It may evaluate employee cybersecurity practices through interviews, security-awareness reviews or simulated phishing exercises. The goal is not to punish employees, but to identify areas where training and clearer procedures can strengthen the organization’s first line of defense.