Perfectyash/human-security-reasoning-classifier
0
1text,label2An employee clicks a phishing email pretending to be HR,High Risk3A developer pushes API keys to a public GitHub repository,High Risk4Firewall rules are reviewed and tightened quarterly,Low Risk5An unknown USB drive is plugged into an office computer,High Risk6Multi-factor authentication is enabled for all admin accounts,Low Risk7A server is running an outdated operating system,Medium Risk8An employee reports a suspicious email to IT immediately,Low Risk9Database backups are stored without encryption,High Risk10Antivirus definitions are updated daily,Low Risk11An open port is detected during a routine security scan,Medium Risk12Employees reuse the same password across multiple systems,High Risk13Security awareness training is conducted every six months,Low Risk14A company laptop is lost without disk encryption enabled,High Risk15Access logs are reviewed only after an incident occurs,Medium Risk16Critical systems are isolated using network segmentation,Low Risk17An intern is given admin access without approval,High Risk18Patch management is delayed due to operational workload,Medium Risk19A public Wi-Fi network is used without a VPN for work tasks,High Risk20Security alerts are ignored due to alert fatigue,Medium Risk21Sensitive files are shared through unsecured messaging apps,High Risk22An organization enforces least-privilege access policies,Low Risk23Default credentials are left unchanged on network devices,High Risk24A web application lacks input validation,Medium Risk25Intrusion detection systems are actively monitored,Low Risk26Employees disable antivirus to improve performance,High Risk27Incident response plans are documented but not tested,Medium Risk28Password managers are recommended and enforced,Low Risk29Third-party vendors are not security-audited,Medium Risk30Logs are centrally collected and correlated,Low Risk31A critical vulnerability is publicly disclosed but not patched,High Risk32Developers follow secure coding guidelines,Low Risk33Remote access is allowed without MFA,High Risk34Security patches are applied after testing,Low Risk35Unauthorized software is installed on workstations,Medium Risk36Privileged access is time-bound and monitored,Low Risk37A cloud storage bucket is publicly accessible,High Risk38Employees share credentials to meet deadlines,High Risk39Regular penetration testing is conducted,Low Risk40Alerts are generated but not reviewed daily,Medium Risk41An email gateway blocks known malicious domains,Low Risk