COMPANY

Accenture

BUSINESS SIZE

Enterprise

INDUSTRY

Professional Services and Consulting

Introduction

Redflags® is a cybersecurity innovator specialising in human-centric security solutions. Its flagship product, Redflags®, is a behavioural risk platform designed to deliver timely, preventative security guidance to users before risky actions occur. In a pioneering deployment at Accenture, a global professional services company with close to 800,000 people, Redflags® has been used to reinforce secure behaviours at an unprecedented scale.

Challenge

Industry research shows that 83% of cyberattacks begin with human error. Accenture has therefore invested heavily in a global security culture and behaviour change programme that includes role-based education, targeted awareness campaigns, phishing simulations, personalised security dashboards, and leadership engagement. These initiatives have helped establish strong security awareness across the organisation. However, Accenture, like many large enterprises, recognised an opportunity to reinforce secure decision-making at the moment employees take action. Real-time, in-workflow support offered a way to complement existing training and help employees apply what they already know in practical situations.

Key challenges

Human error driving 
cyber risk

Moving beyond awareness to action

Real-time reinforcement without disruption

Accenture required a solution capable of embedding secure practices into employees’ daily workflows so that security awareness would extend beyond phishing tests and training courses. Instead, the aim was for secure decision-making to become a natural part of everyday work. The organisation also wanted to provide more targeted support to roles that are frequently exposed to cyber threats, including senior leaders and employees responsible for financial processes.

The goal was to strengthen the security posture of individuals handling sensitive or high-value information while reinforcing positive habits across the wider workforce. In practical terms, Accenture sought a way to prevent risky actions as they occurred while encouraging employees to adopt more secure routines over time. Achieving this required reaching people at their “moment of risk” and offering guidance in real time, without interrupting the pace of their work.

 

 

The Solution

To address this human-factor challenge, Accenture deployed Redflags®, a real-time behavioural security platform, across an initial pilot group of around 9,000 employees. The platform complements Accenture’s existing awareness programme by introducing contextual nudges that support employees during everyday tasks. Rather than replacing security education, Redflags® reinforces it by helping bridge the gap between learning and practice. In practical terms, when an Accenture employee was about to perform a potentially unsafe action, such as clicking a link in an unfamiliar email or leaving their workstation unlocked, Redflags® delivered a short prompt offering guidance at the moment it was most useful. These notifications function as a light-touch reminder, informed by behavioural science principles such as Nudge Theory, encouraging actions like checking a sender address or locking a computer before stepping away.

Key challenges

Real-time behaviour nudges

Redflags® delivered just-in-time prompts at the exact moments risky actions were about to occur.

Micro-targeted risk campaign

Interventions were tailored to high-risk roles and specific behaviours like phishing, password hygiene, and device security.

Seamless on-device integration

A lightweight software agent embedded directly into Accenture’s desktop environment ensured continuous, non-disruptive support.

Positive, voluntary engagement model

Nudges were brief, relevant, and aligned with Accenture’s tone — encouraging voluntary participation rather than enforcement.

 

The deployment was tailored to address specific behaviours that Accenture wanted employees to remain mindful of, particularly in time-sensitive or high-pressure workflows. The nudges supported practices employees had already learned through training. They acted as reminders and helped prevent mistakes before they happened.

Redflags® worked closely with Accenture’s security behaviour change team to identify areas where additional support would have the greatest impact. These included phishing susceptibility, device security, and password practices. Campaigns were then configured to address those behaviours in context.

For example, in a phishing-awareness scenario, if a user hovered over a link from an unfamiliar external sender, a Redflags® prompt would appear asking, “Check the sender: do you know who sent this email?” If the user tried to enter credentials on a suspicious website, another prompt appeared before the action completed. This approach interrupts risky behaviour before it becomes a security incident.

Other initiatives focused on everyday workplace behaviour. One campaign encouraged employees to lock their computers when leaving their desks, reducing the number of unattended workstations across the pilot group. The programme also supported threat-led initiatives, including guidance that warns users about Run Command phishing attempts associated with the ClickFix phishing campaign.

All interventions are delivered through a lightweight software agent integrated into Accenture’s desktop environment. This allows employees to receive guidance while working in email, browsers, and other business applications. Unlike traditional phishing simulations, which happen after mistakes or on a fixed schedule, Redflags® operates continuously. It responds directly to user behaviour as it occurs.

The deployment proved technically straightforward. Redflags®’ on-device integration allowed the platform to run across thousands of endpoints without affecting system performance. Prompts were brief and constructive, using Accenture’s communication style so they felt familiar and unobtrusive.

Participation was voluntary, and employees were not required to respond to the prompts. Even so, engagement was consistently high. About 89% of employees interacted with the guidance during the pilot, showing the interventions were relevant and timely.

 

 

The Results

The Redflags® deployment at Accenture produced measurable improvements in both employee behaviour and programme engagement. During the pilot phase, the organisation observed a reduction in several high-risk actions alongside increased attention to everyday security practices.

%

reduction in targeted, 
risky behaviour.

%

story engagement (around 6% above Redflags average) allowing Accenture to establish an effective communication channel with high-risk groups.

These metrics point to a meaningful reduction in human cyber risk. Behaviours that commonly lead to breaches, such as clicking suspicious links or leaving devices unsecured, improved within three months of Redflags® going live.

The improvements were not only statistically significant but also operationally relevant. Fewer risky actions reduce the likelihood of security incidents, while higher engagement strengthens the organisation’s ability to detect and respond to potential threats.

Engagement levels also compared favourably with traditional awareness programmes. Many organisations struggle to achieve high completion rates for annual training modules, yet Accenture employees interacted with the Redflags® prompts during their normal work routines.

The average engagement rate reached 89%, with some campaigns exceeding 90% acknowledgement or interaction. Participation at this level is uncommon in the security awareness field, particularly where programmes are neither mandatory nor incentivised. The results suggest that employees regarded the prompts as useful guidance delivered at the right moment. In this way, the initiative supports Accenture’s broader emphasis on maintaining an “always on” and “ever vigilant” security posture, where secure behaviour is integrated into everyday work rather than treated as a periodic exercise.

 

 

Conclusion

The deployment of Redflags® at Accenture demonstrates the practical value of behavioural approaches to cybersecurity. By introducing contextual guidance into daily workflows, Accenture strengthened an already mature security culture while helping employees make safer decisions during routine tasks.

For Accenture, the platform provides an additional layer of support that complements existing training and awareness initiatives. Employees receive timely reminders that reinforce secure habits while allowing them to remain focused on their work.

For Redflags®, the project represents an important milestone. The deployment shows that behavioural security interventions can operate effectively at enterprise scale while integrating smoothly into complex corporate environments.

More broadly, the case highlights how organisations can reduce cyber risk by combining technical safeguards with behavioural insight. When employees receive guidance that is timely and relevant, they are more likely to adopt secure practices and maintain them over time.

As Accenture continues to expand the programme, the results offer a useful reference point for other organisations seeking to strengthen their human-centric security strategies. Supporting employees at the moment decisions are made allows security awareness to move beyond periodic training and become part of everyday behaviour.