Make the easiest attack path a dead end
Most incidents start with a password, a phish, or an account nobody turned off. The annual goal is an attack surface where the cheap paths are gone; this quarter closes the three doors attackers actually use.
Employee accounts protected by phishing-resistant MFA 40% → 100% of the employee accounts
How it is measured: Employee accounts on hardware-key or passkey MFA, over all employee accounts
Baseline: 40% · Target: 100%
Initiatives
- Hand out hardware keys with a 30-day cutover date and a help desk hour
- Turn off SMS and app-code fallback once a team is fully enrolled
Employees who clicked the quarterly phishing test 18% → 4% of the employees tested
How it is measured: Test-phish clicks over employees tested
Baseline: 18% · Target: 4%
Initiatives
- Send a two-minute debrief to every clicker the same day, no shaming
Median hours from an employee leaving to all access removed 72 → 2
How it is measured: Median hours between departure and last credential revoked
Baseline: 72 hours · Target: 2 hours
Initiatives
- Drive offboarding from the HR system so access ends when employment does