Cimento is headed to Black Hat USA — catch us in Vegas, Aug 1–6

Black Hat USA 2026 · Aug 1–6

Book a Meeting →

Book a Meeting →

Security Insights

The teams changing employee behavior refuse surveillance

The teams changing employee behavior refuse surveillance

The teams changing employee behavior refuse surveillance

Zain Rizavi

Co-Founder & CEO

3 min

No headings found on page

Highlights

  • A behavior-change team refused raw data access, calling itself "not an investigative team."

  • Surveillance triggers the observer effect: watched employees perform compliance instead of changing.

  • Nudges without policing demand explainable scores and pre-tested triggers.

Every critique of human risk management lands the same punch: it is surveillance wearing a lanyard. Score the employees, watch the employees, and the distance between a risk program and a monitoring program rounds to zero. Critics and vendors disagree about everything except one premise: more visibility means more power, and security teams want more of both.

Then a conversation this week with a large healthcare enterprise broke the frame. Their security culture team, the people accountable for changing employee behavior across tens of thousands of staff, were explicit about what they wanted from a human risk platform. Aggregate scores, not individual dossiers. Deterministic triggers, not open-ended monitoring. And a line drawn in permanent ink: we are not an investigative team, and we do not want access to the raw data.

The thesis follows directly: the teams best positioned to change human behavior are refusing surveillance powers on purpose, and their refusal is the design spec the industry keeps missing.

The observer effect

Physics has a name for the problem. Measure a system intrusively and you disturb the thing you are measuring. Employees are not particles, but the effect is stronger with people, not weaker: the moment staff believe the awareness team is reading their traffic, every interaction with that team changes. Training becomes compliance theater. Nudges read as warnings. The behavior you observe is no longer the behavior you needed to change; it is the behavior of someone who knows they are being watched.

The healthcare team understood this in their bones. Their mandate is culture: awareness, judgment, habits. Culture moves through trust, and trust is exactly the asset that raw data access spends. So they split the roles. Investigations belong to another team with another charter. The culture team wants the score, the trigger, and the nudge: enough to act, too little to police.

Nudges without policing

Their phrase for the goal stuck with me: turn the score into change, without policing. Notice what that requires. The score must be explainable, because a nudge based on an unexplainable number is indistinguishable from an accusation. The trigger must be testable before it fires, because at their scale a bad trigger is not an error, it is an incident. And the escalation path must run through humans: a rising score earns a conversation, not a case file.

None of that needs surveillance. All of it needs precision. That is the trade most human risk tooling gets backward, hoarding visibility while starving explainability.

The narrowed claim

There is a simple test hiding in this conversation. Ask who in your org will consume the human risk score, then ask what they want to see. If the answer is an investigations team that wants everything, you are building an insider threat program, which is fine, but name it that. If the answer is a culture team that wants aggregates, triggers, and nudges, then every unit of individual visibility you add past that point is not capability. It is friction, and it compounds against you.

Human risk management does not fail when it sees too little. It fails when it sees so much that no one trusts it enough to be changed by it.

Key Takeways


  • Ask who consumes your risk score before deciding how much visibility to build.

  • Separate culture and investigations charters explicitly, with different data access levels.

  • Make every nudge explainable enough to survive the employee asking why.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.