On-demand session · 32 minutes Recorded live at HRMCon 2026

Operationalizing HRM: orchestrating your security stack to reduce real incidents

Connecting human risk signals to the controls that already exist — SIEM, DLP, identity — so insight turns into automatic action.

Genady shows how Stewart Title connects human risk signals to the stack it already has — so insight turns into autonomous action.

Genady Vishnevetsky speaking at HRMCon 2026
Genady VishnevetskyStewart Title
Full session · 32 min
Why watch

You already own the controls. The gap is connecting them to human risk.

SIEM, DLP and identity tools each see a slice of workforce behavior. On their own, they rarely change it.

Genady shows how Stewart Title connects human risk signals to the stack it already has — so insight turns into autonomous action.

What you'll learn

In 32 minutes, you'll walk away knowing:

Feeding SIEM, DLP and identity with workforce context.

Where orchestration replaces manual follow-up.

Prioritizing the workflows with the biggest payoff.

Proving the stack is now working together.

Speakers

A CISO who made his existing stack work harder

Genady Vishnevetsky

Genady Vishnevetsky

Stewart Title Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:07 Alright, hi everybody. Good to be back on stage and bringing my friend Gennady here with me. And… You know, as you saw, we had some great examples of Folks who have been pioneers in this space of human risk management. And these awards reflect that. And Gennady and Stewart title, really exemplifies, in my mind, that idea of leaning into a concept which You know, is fairly new still in the market. And when you are that pioneer and you're taking those first steps in that journey, you're really setting the stage for others to come behind you and feel a sense of confidence that they too can achieve the same goals and outcomes that you achieved. And so, I really appreciate what Gennady and Stuart have done in forging ahead, and really kind of creating a program I think that you guys should be very proud of, and I certainly find to be one of the more cutting edge in the industry today.

1:05 So with that, Gennady, maybe you could give a little bit of your background. Obviously, there was a little bit of a intro there, but I think understanding your area of ownership at Stewart, how that's laid out, and how you kind of came to be, you know, the CISO of Stewart today. That would be helpful. Hello, everyone. This is my 12th year at Stuart, and prior to that, I spent in two fintechs, and thank you, Damon, for reminding me how old I am. Speaking of compliance, back in 2003, this was my first introduction, I self-attassed at that time voluntarily, to CISB. Most of you probably don't know what it is, but some of you might know what it became, and it later became PCI DSS 1.0. That was the first, probably, program that actually required mandatory training, employee training, so I've started it back in very, very, very long time ago.

2:11 And, so I've known all cons and pros of this program. I've been running programs on my own using SAT tools, and at some point, I kind of reached that threshold where it's no longer working. Yeah, absolutely. And so, as you've heard throughout the day today, and we know just from industry research, 70% or more of security breaches have a human factor or a human-driven incident that kind of led to that. And we know that we can't train our way out of that, because the breaches keep coming. The security incidents are not stopping or ceasing. So how did you come to that realization that perhaps that status quo that you grew up in, of security awareness training as being kind of your primary tool to interface with your end-user community. How did you come to the realization that, you know what, there's gotta be something more than this? There's gotta be a better way?

3:07 Yeah, our traditional tree that we've been using for decades, fish, train, report, and measure all the out… all of the metrics and performance, really doesn't affect the outcome, and each of those legs of that stool actually has its own problems. like, for example, fish. It's very contextual. It's very important to understand, you know, who your audience is. As a matter of fact, it was interesting, I visited our World Global Company web presence in different regions around the world. And I visit my Costa Rica office one day, and they said, and we've talked about it, and they said, oh, well, we know all of your phishing simulation emails. I said, how do you know? Well, because they all come in English, and, you know, ours is in Spanish. So, as you're developing your program, you need to start thinking about it. For example, you know, those FedEx or DHL emails that you're sending, click on this link to get your updates or your packages delay, well, it may not exist in India, or it might not exist in other parts of the world.

4:16 We have a presence in Canada, and Canada is, on the east side, is divided by French, Canadian, and English. Like, in Toronto, it's English. Up in Quebec, it's French-Canadian, so you really need to understand your audience. The second reason why it doesn't work is because it's very timely. And I've tested it so many times, so if you are doing… if you are doing your training campaigns that are resonate with an event, whether it's the new healthcare enrollment, or tax seasons, etc, you're gonna get more clickers. So basically, it doesn't really measure, you know, is it effective or not? Do the people… are the people actually reacting? Next piece is the training. Simone did a great presentation about how people perceive the information. Different generations perceive information different. And then different people are attuned to a different type of training material and how they perceive this. Some of them like series, some of them like cartoons, some of them like short video, long videos, etc.

5:21 And the final reporting, that's actually interesting. I do a lot of, I do a lot of training and work that I create myself. I do weekly blogs almost every Friday throughout the year. I do my monthly video recording and video blogs, which I don't do anymore, my digital twin does. Full disclosure. And, so I've trained a user over the years, and what I… what was interesting is they're now… they became more resilient, but they became more resistant to click on anything. So what I start noticing, and while I was able to achieve the higher number for reporting… by the way, I hit the threshold, so I set myself a goal, 35%, then 45%, then 40, 40, 40, 45%, then 50. I never reached 50. So I think I stopped at, like, 42. But they really don't measure, they don't measure outcome, because they don't measure the reality. And what I found was there is actually less people now opening the email, opening phishing simulation emails, because they became more resilient, they take with critiques and everything else, and they just don't want to risk it.

6:31 And that's a behavior that I want to embrace, but it's not calculatable. The last problem is, and I actually stopped reporting to the board these numbers, because they're hard to explain. The simulation numbers on reporting are very important. What's even more important is the real phishing emails, because they help my team To be successful, they have my team to stop the attackers and help them every day. And that's very hard to measure, because you really have to extrapolate, take the amount of email that are coming in, and kind of guess. But that's probably the most important number. So that, that's why it doesn't work. And, so we… we've talked about people perceiving information differently. And, so basically, at some point, I come to realization I can't fix the people. So there will always be a person or a few people, who will always click on phishing email, and by the way, you might not be surprised, but some of them are actually the highest performers, so it's a very hard conversation with a business.

7:41 to saying, this employee continuously click on an efficient email, what are you gonna do about it? I mean, they bring in significant revenue to the company. So that's… at that point, I kind of realized I have to do something different. Right. Yep, so behavior change through engagement is a tool. But it's not the end of the story, right? Correct. And so, as we look at the modern cybersecurity team in enterprises today, now, generalization, but pretty consistent, I'm seeing a lot of siloed tools and siloed people, professionals working in those tools. So, there's a portion of a team that maybe owns Endpoint Detection Response, another portion that owns Email Gateway, SAT, GRC, DLP, the acronyms go on and on. But they're sitting in silos, staring down at a console that is specific to their domain. How do you break that? Or how do you actually solve for this problem when that's the construct that exists in a lot of organizations today?

8:39 Yeah, not only the sitting in a silo, but they're also very binary. If you think about the protective and detective technology, there's an alert you, notify you, inform you, and your protective technology actually is their allow or block. So, the DLP with their allow or block action. Your IDS IPS will do the same. Your endpoint detection tools. So, it's very binary, it does not have a contextual information about the user, it doesn't have a contextual information of a behavior. And that's where this human risk attribute becomes essential. Because today, in my SOC, for my security analysts, after they analyze all of these different panels, all of these different parameters, etc, and then they need to make the determination, it's, again, it's a binary decision. It's not only a security technology by themselves are binary, but the decision my SAC analyst was doing yesterday had to be binary, either what am I doing? Am I blocking or allowing? Am I resetting a password I'm gonna let in through? Am I elevating MFA, or… so it was very, very binary without contextual information.

9:49 Yeah, so human risk context. to enrich the decision-making of these folks who are within each of these various security silos. Correct. So, this is really interesting, I imagine, to a lot of our audience, right? Because this is ultimately where a more advanced human risk management program can go, right? Yes, you're engaging your end users, you're trying to change behavior, you're using the tools like training and nudging and phishing to do so, but when you can leap over. and be able to make that human risk context available to the SOC, to your DLP team, right, to your identity team. Now you're really cooking with gas. So, can you give some examples of how you guys are doing that at Stewart? Sure. So, that's a great point, because, you know, essentially what I'm doing now, and this is where the pivotal point for me from the traditional SAT was. So, if I can't control the user's behavior, and if I can't control the outcome for the user's behavior.

10:51 So what can I do? How can I put the controls around the users, additional security controls around users, knowing their behaviors and knowing their behavior store using my existing controls? And what we've done is, Living Security is already incorporated, it already has all the connections to all of our security tools. It receives all of the telemetry. So what I'm using is… I'm using today the bi-directional connectors where existed, and then webhooks where they're not existing, and start enforcing different policies and different security controls using technology that I already own, security technology that I already own. not… for not making a binary decision. In order to be successful, I want to be able to make the risk-averse decision, and the user actually is the highest part of the risk.

11:46 Right, so, maybe starting with identity. maybe you can walk through kind of a use case there today, I think, if you're… if you're comfortable sharing the vendor you're using. Sure. So, I think the pivotal point, and for some of you it may be a difference, so we have an IGA solution, identity governance administration solution, and that's… That's basically, the central brain for us. So this is source of truth. It's connected to a human capital system, it connects to Entra and Active Directory, it pulls the data, it knows everything and anything about the users from those two systems, and it also connects, and that's what provisions user permissions, users control, user actions. And, what we're using… what we're using today is we actually, through… through the Living Security, we're actually pushing, I'll disclose, I'll say it's… we're using CellPoint, Living Security has a CellPoint connector, and I think a few others, for our IGA system.

12:48 So what we're… what we're able to do is to actually use the group membership, but either using or removing users to a specific group, or from a specific group to be able to enforce the controls. These controls could be different, and I'll go through… later, I'll go through some use cases. that we are… we're currently at… we implemented, currently implementing, and will be implementing shortly. But basically, that's our biggest pivotal point. So we're controlling through our IGA system, we're controlling what users can and cannot do based on their behavior. So, identity… and group entitlements being informed by the context of whether the user is risky or not right now. Correct. Right. Now, let's talk about insider threat DLP, right? So, DLP as a product category has been in the market for almost 20 years now, venture to say that the vast majority of DLP is not in a kind of blocking mode, because, frankly, we're worried that we might stop an actual legitimate business process.

13:53 So, how can human risk context help you and your SOC team make better decisions there? Yeah, so, for example, DLP controls have a different control, so it can allow upload, it can allow download, it can… basically, it traverse, it controls the traffic, it controls the traffic flow, what's allowed to users, what's not allowed. So what I'm… what we're doing with DLP is we're actually fitting that data from the user's behavior, user score, to be able to adjust the actions. For example, for normal users, we're actually implementing DLP in kind of a in carrot mode, not a stick mode, because, you know, I believe the human behaves when humans are actually worn or put in specific circumstances, humans behave differently. So what we… what we're doing, actively doing now, is… We're actually prompting users to say, we absorbed this behavior.

14:51 it doesn't match our rules, do you want to continue or not? And that kind of pauses and stops the users, and we actually inform them, that they're, whatever they choose, they continue… they can continue with the action, and… but it will be recorded and audited and potentially reported to their manager, etc. Your mileage may be vary, you can use it in different, forms. in the format. But what that allows us to do is, actually, it allows us to use the score to block certain. So, like, for example, if the user with a higher score, we'll just allow them to be… to self-approve and move on. For the higher users, we'll just block the behavior. So we're basically using the same binary zeros and one block and allow, but now we're taking it in a user's context. Frankly, you can take the risk to potentially block, because you have a higher level of confidence… Correct. …that that user is potentially representing a risk to you right now.

15:50 Right? So you can make that decision. So beyond those specific use cases, how do you think about your deployment of HRM as you've described it? What does success look like? What are the outcomes you're trying to drive to, and how do you know it's working? First of all, I want to see behavior score changes. So, I gave you an example with a DLP. For example, if the user… if I don't see users exhibiting this.

17:29 to this, to us, to this market space. So now, you have 3 different dimensions that you need to look at. Now you have to look… We've teach our users for decades, look at imperfect language, you know, bad punctuations, greetings, images, etc. Now it doesn't exist. Now, if you look at the second dimension, is it's very contextual, because AI can actually… can actually write an email in the tone of your HR. In the tone of your jersey, in the tone of your CEO, your CFO, etc, because it contextualizes and understands the concept. And the last components that we need to factor in is velocity. AI brings in. So remember, the fishing exercise and training that we're doing once a month, or once in three months, or once a year is no longer working. We're seeing new techniques and techniques. My team sees new techniques and techniques literally daily now, today.

18:31 So… no. Yeah. Yeah, because of the speed of AI, being, you know, react and respond needs to be essentially replaced with predict and prevent. I need to be able to get ahead of it, because if I'm trying to react to AI, I gotta react at machine speed. Correct. I can't. Correct. And you can't really adjust, and this is where, I'm excited about where living security is going is, and that's where your training needs to be. Your training needs to be the nudges that are actually relevant. Some of the, some of the use cases with the training we're looking, and I'm very excited about, is, again, using the same technology. For example, user was blocked go into the website, and the category that reported by my secure web gateway was, website is less than 30 days old. Maybe I'll send a nudge to the user 5 minutes later and saying, hey, we've noticed you, you sent… there is probably nothing wrong with this website, but just be aware that attackers are now creating websites, sending these phishing links.

19:39 with orchestrated, websites, they're usually less than 30 days old. This is why we blocked it. So that creates the teachable moment at the moment when it's fresh with users, because when you give them a teachable moment next month, next quarter, etc, it doesn't… that's number one. Number two, it's resonate, and this is where it has to be… you can no longer land them on a page and say, here's the red flags you should have recognized, and here's the seven of them, because these red flags are not relevant anymore. Because they won't exist tomorrow. Yeah, I love that. And this morning, Kelly and I spoke about two things. One, ask Libby. Right? Which is, you know, a capability that's in development now, where the end user has their own AI agent, their own security analyst, who can help them navigate those potentially fraudulent or risky situations, to your point, in the moment, so I can navigate that myself. The second thing we spoke about this morning was the convergence of the human worker and the Agentic worker, right? And having an integrated understanding of risk associated with both.

20:45 You've already started some work in this as well, and we've spoken about how we can kind of meet together with Living Security's direction and what you're doing. Would you expand on that a little bit? Yeah, so there is… your agent needs to have an identity, and if they don't, you probably need to think about it how to assign them identity. There will be non-human identity, but there will be a lot of telemetry affiliated with your agent. So your tools, whatever they are today, whether you're a Google Shop or a Microsoft Shop, so Microsoft E7 license actually has an Agent 365, and Agent 365 has a capability a lot of capability for auditing, for using Purview as a DLP, to have and monitor an added safeguard, and guess what? All of this logging, all of this capability will be bi-directionally fed into your human risk management platform.

21:42 And your platform will be able to determine what's the… whether behaviors of these agents are normal or abnormal. I can also tell you your users change slowly, they're drifting slowly. Most of the users… most of us humans don't change behavior pretty frequently, or it takes a long time, or agent to change the behavior. So the agent will… will be very, very dynamic. They can change behavior very, very quickly, so you need to build a baseline of what the normal behavior of the agent looks like, and start alerting and monitoring and drifting from normal behaviors. Yeah, it's exciting to see this evolve, and we'll be working with UGNATI and our other customers as we bring that new technology out to the market and to get that feedback. My final question really is kind of building on what Damon was saying before about getting buy-in, right? So you're… at your level, at the CISO level, you had a vision.

22:40 and you brought that vision to your team, and you were able to cascade that vision into the different security silos. That buy-in was there from day one. That's not always the case. And so if someone's listening here today on the livestream or in the room, and they're not a CISO, but they believe that this is the right direction, maybe some words of advice for how they can get that buy-in. Yes, I was fortunate because I own, a lot of the stock myself, so I own SOC, I own Identity, I own DLP, I own tools, endpoint detection tools. So, this is all within my power, within my ecosystem, I can connect the dots. Depends on your function and where you're at. You need to build this relationship, you need to build this trust with the different business functions, but not only business functions, but different security functions, because you will need this support. You can be successful. I'm gonna give you some examples some takeaways in a minute that you can take, some use cases I've been working on and continue working on. There is a huge potential in this, because you can Finally, you can control the outcome from the user's behavior. You can control it through the system's control, through your security systems, through turning that binary 0, 0 or 1, allow or disallow, now factor in the user or human's behaviors.

24:03 So, partner with the team, with your leaders, partner with your CISO, if you're not a CISO, if you're in a security… if you own the security awareness and training program. Partner with your identity team, maybe it's belonging IT. Partner with your DLP team, partner with all of these teams, because you can't be successful without them. I want to share… do we have time? Absolutely, go ahead. So I want to share some, and forgive me for kind of reading. I juggle some notes. Some interesting cases, Mike asked me earlier, and I kind of left it for, for later, but, this is… this is my journey, and your mileage may vary, depends where you're at in the journey. I highly recommend you kind of start looking at, because you can't… you can't control, you can't fix people. I… I'd say you can't fix the people. So we, we were already implemented, and it's been, it's been up and running for us for months. for over a month now. So if the user fails a certain number of criteria, I'm not going to give you parameters because it's relevant. Yours will be different. So if the users fail a certain number of times within a certain period of time, they get added to the sale point of the group, and they actually get prompted MFA every single time, as opposed to behavior, as opposed to conditional access that we control for all of the other users that are kind of behavior-based. In order to get off that group, they actually need to exhibit the positive behavior, not click on efficient simulation, and then report over a certain period of time. Here is a great scenario, it's been working for us, we've been very, very successful with it.

25:40 In Security Operations Center, we actually implemented the webhook. Now we're feeding this data, the human risk score, HRI score. We're actually feeding into a security operations. I'll give you a couple examples. I'll give you two examples. One is a geolocation, we trip to alert that's saying users in a location where they haven't been before. So today, before, it was binary. It's actually going live in a couple weeks. So today, or yesterday, this was a binary decision. What do we do? We'll contact the manager, we try to use outbound channels to confirm whether a user is traveling or on vacation. So today, the score allows us to make my SOC to make the immediate decision by either blocking them. Or still going that manager route, if the user is exhibiting good behavior, or if the user is bad behavior, we're just locking them out. It's similar with the password alerts, etc. There's a lot of different telemetries and alerts coming that are related to a user that were before binary, now it allows us to add the intelligence to this.

26:46 So our next chapter in the months, we are… in two months, we are, gonna deal with privileged users. The privileged users, again, depends on the score. Your privileged users have a key to the kingdom, and whether it's the privileged users, privileged administrators. or whether it's your users, privileged users to your application, it really doesn't matter. They still have a key to the kingdom. So you have to tie, behavior, their behavior scores to what the access they have. So we're planning to have multi-factor authentication for user… for administrators or privileged users who have a low score. To use multi-factor authentication every time they connect to the systems. There's a little bit, longer horizon, about 4 months, is the GLP and security web gateway. For risky users, we're gonna block the download, and uploads, and for, not risky users or vigilant users, we're gonna allow them in. And for security web gateways, this is actually a perfect, case if you have, if you have a technology, is… So for the risky users, if they click on an email.

27:56 Then… and they went to the website, so their web sessions will be in remote browser isolation. So that actually protects them from typing in any credentials or uploading or downloading, downloading any information. And then, our longer horizon, about 5 to 6 months. on Secure Email Gateway is, you have this data, you have users are… remember, there is a… there is a behavioral score, and there is a HRI score. One is, driven by users' behavior, something they can't control, and some of them is driven by something they cannot control. For example, I can't control if I'm attacked more than Mike, if I receive more efficient email, more spec… etc. So we… we're planning to also factor that in and use it as a leverage or as a control for users who have access to a sensitive data, and then attack Moors and other users. You know, we'll set up additional parameters and security controls.

29:00 So, I finally found a platform that gives us the power to be able to actually intelligently use the control around the users. Thank you. And context is king, right? When you have the context, I can make better decisions. These use cases and more are the kind of conversations that my team has with you, and would love to have with all of our customers and attendees here, as you look to design out your programs going forward. And I think we might have a question or two From the audience. First question, Gennady. As a CISO, which stakeholders do you recommend are involved when evaluating an HRM solution? Is it the same as SAT, and if not, why? Knowing now what I know, this would be my last answer I just gave 2 minutes ago. Make sure you partner, with your security leaders, because if you want to be successful, if you want to take it to a next level and use it as a leverage, as a control lever.

30:02 you need their buy-in. So you need them to be comfortable, you need them to be on board, if you don't support… if you don't own that function. Obviously, if you do, then it makes it much easier. And when in the life cycle of considering a solution would you bring those folks in? I would bring them at the very beginning. Right away. Right away. Okay. Correct. Because you need to know how you… what capability you have, and whether you can be successful or not, whether you can design the system or not. You're designing the solution together. Correct. Second question, would baselining expected agent behavior against the related human behavior, so human-to-agent relationship. Does that make it easier to detect problematic anomalies? Take it for what it's worth, it's my personal opinion. I would say no. I'll give you an example. I gave this example earlier today. We as a human, our natural-born behavior is always positive. We always… We always think, you know, about good. We always… we intentionally do good things.

31:08 So, example I gave was, I might have permissions and privileges. And I know what I need to access, and I only access what I need to access. I'm not trying to go and poke… find the holes and poke. This is my natural behaviors. But, depends on the complexity of your company. Through inherit permissions, you might have other permissions you don't even know exist. Agent will find them, because that's what this is designed for. They design for to achieve the task. So they'll be able to crawl across your networks, all the niches, and find the permissions and access you didn't even know existed for you. So, I would say… this is why I would say no. So, you have to… you have to treat them from a behavioral perspective, and they would be the same as humans, so you need to monitor them, but I would say you need to baseline them differently.

32:04 Well, I think that's all the time we have, but again, Gennady, I really appreciate you and the program that you've built, and I believe you're a pioneer in this space, and I think there's a lot that the folks here can learn from you, and look forward to continuing your success. Thank you. Thank you.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.