build from there.

8:28 Yeah, your team's done a phenomenal job with that. It's… It's a message that we speak regularly about at Living Security. The… people get intimidated by, how do I run a marathon? So they simply don't start, right? And it's… how do you begin with the tools that you have access to, the credentials, the data you have access to? How do you start with a single incident, understand the… signals that you need to monitor to get ahead of it, understand the behaviors you need to monitor, and then the ROI by saying, did I change that behavior? So how do you really start focus with an MVP, a minimally viable product, and say, let me prove value, gain the trust of leadership, and then there might be another data set and another incident that I can grow to? Scott, finance side, you guys are… we could spend hours talking about your risk journey, but specific to HRM, what convinced leadership? Why are we doing it? So… We started with a social engineering program, and we've always had a pretty robust social engineering program, but we expanded our toolset in recent years. We started doing more advanced social engineering, smishing, phishing, deepfakes, and we were able to show clear risk reduction.

9:36 we have quantified that risk, and that quantification is really what resonated with leadership. Now, as we start to look at expanding into HRM, I think it's really important to state that When we talk about HRM, we're not talking about just phishing rebranded. We're talking about all of the other behaviors, too, that influence security signals. Things you'd get from SIM tools, DLP, your privileged access management. All of this data paints the full, holistic picture around a user, and we've gotten to the point where we're classifying that risk narrative really into two buckets. You've got the active risk, the actions that the person is taking, clicking on the email, sending something outside the firewall, going to a blocked AI website that's active, and then you have the inherent risk, which is Does this user have privilege access management? Do they have access to a service account? Are they an executive staff assistant that can potentially approve something on behalf of an executive? So.

10:39 Those two different buckets really help you understand the risk that you're carrying at any time, and the potential actions that your workforce can take to make that risk worse. Thank you. The, all that data does paint a picture. I remember a previous conversation Scott and I had, you said that the data can actually show you the ticking time bomb. The data can actually show you, you know, where your team needs to be spending time and attention, how to get ahead of it. So, Edna, you're in a lot of boardrooms, a lot of conversations, a lot of M&A, We, of course, are passionate about human risk management. You've heard Scott and Taylor talk about it. But does the board really care about this? Depends on the board. I think they don't think about it From a human risk management perspective. We think about resilience of an enterprise.

11:35 And there are multiple aspects underneath that enterprise resilience. And this is an interesting question about Who… who do you… I always ask people, who do you report to? who actually picks to use living security? Sometimes it's risk, Sometimes it's the CISO. But it's not just about security now, is it? Because rarely is it HR, which is funny, because to me, how many of you have sat in a room… I mean, we've all heard this, right? People are our biggest assets. I believe that. People are our biggest problem. anybody who lives with another person, I've lived with mine for 51 years as a wife. I do for sure. Every day. But the reality is, the board says. I want you to come, and I'm not sure who presents it. I have a view on what that should look like. We can talk about that after. But, I want to know how I'm actually structuring resilience across the enterprise. If people are my biggest assets, how am I dealing with that? Most boardroom discussions today are, how much money am I spending on AI?

12:50 And what is the ROI I am getting on it? If there's any board director who's ever in a room with me who asks the question, how many people can I cut? There will be a conversation in the hallway that will not use language that polite women should use, because that's not what the technology is here for. So I think the board cares, but they… you have to fit it under the construct. I mean, Taylor, when we were talking in advance, you were like, you need to know who… who you're selling to so you can make the pitch easier, right? If you have a board member who actually calls up a senior executive or talks to the CEO and says. We need to be doing something about this, what are you doing? I didn't see it, it's missing. That's invaluable. What really gets things moving is when the board member asks that question, and somebody says. I have a tailor a Scott, you should go talk to them, because we have a plan. Here's what we're doing today.

13:51 Because my first question is gonna be. Great, what are we doing tomorrow? Because whatever we're doing today is not enough. And then the other thing the board really cares about, frighteningly enough, if anybody has ever either pitched to a board, or been told by the boss's boss's boss. I need this data, it's gonna go in a slide. I have 13 seconds to present to the board. I can only get 3 bullet points, tell me what I need to put in. The reality is we care about metrics. So if you can't show me how what you are doing meaningfully adds to my resilience. That's the reason why we started… so many people started with training in fishing, right? Because the answer was, well, if they click less, the theory is we're less likely to be attacked by that type of attack. My answer to that is, that is a great place to start, but it sure a shooting isn't enough. That's it. Underneath the resilience, think about why the company exists.

14:50 And be prepared. And for Pete's sake, start to get to know who's on your board. So many people don't do that. Very well said. Very, very well said. I remember you taught me once, if you're talking to the board, or you're talking to a CISO, a CISO ultimately needs to de-risk the organization. And so, it starts with 3 very simple questions. Can you see the risk? What risk do you see? Prove to me what you're doing about it, and most importantly, can you prove you're making a difference with it? And I think about Mike and Kelly's presentation earlier about closing the loop. And you mentioned starting with phishing and training is integral. It's obvious, right? But there are two levers. And now the industry's talking about nudging, right? You can send somebody a nudge to say you did this positive thing, or maybe this negative thing. But Kelly had a great example of, you can change their approval. their authorization. You can change their access levels, and that's where the industry needs to start thinking bigger, of as we contextualize this risk and we use it.

15:50 Phishing and training are important and integral, but they're two of the tools in your belt. There's many more that you can begin to use this data with as we move forward with. Alright, that was it. I told you I'd go rogue. Here we go! Here we go. If you think… if you think about living, and you think about what living security does in the whole context, right? And you see it in the big picture. You have a whole stack of your infrastructure, and then you have a whole stack on the security side. And heck, you might even have a… HRMS system, God help you. And the reality is, This is a tool that enables Matthew, you said this earlier, I don't know where he is, he got up, but somewhere in this room, you'll hear from Matthew Rosenkrist later today, and make sure you leave enough time for me to ask him a question, because our job to each other is to annoy one another in public places. I do think… That you have an opportunity to say.

16:50 I give you the data that allows the rest of your tools to act A, perhaps predictively, but for sure, faster, on a more informed basis. So it's this linchpin to get to, how do I make everything else that's focused on resilience better. That's a ticket that everybody should want to have. the… how do we become more resilient? How do we not only see the ticking time bomb, but have a preemptive measure in place that is able to get ahead of it faster, and moving at the speed of AI? How do we use automation to get ahead of that? So that leads to this next question. Taylor, I'm going to start with you. What if the riskiest identity? What if the riskiest user is no longer human? That's the… the question of the hour, certainly.

17:47 I'll start by saying that at Abbott, we take a very conservative approach to bringing on AI. So any AI-powered tool that can be used in the organization undergoes a very robust AI review process. Some would say too robust. Although, given what we've heard today, it's hard to argue that anything would be too much. So, our approach, then, is to really use the AI controls that are in place as our foundation for what we do next. So I mentioned at the beginning that our purpose as a team is to empower our people to make safe decisions. The same goes for how we, work with, quote-unquote, the controls that we have. The controls are in place to empower our people to be able to make safe decisions.

18:43 once, once something that uses AI undergoes our approval process, then, there, there is a level of, there's a level of, I don't want to say comfort, it's never good to get comfortable, but understanding that tool, whatever it is, has been reviewed by a team of experts. So that is certainly a starting point that, allows safe decisions. But then our, our team Is, in place to continue to enable our people to use the tool safely, to help them understand what that means. To help them understand their… their roles in it, and to help them, really, utilize the tool for… for what it's intended. I think it starts with controls, right? And, I'm relieved and happy to hear that Abbott has very tight controls over AI and how it's being used. But Ashley Rose earlier talked about often the business moves faster, and there's business efficiency, and there's goals and outcomes that need to be achieved, and the business is driving the adoption of AI. Scott, are you seeing that within Navy Fed? We are, It's an emergent field, and with any large company, it's oftentimes very difficult to keep up with the needs of the business, right? Because you have to move with the speed of the market.

20:09 And security often is the one coming up behind to close that gap. The good news is we are closing that gap. You know, you brought up controls, and one of the things I'll mention is a lot of times what we see when you start talking about AI controls is they're very focused on controlling the way a user interacts with an AI model, preventing model poisoning, prompt injection, that sort of thing. But that's assuming the model then does what it's supposed to do. So what we're looking to do is, I'm coining a new phrase, I'm going off track here too, that the next term, the next conference isn't going to be HRMCOM, it's going to be WRMCOM for Workforce Risk Management, because, essentially, if an AI agent has agency, it's acting like a person. And that means you should test it like a person. So, our social engineering team has identified some products within the organization this year that are meant to mitigate against deepfakes.

21:12 We've got a deepfake tool, so we're actually working with those teams to socially engineer the AI tool to see how… resilient it is against social engineering attacks. Does it do what it's supposed to do, under those stress environments? So we're evolving our program to that next level, treating these AI agents like people. They'll have their own scores. I think it's brilliant. And ultimately, those AI agents report to a human, right? So, who are they tied to? And then their risk score, their vigilance score, should be tied to the performance of that agent, right? That they're a collective risk. And, you mentioned, how many jobs is this gonna cut? What's the savings this is gonna bring? At the board level, at the enterprise level, what's the theory on AI and risk? I think we're moving away from that slowly, because everybody looked at it as an efficiency play at the outset, let's be honest, right?

22:12 I think it's an enabler, and so what I'm starting to see are… Are we deploying it in the right way? for the right purpose. Do we know what right means? And by the way, that can change day to day. And what's the cost? Tolerance that we have. To allow that. The last thing I think that I'll leave you with is, Look… We all understand Agents are not deterministic, but they have a mission, and they will go achieve the mission. And for anybody who dug deep into exactly what they did in the test case that was being run, all the credit to OpenAI for doing it, publicly disclosing it, and to Hugging Face for finding it. This is a great story, but it's like, oh my god, the world is gonna stop. I am not in the world is gonna end, and there ain't nothing that's taking me out. It's not gonna be AI.

23:14 And, you know, last time I looked, we still have weapons and we can shoot the devices that run all of this, so let's be honest, okay? Calm down, people. But… What we can do is we can effectively say, can I put controls in so that when things happen, I can Decrease access, because access alone doesn't mean And authorization doesn't mean I'm safe. Have I balanced the risk? So what I'm starting to do is think about a risk score that I'm testing with the NACD and the Private Directors Association. To think about how we ask the question as board members. where is my resilience, and where is my speed to stop things from happening, to shut things off? And that gets everybody in the business all excited, because at the end of the day, you point… both pointed it out, right? We want to continue to serve our constituents.

24:19 I've never met I've never met an employee who has said, I've been unable to do my job Because of what you shut off access to. Or if I did, it's because you don't have a job anymore, and you don't belong here. So, let's not be afraid. To leverage the power of… what… I like this, workforce risk management can do for us, but look specifically at agent-to-agent development, understand the way they behave, just like God help us psychologists and psychiatrists try to understand how humans behave, and I think we all need to talk to Bella Rose. I'm hoping she'll come today, and educate us all a little bit, but there's an opportunity here for us, and I think we need to be advocates, and I don't know where any of you sit in your organizations, but if you're not talking to your CISO, whoever owns enterprise risk in your organization, and if you're a smaller organization, I mean, at Microsoft, you know, I did get to talk to Satya, but even at my level, it wasn't all that often, right? It was usually a debate.

25:35 and… I think you need to do that, because you become the evangelist for, this is what resilience looks like in the future. And… I'm pretty damn excited about these metrics that we might come up with. But my ask for everybody is, be not afraid to voice your opinion on when shutting things down, or reducing access, or reducing controls, or killing them. Remember the old days? We always said, you need a kill switch in security? I like the word kill. It's an agent. I'm not killing a human. Kill it. If it's gone rogue. to kill it, to make that argument, I go back to what you said to me, I don't know, a year or two ago. Can we see the risk? So, Scott, to your point, we need to bring that agent information in, and Ashley teased that a little bit, and we'll be talking about it more throughout today, but it's how do we bring that agent, their behaviors, their inherent risk, their active risk, into the system.

26:41 reconcile that with the identity, with the human, so you can tell that story with the board. You can say, this is the actual risk, this is the acceptable risk, this is the scary risk, here is what I recommend we do about it. So it starts with visibility and bringing that in. Alright, I think I'm gonna… unless there's a question from the audience, I think we're gonna wrap up. We do. Crystal, in the back here. Okay, come on up. Questions? About how much time do I have, Crystal? Those are the questions. Okay. Whoever wants to… let me see. With Libby asking for human approval, is there a risk of alert fatigue? Taylor, what do you think? With Libby asking for human approval, is there a risk of alert fatigue? I think the short answer is yes. There's always the risk of alert fatigue, with any tool. I also don't think that's a reason not to enable alerts. That is absolutely a reason to have a plan for how they're addressed, to understand what is being alerted, which of those alerts do require action, if there's a threshold.

27:50 At which action is required. That's absolutely a critical thing to map out, because there's no point in having an alert if no one knows what to do with it. Without a doubt. And we would advocate, start with positive alerts, right? Hey, you reported a real fish. You know, build a positive culture, use alerts to do that. Scott. How do you convince a leadership that AI agents and shadow IT are actually a threat to your organization? Well, it depends on the level of leadership, and I'm going to hit on something I mentioned earlier about risk quantification. I think one of the biggest things that helped sell the expansion of this program was being able to attach dollar signs to it. Not the cost of the program, but the risk reduction. So… being able to model out the actual impact, the bottom line. So, the CISO, for instance, is going to be very fascinated on how much cybersecurity insurance they need to carry.

28:53 That's directly proportional to the amount of risk that they're carrying. So, how do you get them to believe that this is the problem, that this needs the efforts? You show them the strategic return on investment. Well said. You need the data to do it. Yep. Edna. How can we convince executives that security is not just a technical issue, but also a critical business concern. How do we convince executives that security's not just technical, but a critical business concern? Bring in 3 customers. Have the customers answer what they care about, which is availability, reliability of whatever it is that you're providing to them and its integrity, and that will answer the question. Very succinct. Well done. The, are you suggesting otherwise I'm verbose? No, I would never suggest that my lovely Italian friend is verbose. Never, never, never, never. The… okay, so this is a great, great question to finalize it, because as I mentioned, I have the privilege to talk to hundreds of customers.

29:53 And we talk a lot about how do we go to advanced, to insider risk, how do we close the loop, how do we change authorization, how do we do all these advanced things of where the industry's heading? And oftentimes, it comes back to training. Somebody says, yeah, but I need to check a box today, or I need to do these specific things, and I need to do that better. And because although we're going to start with an incident, or we're going to start with one particular thing, we need to train and fish everybody, right? So, the question is. While training completion rate isn't everything. What do you do when a third of senior leadership or management team doesn't support a role-based trading program? that's… that's real. So it's… it's something that I think most of us in this room have experienced to, to some extent, and my best advice on that is to use your enterprise training program. and have a role-based program as an AND to that. So, to really make the connection as to what your enterprise program does, and what an additional role-play pro… program can do. And I'll give a very quick example of this. Scott talked about active and inherent risk, which, isn't how… those aren't terms that I've used before, but I'm going to start, because I really like those.

31:12 So, there's… so, active risk, we all understand. Role-based risk is more inherent risk to me. So, one inherent risk in our organization, is people who have privileged access. We actually, with the help of Living Security and the data that's available within the platform, we have added a control that anyone who gets access to… has privileged access at Abbott is not granted their credentials until they complete an action within Living Security. And that was such a… such a technical example, like, there's no reason that everyone within the organization would need to be trained on what it means to have privileged credentials, because it is so irrelevant for others. That… that… posing that to… as kind of an answer to the question of why do we need a role-based program, that's one that we've used to kind of build the case for what, additional programming can do.

32:21 You've done it really well. For those who are in the room, I encourage you to talk with Edna and Scott and Taylor if you have the opportunity. Others, use LinkedIn and network. They are incredible sources of information and have walked the walk. I want to thank you, the three of you, for joining us today, for teaching everybody You need to start. You can start small, you now know the why, you know the how. We know we gotta focus on an enemy. Thank you for your time. Alright, that was incredible. I really love that conversation.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.