Background:The 21st Century firewall isn’t technology...it’s people. Given that 95 percent of all security incidents involve a human component, it is critical to address the human factor as part of an overall cybersecurity program.LabCorp identifies cybercrime as a top risk globally. The Office of Information Security has a risk-aware, evidenced-based security strategy that includes an integrated Behavior Management and Communications service line. Our use case, the themed program OIS mission:SAFE, is a multi-modal approach to cybersecurity that includes both active and passive elements. Through persistent engagement and direct feedback, the program builds awareness, educates staff about the realities of cybercrime, and empowers them to become more security conscious.OIS mission:SAFE has two main goals:1) To inspire staff to want to learn about cyber security2) To convert information security from a choice to a habit.Approach:Based on the principles of Social Cognitive Theory and adult learning methodology (ADKAR), the success of OISmission:SAFE draws upon various psychological triggers including: Expectations Behavioral Capability Self-efficacy Reinforcements Reciprocal Determinism Observational LearningOne of the main elements of success is a simulated phishing program, which began as an all-staff approach and has matured to targeted exercises based on divisional, regional, role-based, and cultural insights. Through the simulation program, Resiliency Rate as a KRI, as well as the results of each exercise, drive strategic decisions to enhance support in our most vulnerable areas.Conclusion:Since the program’s inception two years ago, the OIS mission:SAFE program has become a recognized standard of corporate assurance at LabCorp and has produced measurable results for the human factor.