Everyone is using the same words. They are not necessarily describing the same thing.
Human Risk Management is having a very good year. Security awareness platforms have become Human Risk Management platforms. Phishing simulation products have become Human Risk Management platforms. Behavioral tools, security telemetry products, risk-scoring systems and increasingly AI-powered content platforms are all finding ways to describe themselves in the same language.
Some of that evolution is entirely legitimate. Security awareness has become more sophisticated, behavioral data is becoming easier to access, learning platforms are expanding into measurement, and the boundary between traditional awareness and broader workforce risk has been dissolving for years. The trouble begins when a useful new category becomes elastic enough to absorb almost anything involving an employee and cybersecurity. At that point, two products can carry the same Human Risk Management label while having profoundly different ideas about what human risk is, how it should be measured and what an organization is supposed to do about it.
That is not merely a branding problem. It makes it harder for organizations to work out what they are actually buying, and it risks reducing Human Risk Management to another familiar technology cycle: take the capabilities we already had, add more data, give the dashboard a new title and declare the category transformed.
Our view at Cybermaniacs is that Human Risk Management should be defined by the management capability it creates, not by the collection of features assembled underneath the name.
A phishing simulation can contribute to Human Risk Management. So can security awareness, behavioral evidence, culture research, security telemetry, risk scoring, communications and AI-enabled learning. None of those capabilities, on its own, is a definition of Human Risk Management.

When Every Cybersecurity Product Becomes Human Risk Management
Software categories have a habit of expanding once the market decides there is value in the name. Adjacent vendors broaden their positioning, features migrate between products and, before long, companies with very different origins and methodologies appear beneath the same category heading.
That does not require anyone to be acting in bad faith. Categories genuinely do evolve. Fifteen years ago, security awareness technology largely meant delivering training and tracking completion. Modern programs can incorporate adaptive learning, realistic simulations, segmentation, communications, behavioral data, culture measurement and much richer analytics. It would be odd if the category around those programs had remained frozen.
What matters is whether the newer term creates useful distinctions or merely removes them.
Human Risk Management should imply a capability for understanding relevant human-related cyber risk, determining what deserves attention, choosing appropriate interventions, measuring whether meaningful change occurs and adapting as the organization changes. If a product performs one part of that job exceptionally well, that can make it a valuable component of an HRM ecosystem. It does not automatically mean it performs the whole management function.
A useful Human Risk Management component and a Human Risk Management capability are not the same claim.
That distinction matters because the word management carries an expectation. We are no longer simply observing activity or delivering an intervention; we are suggesting that the organization can use the resulting evidence to make better risk decisions.
Training, Phishing and a Risk Score Still Aren't a Definition
Security awareness and phishing simulation are obvious places to start because they have provided much of the industry's human-risk data for years.
And rightly so. Learning can build knowledge, capability and confidence. Simulated phishing gives employees an opportunity to practice detection and reporting while providing useful evidence about what happened in a controlled scenario. We offer both because they remain important parts of a strong security program.
The problem is not the data. It is what we sometimes ask the data to become.
A training completion rate tells us whether somebody completed the assigned learning. A phishing simulation tells us how a person or population responded to a particular exercise. An assessment result can tell us something about knowledge or capability under defined conditions. Those are useful pieces of evidence, but none arrives with a certificate declaring that it represents the employee's overall cyber risk.
Our guide on Security Awareness vs. Human Risk Management explores that distinction in more depth. Better awareness remains valuable; HRM adds a wider ability to understand why risk may be occurring, determine whether learning is the right response and measure whether the condition the organization actually cared about changed.
Phishing illustrates the point particularly well. Clicking a simulated malicious link is observable behavior, and repeated patterns may tell us something important. The exercise cannot, by itself, explain the person's wider capability, confidence, judgment, organizational pressures, cultural environment or behavior across every other part of the security landscape.
That does not make phishing simulation a weak tool. It makes it one tool with a defined evidential boundary.
The same discipline should apply to everything we call Human Risk Management.
“Behavioral” Does Not Mean We Understand Behavior
Cybersecurity can observe more workforce behavior than ever before. That is potentially transformative for HRM because it moves programs beyond relying entirely on what people say they know or what they do inside a training platform.
What it does not mean is that an observed behavior arrives with its explanation attached.
An employee might click, report, bypass, approve, escalate, share, ignore or challenge something. Those are behaviors. Understanding why they occurred may require a very different set of questions about knowledge, confidence, motivation, incentives, workload, norms, process design, technology, leadership and the employee's previous experiences with security.
This is one of the places where the category can become conceptually loose. A platform may legitimately contain behavioral telemetry while another uses behavioral science to understand why decisions occur and how interventions might influence them. Both can use the word behavior, but they are not necessarily doing the same work.
NIST's Human-Centered Cybersecurity program is helpful precisely because it treats cybersecurity as an interaction between people, processes and technology, with empirical understanding of human behavior informing how secure systems are designed and operated. That wider perspective matters when HRM starts moving from “we observed an event” toward “we think we understand the risk.”
Behavioral evidence expands what we can see. Behavioral science helps us resist overclaiming what that evidence means.
Culture Is Bigger Than a Survey — and Much Bigger Than a Content Library
Culture has acquired a similar elasticity.
A platform can survey employee attitudes and gain useful evidence about how security is experienced. A learning program can reinforce shared expectations and make cybersecurity more visible. Communications can shape norms. Leadership campaigns can change what people believe the organization genuinely values.
All of those can contribute to security culture, but none is culture in its entirety.
The UK's National Cyber Security Centre defines cyber security culture as the collective understanding of what is normal and valued in the workplace with respect to cybersecurity. Its Cyber Security Culture Principles look beyond awareness activity toward leadership, social norms, trust, psychological safety, working conditions and the realities of how people get work done.
We unpack that framework in NCSC Cyber Security Culture Principles: What They Are and Why They Matter, including where we think the NCSC guidance is particularly useful and why we treat culture as part of a wider organizational system.
That wider view prevents culture from becoming the soft-looking tab beside the risk-score tab.
Someone may know the policy perfectly well and still work around it because the secure route makes their job nearly impossible. A team may score well on a sentiment survey while having learned that reporting mistakes carries social or professional consequences. An annual training campaign may tell employees that security matters, while senior leaders teach the opposite lesson every time a commercial deadline wins.
Culture is what people learn from the organization as a whole, not simply what the organization says in the learning module.
AI Can Generate More Content. That Does Not Mean the Program Needed More Content.
Generative AI adds another wrinkle because it radically reduces the cost and effort required to produce learning assets. Video can be generated quickly. Avatars can speak almost any script. Content can be localized, remixed and personalized at a scale that would have been prohibitively expensive only a few years ago.
That can be genuinely useful.
It can also allow us to repeat an old mistake with much better production technology: assuming the problem was insufficient content.
If an organization does not understand which risk condition it is trying to influence, which population is experiencing it or what evidence would demonstrate improvement, generating another fifty modules simply gives the program fifty more things to distribute. The production economics have improved; the behavioral problem has not necessarily changed.
There is also a quality question hiding beneath the efficiency argument. Cybersecurity learning competes with the employee's actual job, internal communications, mandatory training, notifications, meetings and every other demand on attention. Content that feels generic, synthetic or conspicuously impersonal may work perfectly well for some audiences and undermine credibility with others. Tone, authenticity, relevance, humor, context and the relationship employees already have with the security team all affect how a message lands.
“We can make more of it for less” is a production proposition. It is not, by itself, a behavior-change strategy.
This is why we think AI belongs inside Human Risk Management rather than simply inside the content factory. AI should help programs become more adaptive and capable, but the underlying questions still concern people, risk, evidence and outcomes.
Human Risk Scores Can Hide the Definition Problem
A risk score creates an appealing sense of closure. Multiple observations go in, one number comes out, and suddenly a messy human system appears to have acquired the precision of a credit rating.
Scores can be extremely useful. They help summarize complexity, identify priorities and communicate with leaders who understandably do not want to inspect dozens of separate indicators every morning.
The interesting question is what has been encoded into the score.
Two platforms can both display something called a Human Risk Score while drawing very different conclusions from very different evidence. One may be driven heavily by simulated phishing outcomes, another by security telemetry, another by learning activity, another by surveys or assessments, and another by some combination of those sources.
The label on the dashboard tells you very little about the underlying definition of risk.
That becomes increasingly important when scores start influencing prioritization, comparisons between populations, executive reporting or decisions about intervention. A score is where a vendor's definition of human risk becomes operational, whether or not that definition has ever been made particularly explicit.
Our guide What Should Human Risk Management Actually Measure? goes deeper into this problem. We distinguish program measures, underlying health measures, event and flow data, targeted measures of change and the thresholds an organization chooses to monitor. The point is not to create a larger taxonomy of numbers; it is to recognize that different measures have different purposes, cadences and evidential limits.
NIST's current SP 800-55 guidance on information security measurement makes the same broader distinction between merely producing metrics and building a measurement discipline capable of selecting, validating, interpreting and using them well.
A Human Risk Management dashboard may be an excellent interface to that discipline. It is not the discipline itself.
Human Risk Management Is a Management Discipline, Not a Data Category
The amount of workforce-related security data available to organizations is likely to grow substantially. Learning platforms, phishing tools, identity systems, collaboration environments, DLP, SIEM, security operations tooling and AI systems can all contribute potentially relevant evidence.
It would be very easy to define Human Risk Management as all cybersecurity data involving humans.
It would also be almost useless.
A management discipline needs more than observation. The organization has to decide which conditions matter, determine whether the available evidence is good enough to support a conclusion, choose a proportionate response and examine whether the expected change occurred. When the answer is ambiguous—as it often will be with humans—the program needs enough analytical and organizational capability to investigate further rather than simply allowing the dashboard to make the decision by default.
This is also why Human Risk Management needs more than one intervention channel. Learning may be appropriate. So might simulation, communication, manager involvement, policy clarification, process redesign, a technical control, culture work or a deeper investigation into why employees are behaving as they are.
If the only response available when a risk indicator moves is “assign training,” then the sophistication of the measurement system has already outgrown the sophistication of the management system.
Our guide on Human Risk Management as an Operating Model, Not Just a SaaS Platform explores that problem from the program side. Technology can create extraordinary visibility and scale, but somebody still has to understand the evidence well enough to decide what the organization should do with it.
The Human Part Does Not End at the Employee
There is another definitional trap worth avoiding: treating Human Risk Management as the science of identifying risky employees.
Sometimes individual capability and behavior absolutely matter. But human-related cyber risk also emerges from systems built around people.
Poor process design can invite workarounds. A badly implemented security control can create incentives to bypass it. Leadership behavior can tell employees which rules really matter. Organizational restructuring can disrupt trusted relationships and established workflows. Workload, role changes, incentives and competing commercial pressures can all alter how security decisions are made even when the people themselves have not changed.
The NCSC's people-centered guidance makes this point explicitly by encouraging organizations to understand the circumstances surrounding behavior rather than assuming that insecure action reflects a lack of awareness. Its Putting People at the Heart of an Organisation's Approach to Cyber Security guidance considers values, social influence, capability, effort and environmental conditions as part of the behavioral picture.
That matters for HRM because a discipline that only studies the employee while treating the system around them as fixed can end up locating the problem in the wrong place.
The person may be behaving quite rationally inside an organizational system that has made the secure behavior difficult, unrewarded or socially costly.
Understanding that distinction is much more useful than simply deciding they need another red score.
AI Is About to Stretch the Definition Again
AI makes these boundaries harder to ignore because the relationship between human action and technology is changing rapidly.
Traditional HRM often assumes a reasonably clear unit of analysis: an employee learns something, makes a decision and takes an action. AI-enabled work complicates that sequence. An employee may delegate work to a Copilot or agent, accept or reject a recommendation, supervise automated activity, decide when to intervene, provide sensitive context to a system or act on output whose reasoning they cannot fully inspect.
Now the risk may not reside neatly in either the person or the technology.
It can emerge from the relationship between them.
That is why we increasingly argue that AI governance needs to consider the human-agent system, including trust, judgment, delegation, oversight, role clarity and the conditions under which people challenge or rely on automated work. Technical controls remain essential, but governing what an AI system can do is only part of the problem once humans and agents begin sharing consequential work.
Our AI Workforce Risk Management work explores that human layer of AI governance, while AI Enablement & Change Management (AIECM) and Agentic Readiness & Change (ARC) help organizations address workforce readiness, capability, adoption, oversight and change as AI becomes embedded in everyday operations.
A definition of Human Risk Management built mainly around phishing susceptibility and awareness activity will struggle with that future because the nature of the human-risk question itself is changing.
So What Should Count as Human Risk Management?
We do not think the answer is to produce a rigid checklist and eject anybody whose product does not contain precisely the right combination of features. HRM is still developing, and organizations will reasonably assemble the capability in different ways.
A useful definition does need boundaries, however.
At Cybermaniacs, we think Human Risk Management is best understood as an organizational capability for understanding the human factors that contribute to cyber risk, deciding where intervention is warranted, influencing the relevant behaviors or conditions, measuring whether meaningful change occurs and adapting the program as the organization evolves.
That can involve many different capabilities:
- cybersecurity learning and competency development;
- phishing and social-engineering testing;
- behavioral and security-event evidence;
- human and organizational assessment;
- security culture;
- communications and campaigns;
- program governance and operations;
- measurement and analytics;
- organizational change;
- leadership and manager involvement;
- and, increasingly, AI workforce and human-agent risk.
The important distinction is that these are inputs, evidence sources and intervention capabilities. Human Risk Management is the ability to put the right ones together around a defined risk problem and use them coherently.
A phishing platform does not need to become organizational anthropology to be an excellent phishing platform. A learning provider does not need to become a behavioral-research organization to produce excellent learning. Specialization is useful. The problem begins when the category label implies a breadth of understanding and management capability that the underlying product does not actually provide.
How Cybermaniacs Defines the Territory
Cybermaniacs uses a deliberately broad definition of Human Risk Management because the problems our clients bring us rarely fit neatly into one software category.
Sometimes the organization needs a better understanding of its current human-risk condition. ASSURE provides that diagnostic and baseline capability. Sometimes the need is continual workforce competency, where CLX provides structured learning and adaptive development. Sometimes simulation and behavioral evidence matter; elsewhere the problem is program strategy, operating maturity, communication, culture or an intervention that needs to be built specifically for the organization. MANAGE and CHANGE exist because those problems do not disappear simply because the SaaS platform has run out of menu options.
We do not think every organization needs every one of those capabilities at once, and we do not think every human-risk problem should end with either a training assignment or an employee score. The point is to have enough evidence, analytical depth, intervention range and practitioner expertise to understand the problem before deciding what to do about it.
Increasingly, that same thinking extends into AI-enabled work. AIECM and ARC are not separate because AI somehow sits outside Human Risk Management; they exist because AI is changing the human, organizational and technological conditions the HRM program now has to understand.
There is plenty of proprietary machinery underneath how Cybermaniacs does that work—measurement models, analytical approaches and methodologies that quite reasonably stay in the kitchen. The public proposition is simpler: Human Risk Management should help an organization understand something important about risk and become better able to act on that understanding.
A Useful Category Should Become More Precise as It Matures
Human Risk Management is still young enough that its definition will continue to move, and that is probably healthy. Better behavioral evidence, richer security telemetry, more sophisticated measurement and the rapid arrival of AI-enabled work will all stretch the discipline beyond where security awareness programs began.
The danger is not that HRM becomes broad. Human-related cyber risk genuinely is broad, and attempts to reduce it to a single behavior, score or technology would miss much of what makes the problem difficult in the first place.
The danger is that the category becomes broad without becoming more precise.
If every piece of security technology that produces an employee-related signal can be described as Human Risk Management, the term eventually stops helping organizations distinguish observation from understanding, activity from change, or a useful component from a functioning management capability. The category will mature when buyers can ask harder questions about what is being measured, what can legitimately be inferred from it, what organizational conditions are involved and what the program can actually do differently as a result.
That is a harder standard than adding HRM to the navigation bar.
It is also a much more interesting discipline to build.
Frequently Asked Questions
What is Human Risk Management?
Human Risk Management is an organizational capability for understanding human factors that contribute to cyber risk, deciding where intervention is warranted, influencing relevant behaviors or conditions, measuring meaningful change and adapting the program as the organization evolves.
Is phishing simulation a Human Risk Management platform?
Phishing simulation can be an important component of Human Risk Management because it provides behavioral evidence and opportunities for employees to practice threat detection and reporting. On its own, however, it represents one class of intervention and evidence rather than the full HRM capability.
Is security awareness training the same as Human Risk Management?
No. Security awareness is an important Human Risk Management intervention focused on building workforce knowledge, capability and confidence. HRM extends beyond learning into measurement, organizational context, behavior, culture, additional interventions, program operations and risk decision-making.
What does behavior mean in Human Risk Management?
Behavioral evidence records what people do, such as reporting, clicking, escalating or bypassing. Understanding behavior may also require evidence about knowledge, motivation, confidence, norms, workload, technology and organizational conditions. Observing behavior and explaining it are related but different capabilities.
Is security culture part of Human Risk Management?
Yes. Security culture influences what employees understand to be normal and valued and can support or undermine secure behavior. Culture is shaped by factors including leadership, social norms, trust, working conditions and organizational practices rather than by training alone.
Is a human risk score the same as measuring human risk?
No. A score can summarize or combine measures and may be useful for prioritization or communication. Human-risk measurement requires understanding what the underlying evidence represents, its limitations, how it changes and what conclusions or decisions it can reasonably support.
Can AI-generated training create a stronger security culture?
AI can make learning production faster, cheaper and easier to personalize, but content volume alone does not create culture. Effective culture and behavior-change work depends on relevance, trust, organizational context, leadership, norms, working conditions and choosing interventions that match the problem.
How does Cybermaniacs define Human Risk Management?
Cybermaniacs defines Human Risk Management as an organizational capability for understanding the human factors contributing to cyber risk, choosing appropriate interventions, measuring meaningful change and adapting as the organization and risk environment evolve. Our approach connects learning, behavior, culture, measurement, program operations and increasingly AI workforce risk.