A practical map of the capabilities that turn awareness, behavior, culture, data and measurement into an operating risk discipline.
Human Risk Management is often described through its ingredients: awareness training, phishing simulation, behavioral data, culture, risk scores, analytics, communications and, increasingly, security-event telemetry. The list is useful up to a point, but it creates the same problem we explored in Human Risk Management Has a Definition Problem: owning a collection of ingredients does not necessarily mean an organization can manage human cyber risk.
A capability map asks a different question. Instead of starting with the products in the stack, it asks what an organization needs to be able to do. That makes it useful whether the capability is provided by one platform, several technologies, an internal team, specialist partners or—more realistically for many organizations—a combination of all four.
Cybermaniacs' public Human Risk Management Capability Map organizes that work into six connected capabilities: Understand & Diagnose, Develop Capability, Influence Behavior & Culture, Connect Evidence & Context, Measure Risk & Change, and Operate & Adapt. They are not intended as a six-step implementation recipe or maturity ladder. An organization will move between them continually as different risks, populations and business priorities require attention.
The map is deliberately about capabilities rather than features. Human Risk Management becomes useful when an organization can connect evidence, understanding, intervention and measurement well enough to make better decisions about human-related cyber risk.
The Human Risk Management Capability Map at a Glance
| Capability | The question it helps answer | What good looks like |
|---|---|---|
| Understand & Diagnose | What is happening, where, and what might be contributing to it? | A richer view of human-related risk than any single activity metric can provide |
| Develop Capability | What do people need to know, recognize, practice or become ready to do? | Continual, relevant capability development rather than episodic compliance activity |
| Influence Behavior & Culture | What needs to change, and what kind of intervention fits the problem? | More than one lever for influencing behavior, norms and organizational conditions |
| Connect Evidence & Context | What other information changes how this signal should be interpreted? | Workforce, behavioral, organizational and security evidence can be understood together |
| Measure Risk & Change | What should we monitor, and how will we know whether something meaningful changed? | Fit-for-purpose measures with appropriate analytical depth, thresholds and time horizons |
| Operate & Adapt | How do we prioritize, govern, report and continually improve the capability? | HRM becomes an operating discipline rather than a collection of campaigns and dashboards |
There is plenty of overlap between the six areas, deliberately so. Culture influences behavior; behavioral evidence contributes to diagnosis; measurement influences priorities; organizational context can completely alter the interpretation of an event. Trying to force human systems into perfectly separate boxes generally produces a tidier diagram and a worse model of reality.
1. Understand & Diagnose
Human Risk Management needs a way to understand the current condition before deciding what to change. That sounds obvious, yet many programs begin with the intervention because historically that was where the available technology sat: assign training, run a simulation, review the results, repeat.
A diagnostic capability looks more broadly at the human and organizational factors relevant to cyber risk. Depending on the problem, that could include workforce knowledge and capability, attitudes and confidence, observed behavior, cultural conditions, organizational context, exposure and patterns emerging from security activity. The objective is not to collect every possible piece of employee data; it is to develop enough relevant evidence to understand where something deserves attention and what might plausibly explain it.
That distinction matters because the same observed outcome can have very different causes. Weak incident reporting might reflect poor detection capability, uncertainty about what should be reported, lack of confidence, a cumbersome reporting process or a culture in which raising concerns feels professionally risky. The metric can tell us there is something worth investigating without supplying the diagnosis automatically.
NIST's Human-Centered Cybersecurity program provides useful grounding for this approach. It explicitly encourages cybersecurity decisions based on empirical evidence, stakeholder needs and behavior, while treating security as an interaction between people, processes and technology rather than isolating the human as the problem. NIST Human-Centered Cybersecurity
Cybermaniacs' ASSURE Human Risk Baseline sits in this part of the map. Its purpose is to establish a richer current-state view so an organization can see meaningful differences and decide where deeper attention is warranted, rather than beginning with the assumption that everyone needs the same intervention.
2. Develop Capability
Security awareness remains central to Human Risk Management because people still need the knowledge, skills, confidence and practice required to make good security decisions. The difference is that learning now sits inside a wider risk system rather than carrying the entire burden on its own.
A capability-development function should be able to respond to different levels of need, roles and changing risk. For some employees, that means foundational cybersecurity knowledge. Others may need role-specific capability, realistic practice, support around new technology or reinforcement because the work itself has changed. A global manufacturer, healthcare organization or transport company also has to think about learning very differently from an organization in which almost everyone spends the day at a desk.
NIST SP 800-50 Rev. 1 treats cybersecurity and privacy learning as a lifecycle program connected to behavior change, risk management, culture, measurement and continual improvement. That broader framing is useful because it moves the learning question from how much content have we delivered? toward what capability does this population need, and how should we know whether we are building it? NIST SP 800-50 Rev. 1
That is also how we think about Cybermaniacs CLX. Continual competency development, adaptive learning and relevant experiences are more useful to HRM than treating the content library as a vending machine and asking the practitioner to choose this month's flavor.
The distinction from traditional awareness is not that HRM cares less about learning. It expects learning to have a clearer relationship to the risk or capability need it is supposed to address.
3. Influence Behavior & Culture
Understanding a problem is not the same as changing it, and this is where Human Risk Management needs more range than a training workflow.
Learning is one intervention. Depending on the condition being addressed, a program may also need communications, realistic practice, nudges, manager involvement, leadership activity, policy clarification, improvements to a process or technical control, changes to the working environment, or something designed specifically for the population involved.
That range matters because behavior is shaped by more than knowledge. The NCSC's Cyber Security Culture Principles explicitly consider leadership, social norms, psychological safety, working conditions and the way security fits into organizational goals. The guidance also recognizes that every organization's culture journey is different rather than prescribing one universal intervention plan. NCSC Cyber Security Culture Principles
We have explored those principles in our own NCSC Cyber Security Culture Principles series because they illustrate an important HRM idea particularly well: when the surrounding organization makes insecure behavior normal, convenient or socially rewarded, another awareness asset may be technically correct and practically irrelevant.
For practitioners, a useful intervention capability therefore needs more than one lever. The repertoire might include:
- learning and practice where capability is the constraint;
- simulations where rehearsal and observable response are useful;
- communications and nudges where timely reinforcement matters;
- managers and leaders where local norms or priorities are influential;
- process, policy or technical changes when secure behavior is unnecessarily difficult;
- bespoke campaigns or experiences when the organization needs something specific to its people, culture or moment.
Cybermaniacs' CHANGE capability sits here because real organizations regularly encounter problems that were not waiting conveniently in an off-the-shelf catalog.
4. Connect Evidence & Context
This is where Human Risk Management can begin to move beyond the boundaries of the traditional awareness technology stack.
Learning systems know about learning. Phishing platforms know about simulations. Security systems know about events. Workforce systems know about role and organizational structure. None of those sources automatically knows what the others know, yet their relationship can materially change the meaning of the evidence.
Consider a cluster of security events in one business function. Without context, the organization might conclude that the people in that function are simply more risky. Once role, technology exposure, workflow, access patterns, recent organizational change or the nature of the underlying systems are considered, a very different explanation may emerge.
Connecting evidence therefore means more than integrating APIs and filling a data lake. A mature HRM capability should be able to bring relevant forms of evidence into context while preserving what each source can legitimately tell us.
That might include relationships between:
- workforce and organizational context;
- learning and assessment evidence;
- simulations and observable behavioral signals;
- cultural or human-factor evidence;
- security events and relevant exposure;
- previous interventions and subsequent change.
The aim is not to turn every employee action into telemetry. Nor should correlation quietly become causation because two data sources happened to appear on the same chart. The analytical value comes from determining which connections help answer a risk question and being appropriately cautious about what can be inferred from them.
This capability also creates important governance responsibilities. Workforce-related security data can become sensitive quickly, particularly when organizations begin joining information at individual level. Appropriate permissions, aggregation, privacy safeguards, data quality, proportionality and clear rules about how findings can be used are therefore part of the HRM capability rather than administrative details to sort out later.
NIST's Human-Centered Cybersecurity work is again relevant here because its people-process-technology framing resists the temptation to interpret human behavior separately from the environment in which it occurs.
5. Measure Risk & Change
Once organizations have more data, the next temptation is to put all of it on a dashboard. Human Risk Management needs something more disciplined.
As we explore in What Should Human Risk Management Actually Measure?, different measures perform different jobs. Program metrics help practitioners understand whether the machinery is operating properly. Health measures provide a longer-term view of underlying conditions. Flow metrics show what is moving through the environment. Change metrics are designed around something the program is actively trying to influence, while watch metrics and thresholds help determine when ordinary variation becomes interesting enough to investigate.
Those distinctions matter because measures also have different lifespans. A completion measure may need operational attention every month. A cultural or capability baseline may be more useful periodically. A change measure may become intensely important during an intervention and largely irrelevant once the question has been answered.
NIST SP 800-55 Volume 2 similarly treats information-security measurement as an organizational program rather than a dashboard exercise, with a flexible structure for developing and implementing measures over time. NIST SP 800-55 Volume 2
Human Risk Management teams eventually need analytical depth as well as metrics. Simple averages are useful until the organization starts asking whether differences between populations are meaningful, how conditions are changing longitudinally, whether several forms of evidence move together or whether an intervention appears to correspond with the outcome it was intended to influence. Those questions do not require turning every awareness team into a statistical research department, but they do require a measurement foundation capable of growing as the questions become more sophisticated.
A risk score may sit on top of that work and make complexity easier to communicate. It should not become a substitute for it.
6. Operate & Adapt
The final capability is the one that turns the other five into something an organization can sustain.
Human Risk Management needs priorities, ownership, governance, reporting, audience decisions, intervention planning and a way to learn from what happened. Without that operating layer, an organization can have excellent individual tools while still running a collection of loosely related activities.
This is where HRM connects back to broader cybersecurity governance. NIST CSF 2.0 introduced Govern as a core function and emphasizes organizational context, risk-management strategy, roles, policy and alignment with enterprise risk. The framework intentionally defines outcomes rather than prescribing one implementation, which is a useful analogy for the capability-map approach here. NIST Cybersecurity Framework 2.0
For HRM practitioners, operating the capability means deciding what deserves attention rather than simply reacting to whichever metric happens to be red. It also means translating findings for very different stakeholders: the CISO may need an enterprise risk view, a functional leader needs to understand what is happening in their part of the business, and the person running the program needs enough operational detail to know what should happen on Monday morning.
Our MANAGE Human Risk Management capability supports this part of the map because program design, governance, interpretation and ongoing expert support are difficult to reduce to software features. The platform can automate a workflow; somebody still has to know whether the workflow is the right one.
Adaptation matters for the same reason. Organizations reorganize, technologies change, threats evolve, new regulations arrive and the workforce acquires entirely new ways of getting its job done. A sensible HRM capability needs enough continuity to show change over time without becoming so rigid that it continues measuring and treating last year's problems indefinitely.
AI Now Cuts Across the Entire Map
AI is not a seventh box bolted onto the edge of Human Risk Management. It changes what may need to happen inside nearly every existing capability.
Understanding risk increasingly requires looking at workforce readiness for AI-enabled work, confidence and overconfidence, trust, changing roles and new forms of exposure. Capability development has to address safe use and judgment rather than merely tool instructions. Behavioral and cultural work has to contend with new norms around delegation, verification and acceptable use, while measurement needs to distinguish whether people have completed AI education from whether they can actually work safely with increasingly capable systems.
Agentic AI stretches the map further because human involvement may shift from direct execution toward delegation and supervision. The organization then needs to understand where people rely on agents, when they intervene, how responsibility is divided and whether the surrounding workflow makes good oversight realistic.
That is why AI Enablement & Change Management (AIECM) and Agentic Readiness & Change (ARC) sit inside our broader Human Risk Management thinking. AI changes the work and therefore changes the human-risk questions the program needs to be capable of asking.
The Map Is Not a Product Checklist
It would be easy to turn a capability map into another procurement spreadsheet and ask whether every vendor has a green checkmark in every column. That is not what this is for.
An organization may already have excellent simulation technology, a capable learning platform, sophisticated security telemetry and strong internal analytics. It may need program expertise rather than another system. Another organization may have a thoughtful program trapped inside manual administration and disconnected data, making platform investment the obvious next step.
Our related guide on how to evaluate a Human Risk Management platform uses Platform, Program and Partner as the three evaluation lenses for exactly this reason. The capability may be assembled across all three.
Nor is the map a maturity ladder. A mature organization does not permanently graduate from capability development into measurement, any more than a well-run security function stops identifying risk once it begins responding to incidents. Different parts of the organization will be dealing with different questions simultaneously, and new technology or organizational change can send the program back to investigate something it thought it understood quite well six months earlier.
What matters is whether the organization has access to the capabilities it needs when the risk question requires them.
How Cybermaniacs Uses the Capability Map
Cybermaniacs' approach spans the map because our experience has been that the harder human-risk problems rarely stay inside one box.
ASSURE helps organizations establish the diagnostic picture and understand where attention may be needed. CLX supports continual capability development, while simulations and other interventions provide practice and behavioral evidence. CHANGE gives programs room to create communications, campaigns and experiences around the particular problem rather than forcing every response through the same content workflow. MANAGE supports the wider strategy, operating model, interpretation and ongoing program work.
Measurement sits across those activities because the useful question is not simply whether something was delivered, but what the organization learned and whether the condition it cared about changed. As relevant security and workforce evidence becomes more connected, the analytical foundation also needs to become richer without losing sight of data quality, context, privacy and the limits of what can legitimately be concluded.
This map is intentionally one level above the proprietary methods, constructs and analytical models Cybermaniacs uses underneath that work. It describes the capabilities an organization needs to develop without pretending that the difficult part is drawing six boxes and connecting them with arrows. The specialist work lies in determining what should be measured, how different forms of evidence should be interpreted, which intervention fits the condition and how confidently the organization can conclude that something meaningful changed.
A Capability Map Should Help You See What Is Missing
The practical value of the map is not in demonstrating that an organization possesses all six headings. It is in helping practitioners see where a program's current strengths stop answering the questions it now needs to ask.
A strong awareness program may already be excellent at developing capability but lack diagnostic depth. A telemetry-rich security organization may have abundant flow evidence without a useful model for understanding human or cultural conditions. Another program may have good measurement but too narrow a range of interventions, leaving the team able to identify a problem without having many credible ways to influence it.
Those are very different capability gaps and should lead to different investments.
That is why Human Risk Management becomes less useful when it is reduced to a category of SaaS products and more useful when it is treated as an organizational capability. The technology matters, but so do the measurement program, analytical discipline, organizational context, intervention range, governance and expertise around it. The right combination will vary by company, sector and maturity because the risks and workforce are not interchangeable.
A capability map cannot tell an organization exactly what to build. What it can do is make the conversation more precise: what can we already understand and change well, where are we still operating on assumption, and what capability would allow us to make a better risk decision next?
Frequently Asked Questions
What capabilities make up Human Risk Management?
The Cybermaniacs Human Risk Management Capability Map groups HRM into six connected capabilities: Understand & Diagnose, Develop Capability, Influence Behavior & Culture, Connect Evidence & Context, Measure Risk & Change, and Operate & Adapt. Organizations may deliver those capabilities through different combinations of technology, internal expertise and external support.
Is the Human Risk Management Capability Map a maturity model?
No. The map describes capabilities rather than maturity levels or a sequential implementation process. Organizations will use different capabilities at different times depending on their workforce, risk environment, available evidence and program priorities.
Does a Human Risk Management platform need to provide all six capabilities?
Not necessarily. HRM is an organizational capability, and its components may be spread across existing security technologies, HRM platforms, internal teams and specialist partners. The important question is whether the organization can perform the necessary management functions, not whether a single product contains every feature.
Where does security awareness fit in the HRM Capability Map?
Security awareness sits primarily within Develop Capability and can also support Influence Behavior & Culture. Learning remains an important Human Risk Management intervention, but HRM also needs diagnosis, contextual evidence, measurement and an operating capability around it.
How does security telemetry fit into Human Risk Management?
Relevant security telemetry can contribute behavioral and event evidence within Connect Evidence & Context and Measure Risk & Change. Events should be interpreted alongside appropriate workforce, organizational and risk context rather than automatically treated as complete measures of individual human risk.
Why does Human Risk Management need culture and psychology?
Observed behavior does not always explain why an action occurred. Psychological, cultural and organizational factors can influence confidence, motivation, trust, social norms, willingness to report and whether secure behavior is practical. Those factors can therefore be relevant when diagnosing risk or choosing an intervention.
How does AI fit into the Human Risk Management Capability Map?
AI affects several HRM capabilities at once. Organizations may need to understand workforce readiness and trust, develop AI-related capability, influence norms around safe use, measure changing behaviors and govern human-agent roles, delegation and oversight as AI becomes embedded in work.