Escalation Managers: Supervisory Oversight & Manager-Led Accountability¶
Platform Feature:
Escalation Managers
UI Location:Main Navigation > Human Attack Surface > Escalation Managers (/employee-escalation-manager)
Associated Settings:Settings > Platform Management > Escalation Notification Configuration
Remediation Workflows: Weekly Supervisory Risk Digests, Overdue Training Escalations, Repeat Failure Notifications
1. Executive Summary & Value Proposition¶
Security awareness programs frequently fail when treated strictly as an "IT problem." When security teams are the only ones nudging employees, completion rates stagnate and repeated simulation failures go unaddressed. True organizational resilience requires operational accountability: direct line managers must have visibility into their team's security behaviors.
Escalation Managers (/employee-escalation-manager) establishes an automated chain of supervisory oversight. By linking employees to their respective department managers, SimuPhish delivers automated supervisory risk summaries, alerts managers when team members repeatedly fail phishing tests, and escalates overdue compliance training directly into management review loops.
2. The Operational Problem Solved¶
- The "Security Silo" Failure: Line managers often have zero visibility into whether their direct reports are falling for phishing lures or ignoring mandatory compliance courses until a real breach occurs.
- Nudge Fatigue: Generic automated emails from "noreply@security" are easily filtered or ignored by busy employees. When a direct supervisor follows up personally, training completion rates skyrocket.
- Enforcing Consequence Models: Enterprises with formal security consequence frameworks require transparent, auditable manager notification trails when policy thresholds are breached.
3. How It Works (The User Journey)¶
sequenceDiagram
autonumber
participant Engine as SimuPhish Behavioral Engine
actor Employee as Corporate Employee
actor Manager as Assigned Escalation Manager
actor CISO as Security Leadership
Employee->>Engine: Fails 2nd Simulated Phishing Attack within 30 Days
Engine->>Engine: Evaluates Escalation Rule Criteria
Engine->>Manager: Dispatches Automated Supervisory Escalation Digest
Note over Manager: "Action Required: Team member Sarah Jenkins has failed 2 simulations."
Manager->>Employee: 1-on-1 Coaching & Direct Follow-up
alt Overdue Mandatory Remediation Course
Engine->>Manager: Second Escalation (Overdue Warning)
Engine->>CISO: Elevated Incident Logged in Incident Escalation Queue
end
The Administrator Experience¶
- Assign Escalation Managers: Navigate to
Human Attack Surface > Escalation Managers (/employee-escalation-manager). Managers are mapped automatically via directory manager attributes (from Entra ID / Okta) or assigned manually across departments. - Configure Notification Cadence: Under
Settings > Platform Management > Escalation Notification Configuration, customize: - Weekly/Monthly Digest: Automated management summary showing team participation, pass rates, and open risks.
- Trigger Thresholds: Trigger instant notifications after 1st, 2nd, or 3rd consecutive simulation failure.
- Grace Period Cutoffs: Define how many days an employee has to complete remedial training before their supervisor is notified.
- Audit Compliance Records: Full timestamped history of manager escalations is permanently archived in the Compliance Trail (
/compliance-trail).
4. Key Business Benefits & Measurable ROI¶
- 95%+ Training Completion Rates: Introducing direct manager visibility eliminates overdue course backlogs within weeks.
- Fosters Shared Security Responsibility: Transforms line managers into active partners in the enterprise security program.
- Defensible HR & Governance Alignment: Provides objective, verifiable documentation for corporate performance reviews and audit compliance.
5. Target Stakeholders & Governance Roles¶
- Primary Users: VP of Human Resources, CISO, Department Heads, Internal Audit Directors.
- Compliance Mapping: SOC 2 Type II CC2.1 (Enforcing Operational Accountability), ISO 27001:2022 Control 5.4 (Management Responsibilities).