Beyond Annual Training and Phishing Tests: AI is Ushering in Human Risk Management
For years, cybersecurity leaders have wrestled with the "human element." We have provided user awareness training, launched countless phishing tests, and monitored for potentially malicious insider activity. While these efforts have reduced risk, with AI driving increased sophistication of cyber attacks, those traditional activities hardly feel adequate to match the threat. The landscape is changing, though, and AI is helping drive a more effective approach: Human Risk Management (HRM).
HRM is potentially a major step forward in maturity and risk reduction. The core premise is simple: understand each individual’s behaviors and assign risk-informed training, controls, and interventions. This was not feasible in the past, but with AI providing the engine, legit HRM solutions and roadmaps are starting to appear.
At its heart, HRM is built on several key concepts:
A holistic view of each individual's risk: leveraging data from myriad sources – job role, access, security events, privacy incidents, DLP alerts, IT assessments, phishing test results, even physical access logs – to construct an understanding of each employee's unique risk profile.
Risk-informed actions: Based on the holistic view, HRM can enable risk-informed decisions that match individual training, controls, and actions to their demonstrated level of risk. This personalized approach is where HRM shines, moving away from one-size-fits-all approaches.
Being dynamic and continuous: The threat landscape is constantly evolving, and so are human behaviors. HRM is inherently dynamic, continuously monitoring and adjusting risk profiles based on changing risks, new behaviors, and evolving threat intelligence.
Moving down the path of HRM requires:
Leadership Support - Executive buy-in, cross-functional governance, and a management culture of safety, not blame
Creating a comprehensive assessment of human behavioral risks by leveraging available data. Tapping into data from a multitude of sources: security and privacy events, phishing campaign results, policy violation reports, DLP alerts, IT assessment findings, and more to build a comprehensive picture of individual behaviors.
Tying personalized controls to risk profiles - Individually targeted messages, controls, and interventions. AI is the engine that makes this personalization scalable and effective in areas such as:
Tailored training: AI-driven platforms can develop and deploy ongoing cybersecurity training and awareness programs customized to individual or group risk profiles.
Microlearning & role-based scenarios: Deliver bite-sized, relevant content. For instance, a finance employee might receive microlearning modules on invoice fraud based on the volume of suspicious emails they receive, while a developer’s training may focus on secure coding practices.
Targeted just-in-time actions: AI can detect risky behavior in real-time and deliver real-time coaching, nudges to different action, or even interventions that prevent the action, e.g., preventing an employee from sending a document with sensitive data to an unapproved external recipient without manager approval.
Continuous reinforcement: HRM provides continuous reinforcement through regular updates, refreshers, and practice scenarios tailored to individual roles and risks.
Gamification and incentives: HRM can create gamified training experiences and track progress to make security education more engaging. It can also tie to incentive programs and positive reinforcement by tracking good security behaviors.
The shift to Human Risk Management, powered by AI, represents a potentially significant evolution in cybersecurity and may offer a powerful ROI. It may finally provide cybersecurity leaders a defense for the challenge of risky human behaviors. I am digging into where HRM stands today and the roadmap forward, and I recommend cybersecurity programs do the same.
Hold Fast
Stay True

