A financial services company identifies a high risk of data breach through phishing attacks.
After a thorough analysis, the company decides to implement a mandatory, quarterly security awareness training program for all employees, deploy an advanced email filtering system, and establish a clear incident response plan.
This combination of actions BEST represents which risk mitigation strategy?