Targeted Threats

Behavioural science for deeper insights

Data-driven decision-making

Watch on-demand

Review emerging human-centric security risks highlighted in industry reports and research.

Monitor relevant incidents and behavioural trends reported across the news and wider industry.

Incorporate insights from internal sources, such as threat intelligence feeds or SOC findings.

Use available data (such as simulated exercises or email gateway data) to understand human risk, including its likelihood and potential impact on the business.

Identify key metrics from this data to establish a baseline view of current risk, which can later be compared against results after interventions.

Ensure measurements include a mix of quantitative and qualitative insights, as well as indicators of both performance and real-world effect.

Align strategies with assessment-stage metrics, applying targeted interventions (training, nudges, role-based approaches) informed by employee behaviours and risk profiles.

Drive engagement and behaviour change through interactive, contextual nudging, while reinforcing positive, “just” security culture practices (e.g. locking screens, verifying suspicious emails – as advocated by frameworks such as the NCSC Cyber Assessment Framework and NHS guidance).

Gather qualitative feedback from employees to identify barriers, motivators, and opportunities to improve effectiveness.

Review the measurements that you ascertain and the assess stage - are they on track and trending in the way you’d like?

Use this stage to report to your key stakeholders and pre-empt any future tweaks or interventions you may want to make.

Regularly review behavioural metrics and adapt interventions accordingly.

Use insights from interventions to iteratively refine content, delivery methods, and engagement tactics for sustained impact.

New Report:

Redflags Behavioural Impact Report 2026