ARTICLE MSSP

Why Human Risk Management Is Becoming an MSSP Problem

SHARE
By Team CM · Oct 10, 2026, 9:08:30 AM
Why Human Risk Management Is Becoming an MSSP Problem

Security awareness has traditionally sat in its own corner of the security program. Employees complete training, phishing simulations generate a set of behavioral metrics, and the organization gets a record showing that people have been told what they are expected to know.

That model has always been limited, but for a long time it was workable. Most awareness programs were designed around a reasonably stable set of assumptions: employees should recognize common threats, know the policies, avoid obvious mistakes and report suspicious activity. If performance was poor, the usual response was more training.

The problem is that a growing share of human-related cyber risk now sits outside that narrow frame.

Kaseya’s 2026 cybersecurity research is a useful example. Its report, Building Security That Survives Human Error, draws on responses from 1,132 MSPs and IT professionals across more than 60 countries. Sixty-eight percent identified human error, including social engineering and distraction, as a leading threat concern for the year ahead. Among respondents whose organizations had experienced an incident, 41% cited poor user practices or gullibility as a contributing factor, while 40% pointed to insufficient end-user cybersecurity training.

Those findings will sound familiar to most security providers. The more interesting issue is how much is hidden inside the phrase “human error.”

What “human error” actually hides

Consider a fraudulent payment approved by someone in finance. The event may eventually be recorded as a human error, but that description does not tell us much about why it happened.

The employee may not have known the correct verification process. They may have understood the process perfectly well but acted on an urgent request that appeared to come from the CEO. The official control may have been so cumbersome that the team had developed an informal shortcut months earlier. The person may have been distracted or under pressure, or working in a culture where challenging a senior executive carries social or professional risk. Increasingly, the request may also have included an AI-generated voice message, video or convincing chain of contextual information that made the interaction look legitimate.

These situations involve different combinations of knowledge, judgment, process design, organizational pressure, culture and technology. Grouping them together under one label makes the resulting response less precise.

Training can address a genuine knowledge gap. It will do much less when the underlying problem is a badly designed process or a working culture that discourages verification. In those cases, the organization may need to change the workflow, strengthen a control, improve escalation routes or address the way managers respond when employees challenge a request.

The issue is not whether training has value. It does. The issue is whether the organization understands the cause of the behavior well enough to know when training is the right intervention.

That distinction is becoming more important because AI is changing the quality of the situations people are being asked to judge.

AI is changing the decisions people have to make

Much of the discussion about AI and cybersecurity has focused on what attackers can now produce: better phishing emails, convincing voice clones, synthetic video, automated reconnaissance and highly personalized social engineering.

All of that matters. But AI is also changing normal work inside organizations.

Employees are increasingly using AI systems to draft communications, summarize information, analyze data, make recommendations and support decisions. They are deciding what information to trust, what to verify, what to share, when to challenge an output and when to escalate something that does not look right.

That means the human side of cyber risk is expanding beyond threat recognition.

A finance employee may have to decide whether an apparently legitimate request is authentic. A developer may have to judge whether AI-generated code introduces a security problem. A manager may have to decide whether an AI-generated analysis is reliable enough to act on. An employee using an approved AI tool may have to understand what data can be shared and what should remain inside controlled systems.

These are not simply awareness questions. They involve judgment, trust, process, context and organizational norms.

This is one reason traditional awareness metrics are becoming less useful as the sole measure of human security performance. A phishing click rate can tell you something about one type of behavior under one type of condition. It cannot explain how employees respond to ambiguity, authority, pressure, AI-generated information or badly designed workflows. Organizations need a broader view of the conditions that influence security behavior.

Why this creates a different role for MSSPs

MSSPs already see a large part of the problem.

They monitor alerts, investigate incidents, operate technical controls, review identity activity, support compliance programs and help customers understand what is happening across their environment. When something goes wrong, the technical evidence often arrives first.

The human and organizational conditions behind that evidence are harder to see.

A customer may experience repeated account compromise and describe the problem as poor user behavior. The pattern may actually involve a combination of weak verification practices, confusing identity processes and a workforce population under unusual pressure. Another customer may have excellent training completion rates but still see employees working around controls because the approved process interferes with operational deadlines.

Without that context, the MSSP can address the technical consequence while the underlying conditions remain in place. This is where Human Risk Management begins to overlap with the broader security service.

A mature HRM program looks beyond whether someone completed training or clicked a simulated phish. It considers what people know, how they behave, what influences their decisions, how the organization supports or undermines secure behavior, and whether those conditions are changing.

For MSSPs, that creates an opportunity to connect information they already have with a deeper understanding of how risk is being produced inside the organization.

Human risk intelligence can complement security intelligence

This does not mean assigning a simplistic “risk score” to every employee or turning the security program into a surveillance exercise.

The useful opportunity is at the level of patterns.

Security systems already produce large amounts of information about identity, email, data movement, reporting behavior, incidents and control failures. Human risk programs can add another layer of evidence around competency, behavior, culture, workforce conditions and organizational practices.

Taken together, those signals can help answer better questions.

Is a particular business unit showing a recurring pattern of risky workarounds? Are employees reporting suspicious activity less often even though threat volume is increasing? Does a population understand the policy but consistently fail to follow it? Are incidents concentrated around a process that creates unnecessary pressure or ambiguity?

Those are much more useful questions than asking whether the workforce is “good” or “bad” at security.

MSSPs are well placed to participate in this because they already operate close to the technical evidence. The human-risk layer can add context to events they are already seeing, while the technical layer can provide evidence that an awareness platform would never see on its own.

This changes the commercial conversation too

For years, awareness training has often been bought as a standalone product or compliance requirement. That naturally limits the conversation to licenses, content libraries, phishing simulations and completion rates.

Human Risk Management creates a different type of discussion.

If a customer says that people are one of its largest cyber risks, the next step should be to understand what is driving that risk. In some organizations, the problem may genuinely be low competency. In others, the stronger drivers may sit in process design, role pressure, culture or the way controls operate in practice.

Once the provider can distinguish between those conditions, the service becomes more useful. It also becomes more closely connected to the customer’s wider security program.

The commercial opportunity follows from that change in scope. An MSSP can move from supplying or referring an awareness product to helping a customer establish a baseline, interpret patterns, prioritize interventions and measure whether the conditions behind the risk are changing.

That is a more substantial relationship because it is tied to the customer’s actual security problems rather than to a content calendar.

Where Cybermaniacs fits

Cybermaniacs has been moving in this direction for several years.

Our Human Resilience System is designed around the idea that human cyber risk cannot be understood through training data alone. We combine continuous learning, simulation, measurement, workforce risk intelligence, culture and organizational insight with advisory and intervention services.

The models behind the platform look at competency, behavior, psychology, culture and organizational conditions because those dimensions help explain why similar incidents can emerge for very different reasons.

For partners, the practical point is straightforward. An MSSP does not need to build all of that capability internally in order to offer a stronger human-risk service.

Some partners may want a more complete managed awareness capability. Others may want to introduce a Human Risk Baseline for customers that need a clearer picture of their exposure. Some may want human-risk intelligence to sit alongside existing SOC, identity, GRC or advisory services. Others may bring Cybermaniacs into specific customer engagements where the problem extends beyond training.

The delivery model can vary. The underlying shift is the same: human risk is moving closer to the core security conversation.

The next stage of Human Risk Management

Kaseya’s research captures a problem the market has understood for years: people remain involved in a large proportion of security failures, and many organizations do not feel adequately resourced to deal with that exposure.

The useful next step is to stop treating “human error” as a sufficient explanation.

If a customer repeatedly experiences human-related incidents, the provider needs to know whether the cause sits in knowledge, process, behavior, culture, organizational pressure, technology or some combination of them. That is the information required to choose a sensible intervention and to determine whether the intervention worked.

For MSSPs, this creates a clear extension of the role they already play. They already help customers understand technical risk. Human Risk Management adds another source of evidence about why that risk is emerging and what should change.

As AI increases both the quality of social engineering and the amount of machine-generated information people are expected to trust, that capability becomes increasingly useful.


Frequently Asked Questions

What is Human Risk Management?

Human Risk Management is the practice of identifying, understanding and reducing cyber risk associated with people and the conditions that influence their behavior.

It includes awareness training and phishing simulation, but also considers factors such as competency, decision-making, culture, process design, organizational conditions and security evidence.

How is Human Risk Management different from security awareness training?

Security awareness training is one intervention within a Human Risk Management program.

Training is appropriate when people lack knowledge or skill. Other human-risk problems may require changes to process, controls, communications, leadership behavior or escalation routes. HRM provides a way to distinguish between those situations before deciding what action to take.

Why is AI increasing human cyber risk?

AI is making social engineering more convincing while also changing the way employees work. People are increasingly relying on AI-generated information, recommendations and content as part of everyday decisions.

That creates new questions around trust, verification, data handling, intervention and escalation. These issues cannot be measured through training completion or phishing performance alone.

Why should MSSPs offer Human Risk Management?

MSSPs already help customers manage technical security risk and often have access to security telemetry that provides evidence about real behavior and incidents.

A Human Risk Management capability allows them to add context around those events, identify recurring human and organizational conditions, and help customers select more appropriate interventions.

Does Human Risk Management require employee surveillance?

It should not.

Useful Human Risk Management focuses on patterns, populations and organizational conditions rather than creating simplistic judgments about individual employees. The purpose is to understand where risk is being generated and what conditions the organization can improve.

How can an MSSP start offering Human Risk Management?

The starting point is usually an assessment or baseline that establishes what the organization already knows, where evidence is missing and which conditions appear to be contributing to risk.

From there, the provider can connect human-risk findings with existing security services and determine whether the appropriate response involves learning, communications, process changes, controls, targeted interventions or further measurement.

How does Cybermaniacs work with MSSP partners?

Cybermaniacs works with MSPs, MSSPs, vCISOs, consultancies and other security providers through referral, resale, co-delivery and joint service models.

Partners can use Cybermaniacs to provide Human Risk Management technology, measurement, learning, advisory services and Human Risk Baselines without building an entire specialist capability internally.

TAGS: MSSP