An OutThink open standard for driving secure behavior and reducing human risk. The Atlas defines 204 observable secure behaviors - 112 core behaviors across 15 domains that apply to every organization, and 92 sector-specific behaviors across 10 industry libraries - each mapped to the HRM Maturity Model (L1-L4), NIST CSF 2.0, compliance regimes across 11 jurisdictions, and the HRM Metrics Library measures that prove behavior change.
Authentication & Credential Hygiene (Core · 8 behaviors)
AUTH-001 - Uses phishing-resistant MFA and rejects unexpected prompts
Enables and consistently uses phishing-resistant MFA (FIDO2/passkeys, hardware keys) on every work account that supports it, and never approves an MFA prompt they didn't trigger.
Critical · L1 → L2 (bridge) · Risk addressed: Account takeover, credential phishing, MFA-fatigue / push-bombing, session hijacking (ATT&CK T1621, T1078).
AUTH-002 - Uses a password manager and unique strong credentials
Generates and stores long, unique passwords in an approved password manager rather than reusing or memorizing weak ones.
Very High · L1 → L2 (bridge) · Risk addressed: Credential stuffing, brute force, password reuse compromise.
AUTH-003 - Keeps work and personal credentials separate
Never reuses work passwords on personal or third-party sites, and never uses personal accounts for work data.
High · L1 → L2 (bridge) · Risk addressed: Spillover compromise from third-party breaches; data leakage via personal accounts.
AUTH-004 - Treats unexpected MFA prompts as a red flag and reports them
Recognizes an unsolicited MFA push/SMS as a likely live attack, denies it, and reports it rather than approving to 'make it stop'.
Very High · L2 · Risk addressed: MFA-fatigue / push-bombing leading to account takeover (ATT&CK T1621).
AUTH-005 - Never shares credentials or one-time codes
Keeps passwords, OTPs and authenticator codes private and refuses requests to share them - including from people claiming to be IT or a manager.
Very High · L1 → L2 (bridge) · Risk addressed: Vishing/help-desk social engineering, account takeover, repudiation.
AUTH-006 - Signs in only via known pages and checks the URL first
Enters credentials only on the organization's known sign-in / SSO pages, checking the domain before typing, and never on a page reached from an unexpected link.
Very High · L2 · Risk addressed: Credential harvesting via phishing/AiTM proxy pages (ATT&CK T1556, T1110-adjacent).
AUTH-007 - Keeps account-recovery methods current and secure
Maintains accurate, secure recovery details (recovery email/phone, backup keys) and removes stale ones so recovery can't be abused.
Moderate · L2 → L3 · Risk addressed: Account recovery abuse, lockout, orphaned recovery paths.
AUTH-008 - Acts fast on suspected credential compromise
On any sign of compromise (unexpected login alert, leaked password), promptly changes the password, revokes sessions, and reports it.
High · L2 → L3 · Risk addressed: Dwell time after takeover; lateral movement.
Email & Social-Engineering Resilience (Core · 10 behaviors)
SENG-001 - Reports suspected phishing with one click
Uses the built-in report button to flag suspicious emails, treating reporting (not just deleting) as the helpful, protective act.
Very High · L1 → L2 (bridge) · Risk addressed: Undetected phishing, delayed containment, repeat targeting of others.
SENG-002 - Pauses on urgency, pressure or authority cues
Recognizes manufactured urgency, fear, secrecy or seniority pressure as manipulation signals and slows down to verify before acting.
Critical · L1 → L2 (bridge) · Risk addressed: Phishing, BEC, pretexting success driven by emotional manipulation.
SENG-003 - Verifies unexpected payment or bank-detail changes via a trusted second channel
Before paying, changing payee bank details, or releasing funds on an unexpected/urgent request, independently verifies via a known trusted channel - never the contact details in the message.
Critical · L1 → L2 (bridge) · Risk addressed: BEC / CEO-fraud, invoice fraud, deepfake-voice authorization, financial loss (ATT&CK T1656, T1598).
SENG-004 - Checks links and senders before clicking or opening attachments
Inspects the real sender address and link destination, and treats unexpected attachments with caution, before interacting.
Very High · L1 → L2 (bridge) · Risk addressed: Malware delivery, credential phishing, drive-by (ATT&CK T1566).
SENG-005 - Verifies identity on unexpected calls (anti-vishing)
Treats unexpected phone calls requesting action, data or access with caution - verifies the caller through an independent, known channel rather than trusting caller-ID.
High · L2 · Risk addressed: Vishing, help-desk impersonation, MFA-reset fraud (ATT&CK T1598).
SENG-006 - Treats unexpected texts and messaging links with caution (anti-smishing)
Applies the same scrutiny to SMS, WhatsApp and chat messages as to email - especially delivery, IT-support, payroll and 'new number' lures.
High · L2 · Risk addressed: Smishing, mobile credential theft, payroll-diversion fraud.
SENG-007 - Verifies high-stakes voice/video requests against deepfakes
For unusual high-value requests over voice or video, confirms authenticity through an out-of-band method or pre-agreed verification (call-back, code word) rather than trusting a familiar voice or face.
Very High · L2 → L3 · Risk addressed: Deepfake voice/video fraud, synthetic-media social engineering.
SENG-008 - Scrutinizes QR codes before scanning (anti-quishing)
Checks the source and destination of QR codes before scanning, and avoids scanning codes from unsolicited emails, posters or attachments.
Moderate · L2 · Risk addressed: Quishing - QR-based credential phishing and malware.
SENG-009 - Limits information that aids pretexting
Is mindful of what they expose publicly (out-of-office detail, org charts, project names, travel) that attackers use to craft convincing, targeted lures.
Moderate · L2 → L3 · Risk addressed: OSINT-fuelled spear-phishing and pretexting (ATT&CK T1598, T1589).
SENG-010 - Confirms unusual internal requests on collaboration tools
Verifies out-of-pattern requests on Teams/Slack/email that appear to come from colleagues or executives - gift cards, urgent transfers, MFA resets, file access - before acting.
High · L2 · Risk addressed: Internal-account impersonation, compromised-account lateral phishing, BEC.
Data Handling & Classification (Core · 7 behaviors)
DATA-001 - Classifies and labels information correctly
Applies the right sensitivity label/classification to documents and messages so protections (access, sharing, encryption) follow the data.
High · L1 → L2 (bridge) · Risk addressed: Mishandled sensitive data, oversharing, data leakage.
DATA-002 - Shares data only through approved channels
Sends and stores sensitive data via sanctioned, secured channels - never personal email, personal cloud, or unapproved file-sharing.
Very High · L2 → L3 · Risk addressed: Data egress via shadow channels, breach, loss of control (ATT&CK T1567).
DATA-003 - Applies need-to-know and least disclosure
Shares only what each recipient needs, to the smallest necessary audience, rather than broad 'reply-all' or open-link sharing.
High · L2 → L3 · Risk addressed: Over-broad access, accidental disclosure, scope creep.
DATA-004 - Uses approved encryption for sensitive data
Ensures sensitive data is encrypted in transit and at rest using approved methods, and doesn't bypass encryption for convenience.
High · L2 → L3 · Risk addressed: Interception, data exposure on loss/theft.
DATA-005 - Disposes of data and documents securely
Deletes, shreds or returns data per retention rules - secure-deletes files, shreds printouts, and doesn't hoard data beyond need.
Moderate · L2 → L3 · Risk addressed: Data found in disposal, retention-rule breaches, oversized attack surface.
DATA-006 - Checks recipients before sending
Verifies the recipient list (especially autocomplete and external addresses) before sending, to avoid misdirected data.
High · L1 → L2 (bridge) · Risk addressed: Misdirected email - a leading cause of reportable data breaches.
DATA-007 - Avoids unmanaged copies and local data hoarding
Keeps data in sanctioned systems rather than exporting to local drives, personal devices or unmanaged spreadsheets.
Moderate · L2 → L3 · Risk addressed: Shadow data, unprotected copies, breach blast-radius.
Privacy & Personal-Data Protection (Core · 6 behaviors)
PRIV-001 - Collects and uses only the personal data needed
Practices data minimization - gathering, processing and retaining the least personal data necessary for the task.
High · L2 → L3 · Risk addressed: Excessive processing, privacy non-compliance, larger breach impact.
PRIV-002 - Recognizes and correctly routes data-subject rights requests
Spots when someone is exercising privacy rights (access, deletion, correction) and routes it promptly to the right process rather than ignoring or mishandling it.
High · L2 · Risk addressed: Missed statutory deadlines, regulatory complaints, fines.
PRIV-003 - Respects lawful basis and purpose limitation
Uses personal data only for the purpose it was collected for and under a valid basis - doesn't repurpose data without checking.
High · L2 → L3 · Risk addressed: Unlawful processing, function creep, regulatory action.
PRIV-004 - Manages consent and preferences correctly
Captures, records and honors consent and communication preferences, and stops processing when consent is withdrawn.
Moderate · L2 · Risk addressed: Marketing/consent violations, complaints, penalties.
PRIV-005 - Controls cross-border transfers of personal data
Checks that transfers of personal data across borders (including via tools, vendors and AI services) have an approved safeguard before sending.
High · L2 → L3 · Risk addressed: Unlawful international transfers, regulatory exposure.
PRIV-006 - Recognizes and reports a personal-data breach quickly
Identifies a suspected personal-data breach (loss, misdirection, unauthorized access) and reports it immediately so statutory clocks can be met.
Very High · L2 · Risk addressed: Missed 72-hour notification, regulatory fines, harm to data subjects.
Secure Web, Browsing & Shadow IT (Core · 6 behaviors)
WEB-001 - Uses only approved apps and services
Works within sanctioned applications and SaaS, and avoids signing up for unapproved tools with work data ('shadow IT').
High · L2 → L3 · Risk addressed: Shadow IT/SaaS, ungoverned data, supply-chain exposure.
WEB-002 - Installs software only from approved sources
Obtains software from sanctioned stores/repositories, and doesn't install cracked, pirated or random-download software on work devices.
High · L2 · Risk addressed: Malware, trojanized installers, supply-chain compromise (ATT&CK T1195).
WEB-003 - Recognizes malicious or spoofed websites
Spots fake/look-alike sites and risky download prompts, and avoids entering data or downloading from them.
High · L2 · Risk addressed: Credential harvesting, malware, malvertising, fake updates.
WEB-004 - Manages browser extensions safely
Installs only necessary, vetted browser extensions and reviews their permissions, removing risky or unused ones.
Moderate · L2 → L3 · Risk addressed: Malicious/over-permissioned extensions, data exfiltration, session theft.
WEB-005 - Avoids entering data into untrusted sites and forms
Thinks before submitting credentials, personal or company data into web forms, especially on unfamiliar or unsecured sites.
Moderate · L2 · Risk addressed: Data leakage, credential theft, scam sites.
WEB-006 - Requests new tools through the approved path
When the sanctioned tooling falls short, raises a request through the approved channel rather than quietly adopting an unapproved tool.
Moderate · L2 · Risk addressed: Root cause of shadow IT; ungoverned tools; policy friction unaddressed.
Device & Endpoint Security (Core · 7 behaviors)
ENDP-001 - Keeps devices patched and updated promptly
Applies operating-system and application updates promptly rather than deferring them repeatedly.
Very High · L1 → L2 (bridge) · Risk addressed: Exploitation of known vulnerabilities, malware, ransomware (ATT&CK T1190).
ENDP-002 - Keeps endpoint protection enabled
Leaves EDR/anti-malware and host protections running, and doesn't disable or evade them.
High · L2 → L3 · Risk addressed: Undetected malware, defense evasion (ATT&CK T1562).
ENDP-003 - Locks the screen and uses auto-lock
Locks devices when stepping away and enables short auto-lock, in office, home and public settings.
Moderate · L1 → L2 (bridge) · Risk addressed: Unauthorized access, shoulder-surfing, insider misuse.
ENDP-004 - Uses disk encryption on work devices
Ensures full-disk encryption is on (BitLocker/FileVault) so data is protected if a device is lost or stolen.
High · L2 → L3 · Risk addressed: Data exposure on lost/stolen devices; reportable breach.
ENDP-005 - Uses managed, approved devices for work data
Accesses and stores work data on managed/approved devices, and follows BYOD rules where personal devices are permitted.
High · L2 → L3 · Risk addressed: Unmanaged-device exposure, data sprawl, weak controls.
ENDP-006 - Doesn't disable or work around security controls
Respects endpoint controls (no unsanctioned admin use, no disabling protections or bypassing restrictions for convenience).
High · L2 → L3 · Risk addressed: Control bypass, privilege misuse, malware foothold.
ENDP-007 - Reports lost or stolen devices immediately
Reports a lost or stolen device, token or phone right away so it can be wiped and access revoked.
High · L2 · Risk addressed: Data exposure, account access via the device, delayed containment.
Removable Media & Physical Security (Core · 6 behaviors)
PHYS-001 - Avoids unknown removable media and uses only approved devices
Doesn't plug in found or unknown USB drives/peripherals, and uses only approved, encrypted removable media for work.
High · L2 · Risk addressed: USB-borne malware, baiting attacks, data theft (ATT&CK T1091, T1200).
PHYS-002 - Keeps a clean desk and clear screen
Secures sensitive papers, notes and screens when away - nothing confidential left visible or unattended.
Moderate · L1 → L2 (bridge) · Risk addressed: Visual data theft, insider access, lost documents.
PHYS-003 - Manages tailgating and visitors at the door
Doesn't let unknown people tailgate through secure doors, and ensures visitors are signed in and escorted.
High · L2 · Risk addressed: Unauthorized physical access, theft, on-site compromise.
PHYS-004 - Protects access badges and credentials
Keeps access badges/passes secure, doesn't share or lend them, and reports loss promptly.
Moderate · L2 · Risk addressed: Cloned/stolen badges, unauthorized access.
PHYS-005 - Secures printing and physical documents
Uses secure/pull printing, collects printouts promptly, and stores or disposes of physical documents securely.
Moderate · L2 · Risk addressed: Abandoned printouts, document theft, disposal exposure.
PHYS-006 - Prevents shoulder-surfing in public
Shields screens and conversations in public/shared spaces - uses privacy filters and avoids displaying sensitive data to onlookers.
Moderate · L2 · Risk addressed: Visual eavesdropping, data and credential exposure.
Remote, Travel & Home Working (Core · 5 behaviors)
REM-001 - Uses a secure connection on untrusted networks
Uses the approved VPN/secure access on public or untrusted Wi-Fi and avoids sensitive work on open networks.
High · L2 · Risk addressed: Interception, man-in-the-middle, rogue hotspots.
REM-002 - Secures the home working environment
Applies basic home-network hygiene (changed router defaults, updates) and keeps work data off shared/family devices.
Moderate · L2 · Risk addressed: Compromised home network, data on unmanaged devices.
REM-003 - Protects devices and data while traveling
Keeps devices physically secure when traveling, follows travel rules (incl. high-risk destinations), and minimizes data carried.
Moderate · L2 → L3 · Risk addressed: Device theft, border inspection, targeted travel attacks.
REM-004 - Avoids sensitive work in overlooked public spaces
Defers confidential calls and screen work when they can be seen or heard by others in public settings.
Moderate · L2 · Risk addressed: Eavesdropping, visual/audio data leakage.
REM-005 - Uses approved collaboration and conferencing securely
Runs meetings on approved platforms with sensible hygiene (waiting rooms, access control, careful screen-sharing and recording).
Moderate · L2 · Risk addressed: Meeting intrusion, accidental disclosure via screen-share/recording, shadow tools.
Secure Use of AI / GenAI (Core · 17 behaviors)
AIUSE-001 - Uses only approved AI tools for work
Works within sanctioned, contractually-covered AI/GenAI tools rather than ad-hoc public ones for work tasks.
High · L2 → L3 · Risk addressed: Shadow AI, ungoverned data flows, supply-chain & contractual exposure.
AIUSE-002 - Keeps confidential and personal data out of unapproved AI tools
Never pastes source code, customer PII, or sensitive documents into public chatbots; only enters regulated/confidential data into approved, covered AI tools.
Very High · L2 → L3 · Risk addressed: Data leakage to third-party models, IP loss, privacy breach.
AIUSE-003 - Verifies AI output before relying on or sharing it
Treats AI output as a draft - checks facts, figures, code and citations before acting, sharing or publishing.
High · L2 · Risk addressed: Hallucination-driven errors, misinformation, insecure AI-suggested code.
AIUSE-004 - Avoids ungoverned AI decisions about people
Doesn't use AI to make or materially influence decisions about individuals (hiring, credit, access) without approved governance and human oversight.
Moderate · L2 → L3 · Risk addressed: Unlawful automated decision-making, bias, privacy harm.
AIUSE-005 - Treats AI-generated content critically
Stays alert that lures, voices, images and video can be AI-generated, and applies extra verification to convincing-but-unexpected content.
High · L2 → L3 · Risk addressed: AI-crafted phishing, deepfakes, synthetic-identity fraud.
AIUSE-006 - Operates AI agents safely and within scope
When using or building AI agents, keeps them within approved scope and data access, maintains human oversight, and reports anomalous agent behavior.
High · L3 → L4 · Risk addressed: Agent over-reach, excessive privilege, data exfiltration, a new class of insider risk.
AIUSE-007 - Uses enterprise AI accounts, never personal ones, for work
Does work only in the organization's AI tenant (SSO-backed enterprise accounts) where retention, training opt-outs and data residency are governed - never in personal ChatGPT/Claude/Gemini accounts or free tiers.
High · L1 → L2 (bridge) · Risk addressed: Work data retained in consumer tenants, used for model training, or breached outside org control; no audit trail; offboarding gaps (ATT&CK T1530; shadow-tenant data loss).
AIUSE-008 - Treats content fed to AI as a possible attack (prompt injection)
Recognizes that documents, emails, web pages and tickets pasted or connected into an AI tool can carry hidden instructions, and doesn't let AI act on untrusted content without checking - especially when the AI can browse, run tools or send messages.
Very High · L2 → L3 · Risk addressed: Indirect prompt injection hijacking AI assistants and agents; data exfiltration via poisoned content; AI-executed fraud (OWASP LLM01; MITRE ATLAS AML.T0051).
AIUSE-009 - Connects AI tools to data and systems with least privilege
Grants AI assistants, copilots, plugins and connectors only the minimum scopes, drives and mailboxes they need, reviews what a connection can see before approving it, and disconnects integrations no longer used.
High · L2 → L3 · Risk addressed: Over-scoped AI integrations become mass-exfiltration paths and single points of compromise; dormant OAuth grants abused (ATT&CK T1528; consent-phishing).
AIUSE-010 - Reviews agent actions before they touch the real world
Keeps a human checkpoint on consequential AI-agent actions - payments, sending external messages, changing records, deleting data, executing code - and actually reads the proposed action instead of rubber-stamping the approval.
Very High · L2 → L3 (bridge) · Risk addressed: Agent 'approval fatigue' (the new MFA fatigue): unreviewed agent actions executing fraud, mass deletion or data exposure at machine speed; runaway automations (MITRE ATLAS; OWASP LLM08 excessive agency).
AIUSE-011 - Keeps AI chat history, memory and context clean of sensitive data
Treats AI conversation history, persistent 'memory', and uploaded context files as data stores: clears or disables them for sensitive matters, doesn't leave regulated or client data in long-lived chats, and checks what an assistant already 'remembers' before sharing more.
Moderate · L2 → L3 · Risk addressed: Sensitive data accumulating invisibly in AI memory/history, exposed on account compromise, shared devices, or via memory-extraction prompts; retention beyond policy (ATT&CK T1530).
AIUSE-012 - Discloses AI use where it matters and labels AI-generated content
Is transparent about material AI involvement in work products, labels AI-generated media and communications where policy or law requires it, and never passes off unreviewed AI output as human work in regulated, contractual or trust-critical contexts.
Moderate · L2 → L3 · Risk addressed: Regulatory exposure (transparency duties), contract breach (client AI clauses), reputational damage from undisclosed AI content, deepfake-adjacent erosion of trust.
AIUSE-013 - Uses AI meeting assistants and recorders with consent and control
Admits AI notetakers/recording bots to meetings only when approved, participants are told, and the meeting's sensitivity allows it; checks where transcripts go, who can see them, and removes bots from privileged or sensitive sessions.
High · L1 → L2 (bridge) · Risk addressed: Covert recording (consent/wiretap exposure), transcripts of privileged or M&A discussions in ungoverned stores, third-party bot vendors holding meeting content, transcript-based social engineering.
AIUSE-014 - Brings new AI tools and use cases to governance instead of going shadow
Proposes new AI tools, models, agents and use cases through the organization's intake/approval path - making the business case rather than quietly adopting - so innovation lands inside guardrails instead of around them.
Moderate · L2 → L3 · Risk addressed: Shadow AI estate invisible to security/privacy/legal; duplicated spend; ungoverned high-risk uses discovered only after harm.
AIUSE-015 - Reports AI incidents, leaks and near-misses fast
Treats AI mishaps like security incidents and reports them promptly: sensitive data pasted into the wrong tool, an agent acting out of scope, harmful or fabricated output that was acted on, suspected poisoning or manipulation of an AI system.
High · L1 → L2 (bridge) · Risk addressed: AI incidents festering unreported (no containment, no breach-notification clock, no learning loop); repeated agent failures; regulatory exposure from late notification.
AIUSE-016 - Stays the expert: owns AI-assisted work and resists automation bias
Signs their name to AI-assisted work only after applying their own judgment, keeps the skills to do and check the task without AI, and escalates rather than defers when AI output conflicts with their expertise - especially in high-stakes decisions.
High · L2 → L3 · Risk addressed: Automation bias and skill atrophy: errors laundered through confident AI output; accountability vacuum ('the AI did it'); compounding failures when AI is wrong at scale.
AIUSE-017 - Recertifies what their AI agents can still do
Periodically reviews the standing permissions, connections and delegated authority of the AI agents they run - recertifying what each agent can read, spend and execute, retiring unused powers, and escalating when an agent's footprint has drifted beyond its job.
High · L3 → L4 · Risk addressed: Authority drift: agents accumulating scopes and credentials beyond purpose; orphaned agents still acting after their owners move on (OWASP LLM08; ATT&CK T1528).
Incident Recognition, Reporting & Response (Core · 8 behaviors)
INC-001 - Recognizes the signs of a security incident
Notices the indicators of compromise - unexpected behavior, alerts, ransom notes, account anomalies - and treats them as potential incidents.
High · L2 · Risk addressed: Missed/late detection, longer dwell time, bigger impact.
INC-002 - Reports incidents promptly through the right channel
Raises suspected incidents quickly via the official route, with the useful details, rather than staying silent or trying to fix it alone.
Very High · L2 · Risk addressed: Delayed response, evidence loss, escalating damage.
INC-003 - Speaks up without fear in a no-blame culture
Reports their own mistakes and concerns openly, supported by a no-blame culture that treats reporting as learning.
High · L2 → L3 · Risk addressed: Hidden incidents, suppressed near-misses, slower learning.
INC-004 - Preserves evidence and avoids making things worse
During a suspected incident, follows guidance to preserve evidence and avoid actions that destroy data or spread the problem.
Moderate · L2 → L3 · Risk addressed: Lost forensics, malware spread, hampered response.
INC-005 - Follows instructions during a live incident
Acts on response-team instructions promptly during a live incident (isolate device, reset credentials, halt a payment) without freelancing.
High · L2 → L3 · Risk addressed: Uncoordinated action, prolonged impact.
INC-006 - Reports near-misses and weak signals
Flags 'that was weird' moments and near-misses - novel lures, odd requests, glitches - even when nothing bad happened.
Moderate · L2 → L3 · Risk addressed: Missed early warning of emerging campaigns.
INC-007 - Communicates with discipline during incidents
During a suspected or live incident, shares details only through approved channels, doesn't speculate internally or externally (including social media), and leaves customer, regulator and press communication to the designated team.
Moderate · L2 → L3 · Risk addressed: Leaked or wrong incident details: legal privilege broken, regulator notifications pre-empted, attacker tipped off mid-response, market/press fallout from speculation.
INC-008 - Cooperates with automated containment instead of working around it
When automated defenses isolate a device, revoke a session or step up authentication, treats it as the system doing its job: completes the verification, adds context fast, and never sidesteps containment via personal devices or shadow channels.
High · L3 → L4 · Risk addressed: Containment bypass reopening attack paths mid-incident; response delay; unmanaged-device data flows during live incidents.
Access Management & Least Privilege (Core · 7 behaviors)
IAM-001 - Requests only the access needed (least privilege)
Asks for the minimum access required for the task and time period, rather than broad or 'just in case' permissions.
High · L2 → L3 · Risk addressed: Over-provisioning, larger blast radius, standing privilege.
IAM-002 - Gives up access that is no longer needed
Proactively relinquishes or confirms removal of access after a project, role change, or when prompted in access reviews.
Moderate · L2 → L3 · Risk addressed: Privilege accumulation, dormant access, audit findings.
IAM-003 - Manages joiner / mover / leaver access changes
Managers ensure access is provisioned, adjusted and revoked promptly as people join, change roles, or leave.
High · L2 → L3 · Risk addressed: Orphaned accounts, leaver access, insider/ex-employee risk.
IAM-004 - Uses individual accounts and doesn't share logins
Uses personal, attributable accounts rather than shared logins, so actions are accountable and access is controllable.
Moderate · L2 · Risk addressed: Loss of accountability, uncontrolled access, audit failure.
IAM-005 - Protects privileged access (admins)
Privileged users use separate admin accounts, phishing-resistant MFA, and PAM/just-in-time elevation - never everyday browsing on admin accounts.
Critical · L3 · Risk addressed: Privileged-account compromise, catastrophic blast radius (ATT&CK T1078.003).
IAM-006 - Approves access requests responsibly
Approvers review access requests on their merits - checking need and risk - rather than rubber-stamping.
Moderate · L2 → L3 · Risk addressed: Inappropriate access granted, segregation-of-duties breaches.
IAM-007 - Works with just-in-time access instead of standing privilege
Requests elevation only when a task needs it, lets time-boxed access expire instead of stockpiling roles, and gives back entitlements proactively - the human half of zero-standing-privilege.
High · L3 → L4 · Risk addressed: Standing-privilege abuse, lateral movement after account takeover, entitlement sprawl and audit findings (ATT&CK T1078).
Third-Party & Collaboration Security (Core · 6 behaviors)
TPRT-001 - Shares data with third parties only under approved agreements
Ensures a vendor/partner is approved and contractually covered before sharing data, rather than sending data to unvetted third parties.
High · L2 → L3 · Risk addressed: Ungoverned third-party data sharing, processor non-compliance, breach.
TPRT-002 - Manages external sharing and guest access carefully
Uses time-bound, least-privilege external sharing and guest access in collaboration tools, and removes it when no longer needed.
High · L2 → L3 · Risk addressed: Over-broad external sharing, lingering guest access, data leakage.
TPRT-003 - Verifies third-party requests for data or payment
Applies extra verification to requests from suppliers/partners - especially bank-detail changes and data requests - given vendor-account compromise is common.
High · L2 · Risk addressed: Vendor email compromise, supply-chain BEC, fraud.
TPRT-004 - Builds security into third-party selection
Raises security and privacy considerations through the proper process when choosing tools and vendors, rather than bypassing vendor risk review.
Moderate · L2 → L3 · Risk addressed: Unvetted supplier risk, weak processor security, concentration risk.
TPRT-005 - Offboards third-party access promptly
Ensures vendor/contractor access and data are revoked or returned when an engagement ends.
Moderate · L2 → L3 · Risk addressed: Lingering third-party access, data retention by ex-vendors.
TPRT-006 - Checks where the AI is before buying or connecting third-party tools
When selecting vendors or approving tools, asks the AI questions: does it train on our data, where is inference processed, which sub-processors and models sit underneath, what happens to prompts - and routes AI-embedded tools through AI-aware due diligence.
High · L2 → L3 · Risk addressed: Org data silently flowing into vendors' models and sub-processors; 'AI features' switched on in existing tools without review; supply-chain AI compromise (GV.SC blind spots).
Secure Development (DevSecOps) (Core · 6 behaviors)
SDLC-001 - Keeps secrets out of code and repositories
Developers store credentials, keys and tokens in approved secret managers - never hard-coded in source or committed to repos.
Very High · L2 → L3 · Risk addressed: Leaked secrets, repo-based credential exposure, breach (ATT&CK T1552).
SDLC-002 - Manages dependencies and software supply chain
Uses vetted dependencies, keeps them updated, and reviews new packages to avoid malicious or vulnerable components.
High · L2 → L3 · Risk addressed: Vulnerable/malicious dependencies, supply-chain compromise (ATT&CK T1195).
SDLC-003 - Acts on security findings in code
Reviews and remediates SAST/DAST and code-review security findings rather than deferring or suppressing them.
High · L2 → L3 · Risk addressed: Shipped vulnerabilities, exploitable flaws in production.
SDLC-004 - Secures CI/CD and cloud configuration
Avoids insecure cloud configurations (public buckets, open security groups, weak IAM) and follows secure infrastructure-as-code practice.
Very High · L2 → L3 · Risk addressed: Cloud misconfiguration breaches, exposed data stores (ATT&CK T1530).
SDLC-005 - Designs security in from the start
Considers threats early (threat modeling, secure design) rather than bolting security on at the end.
Moderate · L3 · Risk addressed: Design-level vulnerabilities, costly late fixes.
SDLC-006 - Uses AI coding assistants without leaking secrets or shipping unreviewed code
Keeps secrets, credentials, customer data and proprietary algorithms out of AI coding prompts and context; reviews AI-generated code like a junior engineer's PR (it is one); and checks license/provenance before shipping AI-suggested code.
Very High · L2 → L3 · Risk addressed: Secrets exfiltrated via prompts/context windows; insecure AI patterns (hardcoded creds, injection-prone code) merged at scale; license contamination; slopsquatting via hallucinated packages (ATT&CK T1195).
Governance, Accountability & Leadership (Core · 8 behaviors)
GOV-001 - Acknowledges and follows security policies
Reads, understands and follows the organization's security policies - and asks when a policy is unclear or impractical.
Moderate · L1 → L2 (bridge) · Risk addressed: Policy gaps, inconsistent control, audit findings.
GOV-002 - Leaders model secure behavior
Managers and executives visibly follow security practices, engage with the program, and reinforce it with their teams.
Very High · L3 · Risk addressed: Low manager engagement correlates with higher unit incidents (validated insight).
GOV-003 - Builds security into business decisions and projects
Considers security and privacy implications when making business decisions, launching projects, or changing processes - engaging security early.
High · L3 · Risk addressed: Security-as-afterthought, late or missing controls, project risk.
GOV-004 - Keeps role-based security competence current
Engages with role-relevant security development and keeps skills current as threats and tools evolve, rather than treating training as one-and-done.
Moderate · L2 · Risk addressed: Knowledge decay, outdated practice, plateauing programs.
GOV-005 - Owns their security responsibilities
Understands and accepts their specific security responsibilities for their role, data and systems - security as a held responsibility, not a slogan.
Moderate · L2 → L3 · Risk addressed: Diffused responsibility, gaps where 'everyone's job is no one's job'.
GOV-006 - Champions security with peers
Acts as a positive influence - helping colleagues, sharing good practice, and supporting the program as a security champion.
Moderate · L2 → L3 · Risk addressed: Missed culture multipliers, untapped peer influence.
GOV-007 - Leaders set, resource and model the AI guardrails
Leaders publish a clear approved-AI list and acceptable-use line, fund enterprise AI so people aren't pushed to consumer tools, use AI visibly within the rules themselves, and review AI-risk posture as a standing leadership item.
High · L2 → L3 · Risk addressed: Governance vacuum: workforce improvises AI use; bans push usage underground; leaders' own shadow AI use licenses everyone else's.
GOV-008 - Acts on their personal risk insights
Reads the personal risk feedback the program gives them (risk score, CyberQ, coaching nudges), completes the targeted micro-actions, and treats their risk profile as a professional metric they own - not surveillance to ignore.
Moderate · L3 → L4 · Risk addressed: Coaching-loop failure: telemetry without behavior change; persistent high-risk cohorts the program can see but not move.
Resilience, Backup & Recovery (Core · 5 behaviors)
RES-001 - Recognizes and resists ransomware behaviors
Avoids the actions that enable ransomware (risky macros, malicious downloads, unexpected encryption tools) and reports early signs immediately.
Very High · L2 → L3 · Risk addressed: Ransomware execution, encryption, business disruption (ATT&CK T1486).
RES-002 - Ensures important data is backed up
Keeps important work in backed-up, sanctioned systems and follows backup practice so data can be recovered after loss or ransomware.
High · L2 · Risk addressed: Unrecoverable data loss, extended downtime.
RES-003 - Knows their role in business continuity
Understands and rehearses their part in continuity and incident plans, and participates in exercises.
Moderate · L2 → L3 · Risk addressed: Disorganized response, prolonged disruption.
RES-004 - Recovers safely after an incident
Follows guided recovery steps (verify before restoring access, reset credentials, validate integrity) rather than rushing back to normal in a way that reintroduces risk.
Moderate · L3 · Risk addressed: Reinfection, premature restore, repeat compromise.
RES-005 - Shows up for drills and learns from them
Takes part fully in incident, continuity and recovery exercises (including AI-failure and offline-fallback drills), treats them as real practice rather than calendar noise, and feeds what broke back into the improvement loop.
Moderate · L2 → L3 · Risk addressed: Plans that only work on paper; first real rehearsal happening during the actual crisis; fallback skills (manual process, offline comms) atrophied.
Banking & Financial Services (Industry Library · 11 behaviors)
BFS-001 - Follows payment-authorization and dual-control rules
Applies mandated authorization, segregation-of-duties and dual-control steps for payments and transfers, and never circumvents them under pressure.
Critical · L2 → L3 · Risk addressed: Payment fraud, BEC, unauthorized transfers, control failure.
BFS-002 - Protects customer financial data
Handles account, transaction and KYC data strictly within approved systems and sharing rules.
Very High · L2 → L3 · Risk addressed: Financial-data breach, fraud enablement, regulatory penalties.
BFS-003 - Handles material non-public and insider information correctly
Recognizes material non-public information (MNPI), respects information barriers, and never misuses or leaks it.
High · L2 → L3 · Risk addressed: Insider dealing, market abuse, regulatory action.
BFS-004 - Handles cardholder data per PCI rules
Doesn't store prohibited card data, masks/handles PAN per rules, and uses only compliant channels for payment data.
High · L2 → L3 · Risk addressed: Cardholder-data exposure, PCI penalties, fraud.
BFS-005 - Protects trading, model and core-banking system access
Treats access to trading, pricing/model and core-banking systems as high-risk - strict authentication, no sharing, careful change handling.
High · L3 · Risk addressed: Market/financial impact, fraud, systemic disruption.
BFS-006 - Meets operational-resilience reporting behaviors
Reports ICT incidents and third-party concerns promptly and accurately to meet operational-resilience obligations.
High · L3 · Risk addressed: Resilience gaps, missed regulatory reporting, third-party concentration risk.
BFS-007 - Protects customers from authorized-push-payment and scam fraud
Customer-facing staff recognize scam patterns (APP fraud, romance/investment scams) and intervene to protect customers being socially engineered.
High · L2 → L3 · Risk addressed: Customer financial harm, APP fraud losses, reputational damage.
BFS-008 - Meets AML/KYC duties and reports suspicious activity
Follows know-your-customer and anti-money-laundering procedures, handles related data securely, and reports suspicious activity through the proper channel.
High · L2 → L3 · Risk addressed: AML/CTF breaches, sanctions exposure, regulatory penalties.
BFS-009 - Treats voice and video as unverified channels for money movement
Never executes payments, settlement changes or beneficiary updates on the strength of a call or video alone - however real the CFO, client or counterparty looks and sounds - and always completes callback verification to independently known numbers and dual control.
Critical · L2 → L3 (bridge) · Risk addressed: Deepfake-enabled payment fraud and BEC 2.0: cloned executive voices and live video-conference impostors authorizing transfers (Arup-style $25M case); ATT&CK T1656 (impersonation).
BFS-010 - Keeps MNPI and client data out of AI tools and validates AI analysis
Never feeds material non-public information, client portfolios or deal data into unapproved AI tools, and treats AI-assisted research, credit memos and models under the firm's model-risk discipline - validated before anything reaches a client or a book.
Very High · L2 → L3 · Risk addressed: MNPI leakage via AI prompts (market abuse exposure); hallucinated figures in client advice; un-validated AI models driving credit/trading decisions (SR 11-7 model risk).
BFS-011 - Uses AI with customers only inside conduct and fairness rules
Deploys AI in customer-facing work (chat, advice support, credit decisions, collections) only through approved systems with human oversight, explains decisions when customers ask, and never lets unapproved AI generate financial advice or eligibility outcomes.
High · L2 → L3 · Risk addressed: Discriminatory or unexplainable AI decisions about customers; unapproved 'advice' creating liability; EU AI Act high-risk obligations (creditworthiness) breached; conduct-regulator action.
Pharmaceuticals & Healthcare (Industry Library · 11 behaviors)
PHC-001 - Protects patient health information in clinical workflows
Accesses and shares PHI only on a minimum-necessary, need-to-know basis within clinical and administrative work.
Very High · L2 → L3 · Risk addressed: PHI breach, privacy harm, regulatory penalties.
PHC-002 - Never snoops on records out of curiosity
Accesses patient records only for legitimate care or work reasons - never browsing colleagues', family, VIP or celebrity records.
High · L2 → L3 · Risk addressed: Privacy violations, HIPAA penalties, loss of trust.
PHC-003 - Uses connected medical devices and IoMT securely
Follows secure practice with networked medical devices - doesn't bypass controls, reports malfunctions/anomalies, and keeps devices on approved configurations.
High · L3 · Risk addressed: Compromised medical devices, patient-safety impact, lateral movement.
PHC-004 - Handles shared clinical workstations safely
On shared clinical devices, signs in/out properly, never works under another clinician's session, and locks between patients.
High · L2 · Risk addressed: Mis-attributed actions, PHI exposure, record-integrity issues.
PHC-005 - Verifies identity before disclosing health information
Confirms the identity and authority of callers, family members and third parties before disclosing any patient information.
High · L2 · Risk addressed: Pretexting for health data, unauthorized disclosure.
PHC-006 - Protects clinical-trial data integrity and confidentiality
Maintains the confidentiality, integrity, provenance and blinding of research/trial data, follows de-identification rules, and protects study IP.
High · L3 · Risk addressed: Data-integrity loss, unblinding, re-identification, research-IP theft.
PHC-007 - Protects drug-development IP and regulated R&D data
Safeguards formulations, manufacturing process data, and proprietary research, and guards against IP theft (including via AI tools and at offboarding).
High · L2 → L3 · Risk addressed: Loss of high-value pharma IP, competitive/national-security harm, espionage.
PHC-008 - Secures the pharma supply chain and anti-counterfeit data
Protects serialization, track-and-trace and supply-chain data, and follows controls that keep counterfeit or diverted product out of the chain.
Moderate · L3 · Risk addressed: Counterfeit medicines, supply-chain compromise, patient-safety and regulatory impact.
PHC-009 - Keeps patient data out of unapproved AI tools
Never enters PHI - notes, images, letters, lab results, even 'anonymized' patient stories - into consumer AI tools, and uses only AI systems the organization has approved for clinical data (BAA-covered / DPIA-cleared).
Very High · L1 → L2 (bridge) · Risk addressed: PHI breach via consumer AI tenants (HIPAA/GDPR exposure, breach notification); re-identification of 'anonymized' cases; patient-trust collapse.
PHC-010 - Signs off AI-drafted clinical content before it enters the record
Reviews and corrects every AI-drafted clinical artifact - ambient-scribe notes, discharge summaries, referral letters, coding suggestions - before signing it into the record, and challenges AI diagnostic suggestions against their own clinical judgment.
Very High · L2 → L3 · Risk addressed: Hallucinated or mis-transcribed clinical content entering the legal record; automation bias in diagnosis/triage; patient harm and liability from unreviewed AI output.
PHC-011 - Uses AI in research and GxP work without breaking data integrity
Applies ALCOA+ data-integrity discipline when AI touches regulated R&D and trial workflows: AI-assisted records stay attributable and original, trial participant data goes only into approved environments, and AI never silently alters source data or analysis.
High · L2 → L3 · Risk addressed: GxP data-integrity findings (untraceable AI edits); trial-participant privacy breach; IP leakage of compounds/biologics via prompts; regulatory submission integrity.
Software & Technology (Industry Library · 10 behaviors)
SWT-001 - Protects customer and tenant data isolation
Maintains strict tenant isolation and customer-data protection - never mixing, exposing or mishandling customer data across tenants or environments.
Very High · L3 · Risk addressed: Cross-tenant exposure, customer-data breach, contractual breach.
SWT-002 - Manages production access and change control carefully
Accesses production systems with least privilege and follows change-control - no unauthorized prod changes or standing access.
High · L3 · Risk addressed: Production incidents, breaches, customer impact.
SWT-003 - Handles vulnerability reports responsibly
Routes inbound security/vulnerability reports (incl. from researchers) to the right process promptly and supportively, rather than ignoring or dismissing them.
Moderate · L2 → L3 · Risk addressed: Unaddressed vulnerabilities, public disclosure, reputational harm.
SWT-004 - Protects source code and intellectual property
Keeps source code, designs and trade secrets within sanctioned systems, and guards against IP exfiltration (including via AI tools and at offboarding).
High · L2 → L3 · Risk addressed: IP theft, competitive harm, code leakage.
SWT-005 - Manages API keys and integration tokens safely
Stores, scopes, rotates and revokes API keys, OAuth tokens and service credentials securely - never embedding them insecurely or over-scoping.
High · L2 → L3 · Risk addressed: Token leakage, integration compromise, supply-chain pivot.
SWT-006 - Protects build and release pipeline integrity
Safeguards the CI/CD pipeline and build artifacts - verifies/signs artifacts, protects build credentials, and guards against tampering that reaches customers.
Very High · L3 · Risk addressed: Build-system compromise, malicious releases, downstream supply-chain attack (e.g., SolarWinds-style).
SWT-007 - Operates customer-support access without being socially engineered
Support and admin staff verify requesters, use least-privilege support tooling, and resist social engineering aimed at impersonation, account changes or 'admin' access.
High · L2 → L3 · Risk addressed: Support-tool abuse, account takeover via support, customer-data exposure.
SWT-008 - Builds AI features that respect customer-data boundaries
When building AI into the product, keeps tenant data out of shared models and other tenants' contexts, honors training opt-outs and data-residency commitments by design, and never uses production customer data to prototype AI features without approval.
Very High · L2 → L3 · Risk addressed: Cross-tenant leakage through AI features (embeddings, caches, fine-tunes); broken contractual 'no-training' promises; trust-destroying AI-feature incidents.
SWT-009 - Keeps customer content out of ungoverned AI in support and success
Support, success and sales engineers paste customer tickets, logs and configs only into approved AI tooling; strips secrets and identifiers first; and never lets personal AI accounts or browser extensions read customer environments.
High · L2 → L3 · Risk addressed: Customer credentials/PII in tickets leaking via consumer AI; support staff socially engineered into AI-summarized account takeover; SLA-driven shortcuts becoming breach paths.
SWT-010 - Runs agentic dev tools in sandboxes with scoped power
Gives coding/ops agents their own scoped identities and tokens (never personal credentials), runs them in sandboxes or isolated branches, keeps them out of production without explicit human-gated change control, and reviews their action logs.
Very High · L2 → L3 · Risk addressed: Agents with prod access executing destructive or injected commands; personal-credential reuse making agent actions unattributable; unreviewed agent-driven changes reaching customers (ATT&CK T1072-style mass action).
Consumer & Retail (Industry Library · 9 behaviors)
CRT-001 - Protects cardholder data at the point of sale and online
Handles payment data per PCI in-store and online, using only compliant devices/flows and never recording prohibited card data.
Very High · L2 → L3 · Risk addressed: Cardholder-data theft, PCI penalties, fraud.
CRT-002 - Spots POS tampering and web-skimming
Checks payment terminals for tampering/skimmers and stays alert to e-commerce code changes (Magecart-style web-skimming).
High · L2 → L3 · Risk addressed: Card skimming, e-skimming/Magecart, payment fraud.
CRT-003 - Onboards and offboards seasonal staff securely
Ensures seasonal/temporary staff get appropriate, time-bound access and security basics, and that access is removed when they leave.
Moderate · L2 → L3 · Risk addressed: Over-provisioned temps, lingering access, insider risk at scale.
CRT-004 - Handles customer and loyalty data carefully
Treats customer profiles, loyalty and marketing data per privacy rules - minimizing, securing and respecting preferences.
Moderate · L2 · Risk addressed: Customer-data breaches, privacy/marketing violations.
CRT-005 - Guards against gift-card and refund-fraud social engineering
Recognizes gift-card, refund and account-takeover scam patterns targeting stores and contact centers, and verifies before acting.
Moderate · L2 · Risk addressed: Gift-card fraud, refund fraud, customer-account takeover.
CRT-006 - Protects e-commerce accounts against takeover and fraud
Staff protect customer-account and storefront systems against credential-stuffing, account-takeover and bot-driven fraud, and act on fraud signals.
Moderate · L2 → L3 · Risk addressed: Account-takeover, credential stuffing, fraudulent orders, chargebacks.
CRT-007 - Secures supplier portals and consumer-goods supply chain
Protects supplier/vendor portal access, EDI and product data, and verifies supplier requests to defeat supply-chain fraud.
Moderate · L2 → L3 · Risk addressed: Supplier-portal compromise, supply-chain fraud, product-data tampering.
CRT-008 - Uses AI for customer service and content inside the guardrails
Customer-facing staff and marketers use only approved AI for chat replies, product copy, images and campaigns; keep loyalty/customer data out of unapproved tools; and review AI output for pricing errors, claims and brand damage before it reaches customers.
High · L2 → L3 · Risk addressed: Customer PII in consumer AI tenants; AI-invented prices/policies honored at cost; non-compliant marketing claims; brand-damaging AI content at scale.
CRT-009 - Spots AI-powered fraud against stores and operations
Stays alert to AI-era retail fraud - deepfaked 'executives' or 'IT' driving gift-card and refund schemes, AI-generated fake invoices and supplier changes, flawless phishing in any language - and verifies through procedure, not plausibility.
High · L2 → L3 · Risk addressed: Gift-card/refund fraud at scale; supplier-payment redirection via AI-crafted invoices; store staff socially engineered by synthetic voices (ATT&CK T1656).
Advanced Manufacturing (Industry Library · 9 behaviors)
MFG-001 - Maintains IT/OT boundary discipline on the plant floor
Keeps the boundary between IT and operational-technology networks intact - doesn't cross-connect devices, media or laptops between them.
Critical · L3 · Risk addressed: OT compromise, production stoppage, safety impact, lateral movement.
MFG-002 - Controls removable media strictly in production environments
Uses only sanctioned, scanned removable media in production/OT, via approved kiosks/processes - never personal or unscanned drives.
Very High · L3 · Risk addressed: Malware into production systems, line stoppage, quality/safety impact.
MFG-003 - Follows secure remote-access procedures for equipment vendors
Ensures equipment-vendor remote access is approved, time-bound, supervised and via sanctioned methods.
High · L3 · Risk addressed: Remote OT compromise, unsupervised vendor access.
MFG-004 - Reports production and control-system anomalies promptly
Treats unusual machine/HMI behavior, alarms or quality anomalies as potential security events and reports them quickly.
High · L3 · Risk addressed: Undetected OT compromise, quality/safety incidents.
MFG-005 - Never bypasses safety or security interlocks
Doesn't disable, override or work around safety/security interlocks and protections on plant equipment.
Critical · L3 · Risk addressed: Safety incidents, equipment damage, security-control loss.
MFG-006 - Protects manufacturing IP, designs and process data
Safeguards CAD files, formulations, process parameters and trade secrets, and guards against exfiltration (including via AI tools and at offboarding).
High · L2 → L3 · Risk addressed: IP/trade-secret theft, competitive and national-security harm.
MFG-007 - Secures industrial IoT and smart-factory devices
Follows secure practice for IIoT sensors and connected equipment - approved configurations, no default credentials, and reporting anomalies.
High · L3 · Risk addressed: IIoT compromise, botnet recruitment, production manipulation.
MFG-008 - Keeps AI tools away from OT and verifies AI guidance for production
Never connects AI assistants/agents to OT networks or controllers without engineering authorization, keeps plant data (parameters, schematics, alarms) out of unapproved AI, and routes AI-suggested process changes through normal change control - never straight to the line.
Very High · L2 → L3 · Risk addressed: AI tools becoming IT→OT bridge paths; hallucinated process guidance causing scrap, downtime or safety events; plant data leaking targeting information (ATT&CK for ICS).
MFG-009 - Protects designs, formulas and process IP from AI leakage
Keeps CAD files, BOMs, formulations, tolerances and process know-how out of unapproved AI tools, and verifies AI-generated designs and engineering calculations independently before they reach tooling, suppliers or production.
High · L2 → L3 · Risk addressed: Crown-jewel IP exfiltrated via prompts into trainable tenants; AI-generated design errors propagating into physical product; counterfeit enablement.
Infrastructure, Energy & Utilities (Industry Library · 9 behaviors)
IEU-001 - Maintains IT/OT segmentation for critical systems
Keeps critical control networks segmented from IT and the internet, and never cross-connects devices or media that breach the boundary.
Critical · L3 · Risk addressed: Compromise of critical-service control systems, outages, safety/national impact.
IEU-002 - Applies strict removable-media control in control environments
Uses only sanctioned, scanned media in OT/control environments via approved processes - never personal or unscanned drives.
Very High · L3 · Risk addressed: Malware into critical control systems, service disruption.
IEU-003 - Secures and supervises vendor remote access to ICS/SCADA
Ensures remote access to ICS/SCADA is approved, time-bound, monitored and via sanctioned methods, especially for third-party vendors.
Very High · L3 · Risk addressed: Remote compromise of critical control systems (e.g., utility intrusions).
IEU-004 - Reports control-system and grid anomalies promptly
Treats unusual HMI/SCADA behavior, alarms or grid/process anomalies as potential security events and reports them quickly.
High · L3 · Risk addressed: Undetected compromise, cascading outages, safety incidents.
IEU-005 - Never bypasses protection or safety interlocks
Doesn't disable, override or work around safety/protection systems and security interlocks on critical equipment.
Critical · L3 · Risk addressed: Safety incidents, equipment/grid damage, control-loss.
IEU-006 - Secures engineering workstations and field devices
Keeps engineering workstations hardened/patched within change windows, secures field/substation devices, and ensures vendor laptops meet requirements before connecting.
High · L3 · Risk addressed: EWS/field-device compromise as a path into critical systems.
IEU-007 - Treats security as part of safety culture for critical services
Integrates cybersecurity into the safety mindset - recognizing that security failures can cause safety failures and service outages.
Moderate · L3 · Risk addressed: Security treated as separate from safety; operator-behavior gaps.
IEU-008 - Keeps human authority over AI in control-room decisions
Treats AI advisories in operations (load forecasts, anomaly triage, switching suggestions) as input - never authority: verifies against procedures and telemetry before acting, keeps AI tools off control networks, and reports AI guidance that conflicts with safety procedure.
Critical · L2 → L3 · Risk addressed: Automation bias in safety-critical operations; AI-suggested actions bypassing operating procedures; manipulated AI advisories as an attack vector against the grid/plant.
IEU-009 - Keeps critical-infrastructure data out of public AI
Never feeds network topologies, SCADA configurations, site schematics, protection settings or outage plans into unapproved AI tools - this is targeting data - and reports any AI system behaving oddly around operational data.
High · L1 → L2 (bridge) · Risk addressed: Adversary reconnaissance enriched by leaked infrastructure data; state-actor targeting (Volt Typhoon-style pre-positioning); regulatory breach of CEII/security-of-information duties.
Government & Public Sector (Industry Library · 8 behaviors)
GVT-001 - Handles official and classified information correctly
Applies government classification/handling rules - marking, storing, sharing and transmitting information at the correct level.
Very High · L2 → L3 · Risk addressed: Mishandling of classified/official data; national-security & legal impact.
GVT-002 - Protects citizen data and follows records rules
Handles citizen personal data lawfully, follows records-management and freedom-of-information rules, and avoids improper access or disclosure.
High · L2 → L3 · Risk addressed: Citizen-data breaches, FOI/records failures, loss of public trust.
GVT-003 - Stays alert to state-sponsored targeting
Recognizes that public-sector roles are high-value targets for sophisticated/state actors and applies heightened vigilance to targeted lures and access.
High · L2 → L3 · Risk addressed: Advanced spear-phishing, espionage, credential theft.
GVT-004 - Shares information across agencies securely
Uses approved cross-agency channels and agreements when sharing information, respecting classification and data-sharing rules.
Moderate · L2 → L3 · Risk addressed: Improper cross-agency disclosure, data-sharing-agreement breaches.
GVT-005 - Protects access to public-facing and critical services
Guards privileged access to citizen-facing and critical public systems, applying strong authentication and careful change handling.
High · L3 · Risk addressed: Disruption of public services, citizen-data exposure.
GVT-006 - Upholds integrity of public service and reports misuse of access
Uses access to public systems and data only for authorized purposes, and reports misuse, insider concerns or attempts to influence public processes.
Moderate · L2 → L3 · Risk addressed: Insider misuse, data-access abuse, erosion of public trust.
GVT-007 - Uses AI on official information only within approved boundaries
Applies classification discipline to AI: official, sensitive and citizen data go only into accredited AI systems at the right level, never consumer tools; and treats AI outputs derived from official data as official records (retention, FOI/records law).
Very High · L1 → L2 (bridge) · Risk addressed: Classified/official information spilling into uncontrolled tenants; FOI/records-law breaches from ungoverned AI outputs; hostile-state collection against government AI use.
GVT-008 - Keeps AI-assisted decisions about the public transparent and appealable
Where AI informs decisions about citizens (benefits, permits, enforcement, triage), ensures a capable human reviews before adverse outcomes, records the AI's role, and protects the citizen's route to explanation and appeal - never hiding behind 'the system decided'.
High · L2 → L3 · Risk addressed: Unlawful automated decision-making; systemic bias at population scale (Robodebt-style failures); collapse of public trust and legal challenge.
Tertiary Education (Industry Library · 8 behaviors)
THE-001 - Protects student and research-participant data
Handles student records and research-participant data lawfully and on a need-to-know basis across academic and administrative work.
High · L2 → L3 · Risk addressed: Student/participant-data breaches, privacy harm, regulatory penalties.
THE-002 - Protects research data, grants and academic IP
Secures research data and IP, follows funder/data-management requirements and export controls, and guards against research-targeted theft.
High · L3 · Risk addressed: Research-data/IP theft, integrity loss, funder non-compliance, foreign interference.
THE-003 - Maintains shared device and account hygiene on campus
Manages shared lab/library devices and accounts safely - signing out, not sharing credentials, and protecting data on communal systems.
Moderate · L2 · Risk addressed: Account misuse, data exposure on shared systems, malware spread.
THE-004 - Recognizes research- and education-targeted scams
Spots scams aimed at academia - grant, journal, payroll-diversion and credential lures - and verifies before acting.
Moderate · L2 · Risk addressed: Payroll diversion, grant fraud, account takeover, research compromise.
THE-005 - Works securely in open and BYOD-heavy environments
Applies good security in the university's open networks and diverse device population - protecting work/research data on personal devices and using approved access.
Moderate · L2 → L3 · Risk addressed: Data exposure on unmanaged devices, open-network attacks, sprawl.
THE-006 - Protects sensitive collaborations from undue foreign influence
Follows research-security and disclosure rules in international collaborations, and reports approaches that seek improper access to sensitive research.
Moderate · L3 · Risk addressed: Foreign interference, undisclosed conflicts, sensitive-research compromise.
THE-007 - Protects research data and ideas when using AI
Keeps unpublished results, grant applications, participant data and export-controlled research out of unapproved AI tools; checks funder/publisher AI rules before using AI on manuscripts and reviews; and treats novel ideas as confidential until protected or published.
High · L2 → L3 · Risk addressed: Scooping/IP loss via trainable tenants; export-control violations (deemed exports into foreign-operated AI); funder/publisher sanctions; participant-confidentiality breach.
THE-008 - Uses AI in teaching and assessment fairly and lawfully
Faculty and staff use AI on student work only within policy: no feeding identifiable student submissions into unapproved tools, no high-stakes decisions on unreliable AI 'detectors' alone, and course AI rules stated clearly so students aren't trapped by ambiguity.
Moderate · L2 → L3 · Risk addressed: Student personal data (FERPA/GDPR) leaked via AI tools; false-positive 'AI detection' accusations harming students; discriminatory outcomes; institutional liability.
K-12 Education (Industry Library · 8 behaviors)
K12-001 - Protects students' (minors') personal data
Handles pupil data lawfully and on a need-to-know basis, with extra care for minors and vulnerable students.
High · L2 → L3 · Risk addressed: Children's-data breaches, privacy harm to minors, regulatory penalties.
K12-002 - Vets and uses classroom edtech safely
Uses only approved, privacy-vetted edtech apps with pupils, respecting consent rules and not signing pupils up to unvetted tools.
Moderate · L2 → L3 · Risk addressed: Children's-data exposure via edtech, consent violations, shadow apps.
K12-003 - Defends against phishing and BEC targeting schools
Recognizes and reports lures aimed at schools/districts - payroll/W-2 diversion, vendor-invoice fraud and ransomware delivery.
High · L2 · Risk addressed: Payroll/BEC fraud, ransomware, district-wide disruption.
K12-004 - Manages classroom and young-user device/account hygiene
Keeps classroom and shared devices secure, manages pupil accounts and passwords appropriately for age, and supervises safe use.
Moderate · L2 · Risk addressed: Account misuse, data exposure, inappropriate access on shared devices.
K12-005 - Handles student information with safeguarding in mind
Treats sensitive pupil information (welfare, safeguarding, special-needs) with strict confidentiality and routes online-safety concerns correctly.
High · L2 → L3 · Risk addressed: Harm to vulnerable children, confidentiality breaches, safeguarding failures.
K12-006 - Supports ransomware resilience in the school
Follows the basics that keep a resource-constrained school resilient - recognizing ransomware signs, protecting backups, and reporting early.
High · L2 → L3 · Risk addressed: Ransomware, prolonged closure, data loss in under-resourced schools.
K12-007 - Keeps students' data out of consumer AI and uses approved edtech AI only
Never enters student names, grades, IEPs, safeguarding notes or photos into consumer AI tools; uses only district-approved AI/edtech with proper agreements; and is doubly careful because the data subjects are children.
Very High · L1 → L2 (bridge) · Risk addressed: Minors' data in trainable consumer tenants (COPPA/FERPA/GDPR-child breach); safeguarding information exposure; predatory profiling of children.
K12-008 - Checks AI-generated classroom content and models healthy AI habits
Reviews AI-generated lesson materials for accuracy and age-appropriateness before classroom use, demonstrates honest, critical AI use to students, and stays alert to AI-specific safeguarding signals (deepfake bullying, AI 'companions', sextortion imagery) - reporting them through safeguarding channels.
High · L2 → L3 · Risk addressed: Inaccurate/inappropriate AI content taught as fact; normalized careless AI use shaping a generation; AI-enabled harm to children going unreported.
Professional Services (Industry Library · 9 behaviors)
PRO-001 - Protects client confidentiality and privilege
Safeguards confidential and privileged client information, sharing only with authorized parties through secure channels.
Very High · L2 → L3 · Risk addressed: Privilege waiver, confidentiality breach, professional-conduct violations.
PRO-002 - Maintains engagement segregation, ethical walls and conflict checks
Keeps client/engagement information appropriately segregated, respects ethical walls, and supports conflict-of-interest and independence checks.
High · L2 → L3 · Risk addressed: Conflicts, improper information flow, independence/ethical breaches.
PRO-003 - Verifies counterparties to prevent transaction fraud
Independently verifies bank details and counterparties in transactions (settlements, escrow, closings, client disbursements) to defeat wire/closing fraud.
Critical · L2 → L3 · Risk addressed: Wire/closing fraud, diverted client funds, large losses.
PRO-004 - Handles sensitive documents and disclosure securely
Manages sensitive documents, e-disclosure/discovery and deliverables securely, with careful redaction, access control and transfer.
High · L2 → L3 · Risk addressed: Disclosure leaks, redaction failures, data breaches.
PRO-005 - Protects client data across multi-client environments
Keeps client data (incl. tax, audit and advisory) segregated and secure across portals, file-exchange and shared tooling, exchanging files only via approved secure methods.
High · L2 → L3 · Risk addressed: Cross-client data exposure, insecure file exchange, breach.
PRO-006 - Manages subcontractor and engagement offboarding of client data
Ensures subcontractors/associates handle client data under agreement, and that client data and access are returned or destroyed when an engagement ends.
Moderate · L2 → L3 · Risk addressed: Lingering access, retained client data, third-party exposure.
PRO-007 - Protects privilege and client confidentiality in every AI interaction
Never puts client-identifying matter information into AI tools outside the firm's approved, confidentiality-preserving environment; checks engagement terms and outside-counsel guidelines before AI touches a matter; and understands that careless AI use can waive privilege.
Very High · L1 → L2 (bridge) · Risk addressed: Privilege waiver via disclosure to third-party AI; client-confidentiality breach (bar/regulator sanctions); conflicts leakage across matters through shared AI context.
PRO-008 - Verifies AI-assisted work product before it reaches a client or court
Checks every AI-assisted deliverable - citations, precedents, figures, valuations, audit evidence - against authoritative sources before filing or delivery, because fabricated authority in professional work product is career-ending and sanctionable.
Very High · L2 → L3 · Risk addressed: Hallucinated case citations and figures in filings/deliverables (Mata v. Avianca-style sanctions); audit/valuation errors at client scale; negligence claims.
PRO-009 - Honors each client's AI rules and discloses AI use as agreed
Knows and applies each engagement's AI terms - some clients prohibit AI on their matters, some require disclosure, some mandate specific tools - and confirms before applying firm-standard AI workflows to a client whose contract says otherwise.
Moderate · L2 → L3 · Risk addressed: Breach of engagement terms/OCGs (fee clawbacks, terminated panels); misrepresentation of AI involvement; conflicting obligations across concurrent engagements.