What human risk management is, how it differs from annual awareness training, what it measures, and where it goes wrong.
Most cybersecurity work targets systems: patch the flaw, harden the config, tighten the rule. Human risk management (HRM) applies the same discipline to people — measuring how human behaviour actually creates exposure, and reducing it deliberately rather than hoping training worked.
For how it fits a broader strategy, see the deep-dive into human risk management.
How it differs from awareness training
Awareness training is an activity. Human risk management is a measurement discipline that decides which activity to run, for whom, and when.
The traditional model trains everyone identically once a year and records completion. That tells you people attended. It says nothing about whether risk fell.
HRM starts from the opposite end: which people, roles and behaviours actually carry exposure right now, and what would reduce it? Training becomes one intervention among several — alongside policy changes, tighter approval controls, and removing the opportunity for error altogether.
What it measures
- Reporting rates. Are people actively flagging suspicious messages? The clearest sign of genuine engagement.
- Simulation results. How the team performs against realistic, varied lures over time.
- Repeat behaviour. Who clicks across multiple campaigns, as opposed to once on a bad day.
- Role and access weighting. A finance approver clicking matters more than someone with no payment authority. Risk is exposure multiplied by access, not click count alone.
- Resilience scores. A composite that resists being gamed by any single easy metric.
Why per-person measurement changes the response
Averages conceal the thing you need to act on. An organisation at a respectable 8% click rate may have a small group clicking every campaign and a large majority who never do. Blanket retraining wastes the majority's time and under-serves the few who need real help.
Measuring per person lets the response scale with the risk: light-touch reinforcement for most, targeted support for repeat clickers, and role-specific depth for finance, IT, and executives — the people attackers actually pursue.
Moving beyond blame
The older instinct was to name whoever clicked. HRM treats that as counterproductive, and not for soft reasons: people who fear exposure hide their mistakes, and a hidden click is an incident nobody is containing.
The measurable goal is a workforce that reports quickly and recovers well, not one that never errs. Reducing incident frequency and severity is also what produces the training ROI benchmarks that leading organisations report.
Where it goes wrong
Scoring people without helping them. A risk score that produces no intervention is surveillance, not management.
Measuring what is easy instead of what matters. Completion rates are simple to collect and tell you almost nothing.
Treating the score as the goal. The number is an instrument, not the outcome. A programme optimising its dashboard rather than its behaviour will get a better dashboard and no more safety.
Ignoring the conditions that produced the error. If someone approves a fraudulent invoice, the question is not only whether they were trained but whether one person should have been able to approve it alone. Some human risk is best reduced by changing the process rather than the person.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
What Is Social Engineering?
How social engineering manipulates normal human behaviour to bypass security, the forms it takes, and how to build a verify-first culture.
Phishing Email Examples
Seven phishing emails your team will actually receive, what makes each one work, and the two habits that catch them all.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.