Human Risk Management has reached the slightly awkward stage of category development where almost everybody appears to sell roughly the same thing.
Behavior change. Culture. AI. Personalized learning. Risk scores. Analytics. Adaptive interventions. A dashboard with enough gradients to suggest that something very scientific is happening underneath it.
Some of those capabilities are excellent. Some are genuinely innovative. The difficulty for buyers is that the vocabulary has converged much faster than the products, methodologies and service models behind it. Two vendors can both claim to measure “human risk” while meaning materially different things. A platform can have an enormous content library without having a coherent learning strategy. It can be gamified and work for only some of the humans it is supposed to engage.
So evaluating a Human Risk Management platform requires more than comparing feature columns.
At Cybermaniacs, we think about the decision through three lenses: Platform, Program and Partner. The platform has to provide the right technology and evidence. It needs to support the program you are trying to build, including the one you may want three years from now rather than simply the one you have today. And because Human Risk Management sits at the intersection of cybersecurity, behavior, culture, learning, measurement and organizational change, it is worth paying rather more attention to the people standing behind the software.
If you are still defining the category itself, start with our guide to what a Human Risk Management platform should actually do. This guide tackles the harder buying question: how do you tell whether one is actually any good?
| Evaluate | The question you are really trying to answer |
|---|---|
| Platform | Can the technology meaningfully understand, influence and measure human cyber risk, and can your team actually operate it? |
| Program | Will it help you build a stronger Human Risk Management capability as your needs, data and maturity evolve? |
| Partner | When the problem requires judgment, expertise or something outside the standard software workflow, who is going to help you? |
There will always be practical procurement questions around security, integrations, SSO, SCIM, privacy, accessibility, localization and enterprise architecture. They matter. But those are increasingly table stakes for serious enterprise software.
The questions that distinguish Human Risk Management platforms are about what the system understands, what it helps you change, how well it fits the workforce and whether the organization selling it understands the discipline beyond its own product.
This sounds philosophical until someone puts a human risk score in front of your CISO and asks what it actually represents.
Does the platform's concept of human risk primarily come from phishing behavior? Training activity? User-reported events? Surveys? Security telemetry? Organizational data? Some combination of these? More importantly, what does the vendor believe each source of evidence allows it to conclude?
A number is not inherently more meaningful because it has been branded as risk.
The point is not that every vendor needs the same measurement model. Human Risk Management is still developing, and different organizations will reasonably emphasize different signals and use cases. What matters is whether there is a coherent logic underneath the platform and whether the vendor can explain it without disappearing into a cloud of proprietary-algorithm hand waving.
NIST's Human-Centered Cybersecurity work makes a useful broader point here: cybersecurity decisions should be grounded in empirical evidence, take people's needs and behavior into account, and address the interaction between people, process and technology. The aim is security that works in practice, not merely in theory. NIST Human-Centered Cybersecurity
That is a useful test for Human Risk Management too.
Risk scores can be useful. Executives cannot reasonably be expected to inspect thirty-seven separate workforce indicators every time they want to understand whether things are moving in the right direction, and good models help teams summarize, prioritize and communicate complexity.
The trouble starts when the score becomes a magic trick.
Buyers should be able to understand what kinds of evidence contribute to a conclusion, why those signals matter and what changed when the score moved. If your risk score gets better because course completion rose, you should know that. If a functional population is surfacing as higher risk because several different conditions have converged, the platform should help you investigate rather than simply paint the box red.
Cybermaniacs approaches this distinction deliberately in our Human Risk Baseline and ASSURE work: the point of measurement is not to produce a prettier number but to help organizations understand where risk exists, why it may be occurring and what deserves attention next.
The recipe beneath that analysis is the specialist part. The buying principle is simpler: if you cannot get from the score back to an understandable risk story, you may have purchased a scoreboard rather than a measurement capability.
Early in a Human Risk Management journey, straightforward questions are often exactly the right questions.
Who completed the learning? Where are phishing-reporting rates weakest? Which groups need more support? Are employees becoming more confident in an important competency?
As a program matures, the questions tend to get harder. Teams begin looking for meaningful differences between populations, patterns over time, relationships between different forms of evidence, variations across business functions, the effect of organizational context and whether interventions appear to correspond with changes in the conditions they were designed to address.
That progression matters when choosing technology.
A platform may be perfectly adequate while you are looking at simple activity and summary scores, yet become constraining once the program wants to conduct richer group comparison, longitudinal analysis or investigate patterns across multiple sources of evidence. You do not need every advanced analytical capability on day one, but it is worth asking whether the platform has somewhere intelligent to go.
The useful procurement question is not simply “Does it have analytics?”
It is:“Will this still help us when our questions become better?”
Cybersecurity has developed a peculiar affection for the size of the content library.
A library containing 700 courses may be a tremendous asset. It can also be 699 additional decisions for the practitioner who logged in hoping the platform might make Monday morning easier.
Volume and choice are useful when they sit inside a thoughtful learning architecture. They are much less useful when the customer is handed a warehouse and asked to design a curriculum from the shelves.
Look at how the content fits together. Is there a progression? Does learning develop capability over time, or do topics recur because the calendar has come around again? Is new material genuinely new, or the same advice in this year's wardrobe? Can the program respond to emerging threats and organizational priorities without forcing the practitioner to rebuild everything manually?
NIST's current guidance in SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program treats learning as a lifecycle program connected to risk management, behavior change, security culture, evaluation and continual improvement—not a once-a-year content transaction.
That is much closer to how we think about the Cybermaniacs Cyber Learning Experience. CLX is built around a multi-year competency journey, continual reinforcement and adaptive learning rather than treating the customer as the proud new owner of an unusually large video cupboard.
Gamification can work brilliantly.
Competition can be motivating. Points can make mundane activity more interesting. Progress mechanics can encourage participation and give people a satisfying sense of mastery.
They do not work equally well for everybody.
A 2024 study comparing personalized and one-size-fits-all gamification in online learning found that individual differences mattered and that personalized approaches based on player types produced stronger motivational, behavioral and cognitive outcomes than the same game mechanics applied universally. Read the study in Learning and Individual Differences
That supports a broader principle we have believed for a long time: gamification is a technique, not a theory of human personality.
Some people will happily chase a leaderboard. Others are motivated by mastery, curiosity, relevance, autonomy, social connection, practical usefulness or simply being allowed to get on with their work without turning cybersecurity into Mario Kart.
A strong Human Risk Management platform should have more than one engagement lever. It should be able to make learning relevant and personal without assuming that every employee is secretly waiting for points, badges and a weekly championship table.
This question becomes particularly important outside highly desk-based industries.
A financial analyst with two screens and Outlook open all day experiences cybersecurity very differently from someone on a manufacturing line, a nurse moving between patients, a retail associate, a logistics team, a field engineer or an employee whose primary interaction with corporate technology is a shared terminal or mobile device.
They may have different access patterns, time constraints, language needs, security responsibilities, technology exposure and reasons for engaging with the program.
The UK's National Cyber Security Centre explicitly recommends understanding people's experience, working environment, competing demands and local ways of working when designing secure systems and interventions. It also warns against narrow approaches that assume information alone will produce the required behavior. NCSC guidance on putting people at the heart of cybersecurity
So ask whether the platform works for your workforce rather than the workforce imagined in the demo.
Can it accommodate different populations? Different roles? Different languages? Different devices and working patterns? Can interventions be made relevant without manually creating a separate program for every team?
One of the reasons Cybermaniacs has spent so much time thinking about personal relevance, audience design and adaptable delivery is that Human Risk Management gets considerably more interesting once you leave the corporate laptop behind.
Sophisticated Human Risk Management should not require a sophisticated new administrative burden.
The platform ought to take work away from the practitioner by automating sensible delivery, organizing evidence, managing audiences, reducing repetitive workflows and making useful information easier to extract. If the technology generates several new dashboards, a weekly CSV ritual and an exciting second career in spreadsheet reconciliation, something has gone slightly wrong.
This is an area where proof matters more than promises. On our Cyber Learning Experience page, for example, we describe a regional bank whose administrative effort moved from roughly eight hours each week to around two hours a month after automating its learning operation. The more interesting outcome was not automation for its own sake; it was giving the security team its time back so it could work on risk rather than chase training administration.
Ask vendors to show what ordinary program operation looks like after implementation, not just the beautiful dashboard on demo day.
Human Risk Management is not a settled discipline.
Organizations are moving beyond training and simulated phishing into richer behavioral evidence, security culture, workforce segmentation, organizational context, security events and more sophisticated measurement. AI is changing both the threat environment and the nature of work itself. Agentic systems will push questions of judgment, delegation, reliance and oversight still further.
That means product vision matters.
A vendor does not need to predict the next ten years perfectly. Nobody can. But it should be able to explain where it believes the discipline is going and why it is building toward that future.
Ask what Human Risk Management will need to accomplish as your program matures. Can the platform incorporate new forms of evidence? Can it support more sophisticated measurement and intervention? Does the company think of HRM mainly as better awareness technology, or as an emerging risk-management capability?
Our related article on Human Risk Management as an operating model, not just a SaaS platform explores this distinction in more depth. A platform provides capabilities; the operating model determines how an organization turns those capabilities into a functioning risk discipline.
You are not merely buying today's features. Not to sound too much like a Magic Qudrant, but you are, to some degree, buying the vendor's theory of tomorrow.
Human Risk Management becomes useful when the organization can do something with what it learns.
Sometimes the answer will be education. Elsewhere it might involve a communication, manager involvement, a role-specific intervention, a new simulation, a policy clarification, an executive message, a process change or a closer look at the organizational conditions driving the behavior.
The National Cyber Security Centre's culture guidance is particularly useful here. It describes security culture in terms of what an organization treats as normal and valued, and highlights the influence of social norms, leadership, trust, working conditions and competing business demands. Simply telling someone to behave differently may accomplish very little when the surrounding environment rewards the opposite behavior. NCSC Cyber Security Culture Principles
A Human Risk Management platform therefore needs to fit into a broader intervention system.
Ask what happens after a risk condition appears.
If the answer always eventually becomes “assign another course,” you have learned something important.
Cyber programs have a habit of encountering reality.
A major policy changes. An acquisition lands. Cybersecurity Awareness Month appears on the calendar with suspicious speed. The board wants a new briefing. An incident raises uncomfortable questions about human factors. AI adoption accelerates. A particular business function needs help. A senior leader decides that the program suddenly matters very much indeed.
These moments reveal whether you bought a product or gained capability.
Can the provider help create something specific? Can they build a campaign? Help make sense of the findings? Develop content for a difficult audience? Think through a change problem? Help the internal team prepare an executive story rather than simply export another chart?
Cybermaniacs' custom cybersecurity content and CHANGE capability exists precisely because mature programs routinely need things that were not sitting pre-packaged in a catalog. Sometimes the right answer is a course. Sometimes it is a film, campaign, event, communications series or something nobody sensibly predicted twelve months earlier.
A platform should give a program structure without putting it in a cage.
Support is usually treated as a procurement footnote.
Business-hours support. Premium support. Dedicated customer-success manager. Response-time SLA.
Those things matter, but Human Risk Management raises a more interesting question:
Who are you actually going to be able to talk to?
The discipline crosses cybersecurity, risk, measurement, learning, behavioral science, organizational culture, communication and change. Very few internal security teams have deep expertise across all of those areas, and there is no particular reason they should have to build it all themselves.
So find out whether the provider's expertise is merely baked into the software or genuinely available to the customer.
Eventually, you will have a question that the knowledge base cannot answer.
Perhaps the data is behaving oddly. Perhaps two sources of evidence disagree. Perhaps the CISO wants to know what the program should prioritize next year. Perhaps a particular business population is struggling and another course feels unlikely to fix it. Perhaps the board wants a clear explanation of what “human risk” actually means before approving more investment.
At that point, product expertise is useful. Human Risk Management expertise is better.
Ask who participates in the relationship once the contract is signed. Are experienced practitioners available? Can they help interpret findings? Can they challenge an assumption? Can they help you think through strategy, measurement or program maturity? Or does every conversation ultimately return to how the software feature works?
This is a deliberate part of the Cybermaniacs model. Our MANAGE Human Risk Management advisory and program support pairs technology with hands-on practitioners who help customers turn strategy into execution, mature the capability and work through the messy parts that do not fit neatly into a software workflow.
Sometimes you need a login.
Sometimes you need someone smart, helpful, and a good listener on the other end of the phone.
Knowing which kind of company you are buying from matters.
Enterprise technology demos are controlled environments. The data behaves. The workflow is elegant. The sample users have impeccably complete profiles. Nobody has recently reorganized Europe, acquired a company, replaced the CISO, migrated identity providers and asked the security team to explain the whole thing to the board by Thursday.
Real programs are less considerate.
This is why partnership is not soft, feel-good procurement language. It affects whether the technology continues to create value as the organization changes.
Ask how the provider works with customers after implementation. What happens when the program matures? When priorities shift? When the internal team is short-handed? When something needs to be changed quickly? When you want advice rather than another upsell?
Human Risk Management is a long game. The provider should behave like it knows that too.
The best demo questions are often the ones that force the conversation away from polished workflows and toward the thinking underneath them.
| Ask this | What you are trying to discover |
|---|---|
| 1. What do you mean by human risk? | Whether the platform has a coherent risk model rather than a renamed collection of existing metrics |
| 2. What evidence sits underneath your risk scores? | Whether conclusions are inspectable and understandable |
| 3. What can this metric legitimately tell me—and what can't it tell me? | Whether the vendor understands measurement limitations |
| 4. How does the platform distinguish knowledge, behavior and culture? | Whether materially different concepts have simply been collapsed into one score |
| 5. What happens after the platform identifies a problem? | Whether measurement connects to a meaningful range of interventions |
| 6. How does your approach work for different workforce populations? | Whether the experience assumes everybody sits at a desk and responds to the same motivation |
| 7. How much ongoing administration should we expect? | Whether the platform creates leverage or another operating burden |
| 8. What will we be able to analyze as our HRM program becomes more sophisticated? | Whether the analytical model can grow with you |
| 9. Where do you believe Human Risk Management is heading over the next few years? | Whether the vendor has a coherent product and category vision |
| 10. Who can help us interpret the data and decide what to do? | Whether expertise extends beyond technical product support |
| 11. What happens if we need something outside the standard content or workflow? | Whether the provider can adapt to real organizational needs |
| 12. Show us a customer whose program became materially better—not merely someone who implemented the software. | Whether the vendor can demonstrate outcomes, maturity or reduced operational burden |
The answers are often more revealing than another hour of clicking through menus.
Cybermaniacs combines Human Risk Management technology with continual learning, phishing and social-engineering testing, measurement, program advisory, communications and custom content capabilities.
That is not an accident of packaging. It reflects how we think Human Risk Management works.
Technology is essential because enterprise programs need scale, automation, data and repeatability. Good measurement is essential because intuition and activity metrics are not enough. Content and interventions matter because insight without action is merely an interesting report. Program expertise matters because organizations need to know what to do with the technology. And sometimes a customer simply needs a group of experienced people who understand their world well enough to help solve the thing that appeared on Tuesday morning.
Our ASSURE Human Risk Baseline provides the diagnostic layer. CLX supports continual competency development and adaptive learning. MANAGE helps organizations build and operate the wider HRM capability. And CHANGE exists for the moments when an organization needs something made for its particular people, culture, brand or problem.
And then there is AI. Any Human Risk Management platform you are considering now should have a credible answer for what happens as AI changes the workforce—not simply a new awareness module called Using Copilot Safely. AI adoption changes judgment, data handling, accountability, role design, trust, supervision and, increasingly, who or what is actually doing the work. We think AI enablement, AI governance and AI workforce risk belong squarely inside the HRM conversation, because the human side of AI adoption is already becoming part of the human-risk landscape. Cybermaniacs’ AI Enablement & Change Management (AIECM) helps organizations understand workforce readiness, capability, adoption barriers and emerging risk, then turn those findings into targeted change and enablement. For organizations moving into Copilots and AI agents, Agentic Readiness & Change (ARC) goes further into the changing relationship between people and increasingly autonomous systems: roles, workflows, oversight, judgment, intervention and governance in the work itself. If your HRM strategy has no answer for AI-enabled work, it may already be designing for yesterday’s workforce.
We think that combination matters because Human Risk Management is not really a battle between software and services.
It is a question of what the organization needs in order to manage the risk well.
Sometimes the technology can do the heavy lifting. Sometimes practitioners need to interpret, design, communicate or intervene. Mature programs need to be able to do both.
There is nothing wrong with a feature matrix. You need to know whether the product integrates with your environment, supports the right workflows and contains the capabilities your program requires.
Just do not confuse the matrix with the evaluation.
The better questions are whether the technology produces evidence you can trust, whether it fits the humans who actually work in your organization, whether it makes the program easier to operate, whether it will still be useful when your questions become harder, and whether the people behind it can help when the answer isn't hiding inside a dropdown menu.
That is when you discover what you really bought.
And with Human Risk Management, that distinction tends to matter for a very long time.
Look beyond training, phishing and dashboard features. A strong Human Risk Management platform should provide meaningful measurement, support different workforce populations, connect evidence to interventions, reduce administrative burden and remain useful as the organization's HRM capability becomes more sophisticated.
A useful approach is to evaluate three areas: the Platform, including technology, measurement and workforce fit; the Program, including operating model, maturity and future needs; and the Partner, including expertise, adaptability and ongoing support.
Not on their own. Risk scores can be useful for summarization and prioritization, but buyers should understand what evidence sits underneath the score, why those inputs matter, what the score can legitimately indicate and whether they can investigate the reasons it changes.
Content remains important, but quantity is not the same as quality. Buyers should consider whether the provider offers a coherent learning journey, keeps material current, supports different workforce populations and builds relevant capability over time rather than simply supplying a large catalog.
The right model depends on the organization. Some teams primarily need technology, while others benefit from support with strategy, measurement, program design, interpretation, communications, custom content or organizational change. Buyers should understand what expertise is available before they need it.
Gamification can improve engagement and motivation for some people and contexts, but evidence suggests that individual differences affect how people respond to game mechanics. It is better treated as one engagement technique within a broader learning strategy than as a universal model of employee motivation.