Human risk management is an approach to security that measures how people in an organization actually behave, identifies which people and actions create the most risk, and responds with targeted training, prompts and controls. The term is largely an analyst and vendor label, and many products sold under it grew out of security awareness training (SAT). What sets it apart is the emphasis on measuring real behavior, often from several security tools, rather than counting course completions.
At a glance
- Human risk management focuses on changing and reducing risky behavior, not just delivering training.
- It typically uses phishing simulation and training data, and many platforms add signals from email, identity, endpoint and data security tools.
- Risk is often scored by person, team or department so effort goes where it matters most.
- Responses can include short targeted training, real-time prompts and, in some products, tighter controls for high-risk users.
- The scope of what vendors call human risk management varies, so compare data sources and actions, not labels.
What problem it solves
Many breaches start with a person: someone clicks a phishing link, approves a fraudulent payment, reuses a password or shares a file too widely. Organizations have answered that with annual training and periodic phishing tests, but completion rates say little about whether behavior changes. Everyone gets the same content, whether they are a cautious accountant or someone who has failed five phishing tests and has access to the payroll system.
Human risk management treats people risk like other security risk: measure it, prioritize it and track it over time. By combining training results with what security tools already see, such as reported and clicked phishing, risky sign-ins or blocked data transfers, the program can focus attention on the smaller group of people and behaviors that drive most of the exposure, and show leadership whether things are improving.
How it works
Data collection. The platform gathers behavior signals. Most start with phishing simulation results and training activity. Many connect to email security, identity providers, endpoint tools and data loss prevention to add real-world events.
Risk scoring. Signals are combined into a risk view by individual, team, role or location, often weighted by how much access or sensitive data a person handles. A finance approver who clicks links may score higher than an intern who does the same.
Targeted interventions. Instead of one course for everyone, the program assigns short training tied to a specific behavior, sends a prompt at the moment of a risky action, or recognizes good behavior such as reporting phishing. Some platforms can recommend or trigger control changes, such as stronger authentication for high-risk users.
Reporting. Dashboards show trends over time, which helps answer questions from the board, auditors and insurers about whether human risk is falling.
When it matters for buyers
- When training feels like a checkbox. If completion is high but incidents keep coming, measuring behavior is the next step.
- When renewing an awareness training contract. Many SAT vendors now sell human risk features, so compare tiers before switching. See our security awareness training overview.
- After a social engineering incident. Business email compromise (BEC) and payment fraud make people risk visible to executives.
- When insurers or boards ask for metrics. Behavior trends answer “is it working?” better than completion counts.
- When you have many security tools but no view of people. Integration can connect existing alerts to the humans behind them.
Questions to ask vendors
- Which data sources do you use beyond phishing simulations and training, and which integrations are included?
- How is a person’s risk score calculated, and can we adjust the weighting?
- What interventions can the platform deliver automatically, and which need an administrator?
- How do you handle employee privacy, data retention and access to individual scores?
- Which metrics will we see, and can we export them for board or insurer reporting?
- How is it priced, and which features need a higher tier than standard awareness training?
- How much administration does the program need each month?
How it differs from security awareness training
Security awareness training teaches employees to recognize and report threats, usually through courses and phishing tests, and is often measured by completion and click rates. Human risk management includes training but treats it as one response among several. It measures behavior from a wider set of signals, scores risk by person or group and targets action accordingly. In practice the line is blurry: many training platforms have added human risk features, and some products called human risk management are mainly training with better reporting. It is also different from an insider threat program, which focuses on detecting deliberate or negligent misuse of access rather than improving everyday security habits.
