Cybersecurity has a human dimension

Firewalls, multi-factor authentication, Zero Trust architectures and advanced access management are essential elements of modern cybersecurity. Yet even the best technology cannot fully secure one critical factor: people.

The Swiss Federal Office for Cybersecurity (BACS) highlights this development in its 2026/1 semi-annual report. During the first half of 2026, BACS received 27,128 voluntary reports and 200 mandatory reports of cyber incidents. At the same time, cybercriminals are increasingly using artificial intelligence to create personalised and more convincing attacks.

This puts the targeted manipulation of employees increasingly into focus. Effective cybersecurity therefore requires organisations to consider technical and human risks together.

Human risk differs significantly between roles

Not every employee represents the same risk profile. An employee with limited system access has a very different potential impact from a system administrator with privileged access.

The same applies to a CFO with extensive payment authority, employees handling sensitive personal data, R&D specialists with access to intellectual property, or executives with strategic information.

The relevant risk therefore does not arise from the individual alone. It results from the combination of the person, their role, responsibilities, access rights and potential impact.

Human Risk Management should start here: classify roles according to their actual risk exposure and define appropriate measures for each risk level.

From background checks to the Employee Lifecycle

Traditional background checks are often conducted before employment. This is an important safeguard, but it represents only one point in the Employee Lifecycle.

Roles and risks evolve. Employees are promoted, receive additional system privileges, assume financial authority or move into security-critical positions. A modern approach should therefore consider the complete lifecycle: Pre-Employment, Onboarding, Employment, Role Change or Promotion, Periodic Review and Offboarding.

This does not mean continuously screening every employee. Instead, organisations should identify roles with elevated risk exposure and implement proportionate measures accordingly – ranging from background screening and access management to awareness programmes and periodic reviews.

Proportionality is essential in Switzerland

Risk-based Human Risk Management must not become indiscriminate employee surveillance. Swiss employment and data protection requirements set clear boundaries.

The Federal Data Protection and Information Commissioner (FDPIC), for example, states that debt-enforcement or criminal-record extracts must be relevant to the specific role. Such checks may be justified for positions of trust or roles involving customer accounts, cash, safes, valuable goods or significant financial amounts. Systematically checking all employees, by contrast, cannot be justified.

A similar risk-based principle can be found in the Swiss Confederation’s personnel security screening system, where the scope of checks depends on the security sensitivity of the role.

The principle is simple: The objective is not maximum screening, but the right screening for the relevant risk.

Human Risk Management belongs on the management agenda

Human Risk Management sits at the intersection of HR, Cybersecurity, Compliance, Risk Management and Corporate Governance. These functions should jointly determine which roles are particularly critical and which measures are appropriate.

Three questions provide a useful starting point: Do we know which roles are critical from a human-risk perspective? Have we classified these roles according to their actual risk exposure? And have we defined appropriate measures for different risk classes throughout the Employee Lifecycle?

Companies already protect their systems, data, finances and infrastructure through structured, risk-based approaches. Human risk should be managed with the same discipline.

Human Risk Management does not start with more control. It starts with understanding where the risks are.

Human Risk Management with Validato

Validato supports organisations in identifying critical roles, developing risk-based Human Risk Management frameworks and implementing appropriate background screening throughout the Employee Lifecycle.

The result is an approach that combines security, compliance and proportionality.

Talk to our experts about how a risk-based Human Risk Management Framework can be designed for your organisation.

Sources: Swiss Federal Office for Cybersecurity (BACS), Semi-Annual Report 2026/1; Federal Data Protection and Information Commissioner (FDPIC), Data Processing by Employers; State Secretariat for Security Policy (SEPOS), Personnel Security Screening.