The challenge.
Security teams applied blanket controls — DLP, USB restrictions, training — that frustrated everyone and still missed real risks.
User-level risk was a spreadsheet effort, if it happened at all.
The client wanted targeted controls that respond to the specific risk of a specific user.




