Cybermaniacs Human Risk Management Guides

What Data Does Workforce Risk Intelligence Actually Need?

Written by Team CM | Sep 18, 2026, 12:50:44 AM

The technical answer to almost any modern analytics problem is increasingly the same: connect more data. 

For Workforce Risk Intelligence, that instinct deserves some resistance.

Security teams already have access to an extraordinary amount of information involving the workforce. Learning systems record assessments and completion. Phishing platforms capture simulated behavior. Identity systems know about authentication, privilege and access. Email, DLP, SIEM and other security technologies generate events involving employees. HR systems contain role, organizational and employment information. Surveys can add evidence about capability, confidence, culture and attitudes. AI platforms are beginning to create another layer of signals about how people use, trust and supervise technology.

There is obvious analytical value in connecting some of this. There is also a point at which more data stops producing better intelligence.

The useful question for Workforce Risk Intelligence is therefore not simply what data the organization can obtain. It is what evidence would materially improve its understanding of a defined workforce risk problem, at what level that evidence should be interpreted, and whether collecting it is justified by the decision the organization needs to make.

That makes data sufficiency more important than data abundance.

Quick Answer: What Data Does Workforce Risk Intelligence Need?

Workforce Risk Intelligence needs enough relevant, reliable and appropriately governed evidence to understand a workforce-related risk condition and support a better decision.

Depending on the problem, that evidence may concern workforce capability, behavior, culture, role and organizational context, threat exposure, access and consequence, security controls, interventions or outcomes.

It does not follow that every Workforce Risk Intelligence system needs every one of those data sources.

A useful evidence set is determined by the risk question. If additional information would not materially change the interpretation, decision or confidence in that decision, its value may be limited regardless of how easy it is to ingest.

This is an important principle for Human Risk Management because employee-related data carries analytical, privacy and governance costs. Mature Workforce Risk Intelligence should be able to explain why it needs a piece of information before asking the organization to provide it.

Start With the Decision the Organization Is Trying to Make

Security analytics often begins with available telemetry.

That makes sense operationally. Integrations already exist, logs are structured and vendors understandably want to demonstrate that their platforms can ingest them. The resulting data lake can become impressive very quickly.

Workforce risk analysis works better when the order is reversed.

Begin with the condition the organization is trying to understand and the decision that understanding will support.

Suppose the concern is payment fraud in Finance. The relevant evidence might include the population's exposure to impersonation attacks, its ability to recognize and verify suspicious requests, the approval process, access and transaction authority, relevant controls and any organizational conditions changing the way that work is performed.

An authentication log may contribute something. An annual engagement survey probably contributes very little unless there is a specific hypothesis connecting it to the risk condition.

Now consider insecure AI use among software developers. The evidence may shift toward approved and unapproved tool use, data handling, task type, capability, verification practices, code-review controls and the consequences of AI-generated errors.

The fact that both problems concern employees does not mean they require the same dataset.

NIST's current information-security measurement guidance takes a similar approach to measurement more broadly. SP 800-55 emphasizes the deliberate selection and prioritization of measures, along with their validation, data quality, uncertainty and usefulness for continuous improvement. The goal is a measurement program built around meaningful decisions rather than an indiscriminate accumulation of metrics.

Workforce Risk Intelligence needs the same discipline.

The mature question becomes: what evidence would change our understanding or alter what we do next?

Different Evidence Answers Different Questions

One reason workforce data becomes difficult to manage is that very different kinds of evidence are often combined as though they describe the same underlying thing.

They do not.

A knowledge assessment tells us something about capability under the conditions of the assessment. A phishing interaction records a behavior in a simulation. An authentication event records something that happened in an identity system. A culture survey measures reported perceptions or attitudes. Access data can tell us something about potential consequence. Threat intelligence can alter our understanding of exposure.

Each can be useful while remaining analytically distinct.

A practical Workforce Risk Intelligence model therefore needs to understand what a source contributes before deciding how it should influence the interpretation.

Evidence domain What it may help explain What it cannot establish by itself
Competency and capability What people know, recognize or can apply How they will behave in every real-world context
Behavioral evidence What happened under particular observed conditions Why it happened
Culture and psychological evidence Shared norms, confidence, perceptions or decision conditions Direct proof of a specific future security event
Role and organizational context Where the evidence sits within real work Whether the role or population is inherently risky
Access, exposure and consequence Why an event or behavior may matter more in one context than another Whether the person will actually cause a loss
Security and threat evidence Where human activity intersects with attacks, controls and technical events The human cause of every technical event
Intervention and outcome evidence Whether conditions moved after action was taken Causality without considering other explanations

That final column matters as much as the first two.

Human Risk Intelligence becomes unreliable when a data source is allowed to answer questions it was never capable of answering.

A failed login may be important security evidence, for example. It is not automatically evidence of risky human behavior. Repeated MFA challenges followed by an approval may tell a more interesting story, particularly when connected with threat and identity context, but even then the interpretation requires care.

Our earlier Guide on how to measure human cyber risk explores this distinction between events, measures, signals and risk conditions in more depth. Workforce Risk Intelligence depends on preserving those differences rather than flattening them for convenience.

Context Is Data Too

Human Risk Management has traditionally been strongest at recording activities and behaviors. What it has often lacked is enough information about the environment in which those activities occurred, and that becomes a serious limitation once organizations start making stronger claims about risk.

Imagine two employees who interact with the same simulated social-engineering message. One works in a low-exposure administrative role and has been with the organization for several years. The other recently moved into Treasury, now possesses payment authority and has begun receiving increasingly convincing executive impersonation attempts.

The behavioral event is identical.

Its meaning is not.

Role, access, organizational transition and threat exposure change the significance of the evidence without changing the event itself.

That is why the emerging connection between cybersecurity risk and workforce management matters. NIST's March 2026 CSF 2.0 quick-start guide explicitly brings cybersecurity risk management, enterprise risk management and workforce management into the same conversation, with workforce decisions expected to reflect risk reality and changing threats and technologies.

Workforce Risk Intelligence extends that idea by treating organizational context as part of the analytical model. That context does not have to mean a wholesale copy of the HR information system, and often a smaller set of attributes can answer the question adequately: business function, role type, relevant access, organizational unit, geography where material, manager or reporting structure where justified, employment or role transition, and other context directly related to the risk being analyzed.

The Right Level of Analysis Is Part of the Data Design

The industry talks a great deal about which data to collect and rather less about at what level it should be interpreted.

That distinction has major consequences.

Some risk questions genuinely concern an individual. A highly privileged account behaving unusually may require individual analysis. An investigation into suspected insider activity is necessarily specific.

Many Human Risk Management questions do not.

A weak security norm may exist across a team. A process problem may affect everyone performing a particular task. One region may face different threat exposure from another. A newly acquired business unit may exhibit a pattern because its technology, policies and working norms differ from those of the parent organization.

Analyzing those problems only at the employee level can obscure the thing we are trying to understand.

It can also encourage unnecessary collection and retention of individual data.

Workforce Risk Intelligence should therefore be capable of operating across different analytical grains: individuals where justified, but also roles, teams, cohorts, functions, workflows and organizations.

This is one of the areas where privacy and analytical quality often point in the same direction. If the question concerns a population-level condition, individual attribution may add very little useful intelligence while substantially increasing sensitivity.

NIST's Privacy Framework approaches privacy as an enterprise risk-management problem, asking organizations to understand their data-processing activities, the associated risks and the outcomes they actually need. Its guidance encourages organizations to select privacy activities according to mission, processing context and risk rather than treating privacy controls as a universal checklist.

That mindset is useful for Workforce Risk Intelligence too.

Collect and analyze at the lowest level of personal specificity that still supports the decision.

Time Changes What the Evidence Means

A workforce is not static, and neither is the risk around it.

People join, leave and change roles. Organizations merge, restructure and outsource. New technologies alter workflows. Access changes. Threat actors shift tactics. AI adoption changes who performs parts of a task and how much human judgment remains in the process.

A snapshot can therefore be accurate and still become misleading remarkably quickly.

This is why Workforce Risk Intelligence needs some conception of continuity and change.

A person who appears to have unusually high exposure today may have moved into a role where that exposure is perfectly predictable. A sudden cluster of security events may follow a system migration rather than a deterioration in workforce behavior. A population that performed strongly six months ago may now be working through an entirely different process.

Historical evidence also needs to remain interpretable after context changes.

If an employee moves from Marketing into Treasury, their earlier behavioral evidence does not become false. Its relevance to the new role may change. The intelligence system should be capable of preserving the history without pretending the context remained constant.

That is a subtler requirement than simply retaining more records.

It means knowing enough about when something was true to understand what the evidence meant at that point in time.

For workforce risk, change itself can be evidence. A reorganization, role transition or technology rollout may be a reason to reassess a population even before a security event occurs.

Data Quality Matters More Once the Claims Become Stronger

The more ambitious Human Risk Intelligence becomes, the less room there is for casual data quality.

Simple activity reporting can tolerate a degree of messiness. A program may still be able to say that 92 percent of employees completed training even if a small number of organizational records are imperfect.

Risk interpretation raises the stakes.

If the organization is going to compare populations, diagnose conditions, prioritize intervention or change controls based on the result, it needs to know where the evidence came from and how much confidence to place in it.

NIST SP 800-55 explicitly addresses data quality and uncertainty, including validation, normalization and other methods for improving the usability of measurement data. It also encourages testing and validating measures rather than assuming that a metric is useful merely because it can be calculated.

For Workforce Risk Intelligence, this creates several practical questions.

Was the data source complete during the period being analyzed? Did a vendor change a policy or detection rule? Did a new population enter the dataset? Does “reported phishing” mean the same thing across systems? Has an organizational attribute been updated consistently? Are missing values truly unknown, or are they being interpreted as negative evidence?

Those details sound unglamorous because they are.

They are also the difference between an intelligence system and a colorful dashboard that also just so happens to be wrong.

Unknown Is a Legitimate Result

There is a natural pressure in risk analytics to turn missing evidence into a conclusion.

An employee has no recorded phishing failures, therefore they appear low risk. A team has no security incidents, so the risk condition looks healthy. A system has no culture data, so another available signal quietly takes on more weight.

Sometimes absence really is informative.

Sometimes it means nobody looked.

Workforce Risk Intelligence needs to preserve that distinction.

If the organization lacks enough evidence to assess a particular capability or condition, unknown should remain available as an analytical state. That can be frustrating when buyers expect every box on the dashboard to contain a number, but manufacturing certainty from missing information does not improve risk management.

It can actually make intervention worse.

A team with insufficient evidence may deserve further measurement. A team with strong evidence of low risk may deserve no intervention. Those are different conclusions and should remain different in the model.

The same principle applies when evidence conflicts. A population can have strong competency results and poor observed behavior. That disagreement should not automatically be averaged away. It may reveal exactly where further investigation is useful. Intelligence benefits from knowing where its own boundaries are.

Provenance Matters Because Evidence Changes

Workforce Risk Intelligence is likely to rely increasingly on information generated outside the HRM platform which makes data provenance important.

A practitioner examining a risk condition should be able to understand where important evidence came from, what period it describes, and whether it was directly observed, supplied by another system or inferred through analysis.

And this becomes particularly important when underlying data is corrected or reprocessed.

Imagine a security platform changes its classification logic and several months of events are subsequently re-categorized. The organization should be able to update its current interpretation without pretending the previous analysis was based on information that did not exist at the time.

The details of how that lineage is implemented belong inside the technical architecture. The public requirement is simpler: an intelligence conclusion should remain connected to the evidence that produced it.

Without that connection, explainability becomes a storytelling exercise.

Security Telemetry Is Powerful, but It Needs Translation

One of the most interesting developments in Human Risk Management is the increasing use of evidence from the wider security stack.

This is where the category can (finally!) begin to move beyond simulations and self-contained awareness metrics.

Authentication, MFA, email-security events, DLP activity, identity context, security reports and other telemetry can provide evidence about how workforce behavior intersects with real systems and real threats.

But there is the risk of over-attribution to consider as well.

Security telemetry was usually generated to detect or manage a technical condition. It did not necessarily originate as a measure of human behavior, capability or intent.

A DLP alert can show that a policy condition fired. Additional evidence may be needed to understand whether the underlying event involved error, legitimate work, a poorly designed policy, deliberate action or something else entirely.

Authentication failures can reveal friction, attack pressure, user error or technical problems. The event alone may not distinguish among them.

This is where Workforce Risk Intelligence needs translation between security evidence and human-risk interpretation rather than simply copying SOC events into an employee profile. The goal is to recognize when security evidence genuinely adds to our understanding of a workforce risk condition.

Privacy Is Part of the Intelligence Architecture

Workforce Risk Intelligence deals with information about people. That makes privacy a design consideration from the beginning rather than a compliance task added later.

The most obvious principle is purpose.

If an organization cannot explain which risk question a particular employee attribute helps answer, there is a reasonable argument that the data does not belong in the model.

That discipline also improves analytics. Large datasets contain relationships that are statistically detectable, especially across large workforces. Not every detectable relationship is meaningful, fair or useful.

Purpose provides a filter.

Governance also needs to address who can see information at different levels, how long it is retained, how population sizes are handled, when identity-level analysis is appropriate and whether evidence collected for one purpose should be reused for another.

De-identification and aggregation can help in situations where the organization wants to understand population patterns without exposing unnecessary individual detail. NIST's work on de-identification makes the broader point that data can often retain analytical value while reducing the risk created by association with identifiable individuals, although de-identification itself needs careful governance.

Sensitivity should therefore increase the standard of justification. A mature program should be able to say what information it uses, why it uses it, how it is protected and what decisions that information is permitted to influence.

Intervention Data Is Part of the Evidence Model

There is another category of information Human Risk Management has often underused: evidence about its own actions.

If the organization identifies a risk condition and then intervenes, the intelligence system should know that the intervention occurred.

Otherwise the next change in the data is difficult to interpret.

Suppose a population's reporting behavior improves significantly. That could reflect better capability, a communications campaign, a new reporting button, a change in manager expectations, an increase in threat exposure or several of those factors at once.

Knowing which interventions occurred gives the organization a better basis for understanding the movement.

Intervention data should therefore contain enough information to reconnect action with the problem it was intended to address: what changed, which population or condition it targeted, when the change occurred and what outcome was expected.

This closes the loop described in our Guide to measuring and reducing workforce cyber risk. Workforce Risk Intelligence should become better after intervention because the organization now has new evidence about both the risk condition and its own response.

AI Will Create More Data Than Organizations Know What to Do With

AI makes disciplined data selection even more important.

Organizations may increasingly have access to AI usage logs, prompt activity, application metadata, agent actions, approvals, overrides, escalations and other information about human-machine work.

Some of that evidence could be extremely valuable in helping to identify populations using unsanctioned tools, reveal where high-consequence tasks are becoming heavily automated or show where human review is consistently overriding agent recommendations.

It could also encourage an extraordinary amount of workplace surveillance, so the useful analytical question is again narrower than the technically possible one. If the risk concerns inappropriate disclosure of sensitive information, the organization may need evidence about data flows, approved tools and role context. It does not necessarily need to inspect every prompt an employee writes.

If the concern is over-reliance on AI outputs, raw usage volume is not enough. Task type, consequence, verification behavior and changes in capability may matter more.

Human-centered cybersecurity research increasingly emphasizes designing security around the real interaction among people, processes and technology rather than expecting training alone to compensate for poorly designed environments. NIST's 2026 work in this area is particularly relevant as organizations redesign work around AI and automation.

Our own work on AI Workforce Enablement and Agentic AI Readiness is developing this same problem from the workforce side.

The new availability of AI telemetry should not reset the principle.

Collect evidence that helps answer the risk question. Resist collecting intimate detail merely because the technology makes it easy.

What Should a Workforce Risk Intelligence Platform Do With the Data?

The platform question follows naturally from the evidence question.

For an enterprise evaluating Human Risk Management technology, the value of an integration should not be judged solely by the number of logos on the integrations page.

The system needs to preserve meaning once the data arrives.

It should know where evidence came from and when it applies. It should be capable of carrying organizational and workforce context without forcing every conclusion to the individual level. It should distinguish direct observations from interpreted signals and leave room for uncertainty where evidence is incomplete.

Time matters as well. A useful system needs enough historical context to understand transitions, interventions and changing conditions rather than overwriting the past every time an employee changes role or a source system updates an attribute.

Governance needs to survive integration too. Role-based access, population controls, appropriate aggregation and clear handling of sensitive information are not administrative extras once workforce and security evidence are being connected.

Finally, the platform should make it possible to investigate.

A practitioner looking at an elevated risk condition should be able to move toward the evidence and context underneath it rather than being asked to trust an unexplained score.

These requirements are part of the wider model described in the Cybermaniacs Human Risk Management Capability Map. The value comes from connecting evidence, interpretation, intervention and outcomes rather than accumulating integrations as an end in themselves.

How Cybermaniacs Thinks About Workforce Risk Evidence

Cybermaniacs has spent several years building models around competency, psychology, behavior, culture, workforce context and organizational conditions because workforce risk cannot be understood reliably through one type of evidence.

The deeper work involves establishing what a source can tell us, what it cannot tell us, how different evidence relates and when there is enough information to support a conclusion. Underneath that public view sit detailed taxonomies, risk-evidence structures, signal models, temporal and contextual relationships, diagnostics and intervention logic that form part of the Cybermaniacs system.

With all this work, we believe that workforce Risk Intelligence should be selective before it is comprehensive.

A strong intelligence capability knows what evidence it needs, preserves the context required to interpret it and is comfortable acknowledging when the available information is insufficient.

Better Intelligence Does Not Require Knowing Everything About Everyone

The future of Human Risk Management will undoubtedly be more data-rich.

That is welcome. Awareness teams have spent too long trying to understand organizational risk through a handful of metrics generated inside their own programs. Security telemetry, workforce context, threat evidence and better measurement can produce a much richer picture.

The danger is assuming that the richest possible picture is automatically the best one.

Workforce Risk Intelligence has a different standard.

The evidence should be relevant to a defined risk condition. Its provenance and limitations should remain understandable. The level of analysis should fit the problem. Sensitive workforce information should have a clear purpose. Changes in context should not erase history. Missing evidence should remain missing rather than quietly becoming certainty.

Most importantly, the information should improve a decision.

That gives organizations a practical boundary in a world where the amount of workforce data available to security teams will continue to expand.

Frequently Asked Questions

What data does Workforce Risk Intelligence need?

Workforce Risk Intelligence needs evidence relevant to the particular workforce risk condition being investigated. Depending on the problem, this can include competency, behavior, culture, psychological factors, role and organizational context, access, threat exposure, security events, controls, interventions and outcomes. A useful system does not need every available data source for every question.

Does Workforce Risk Intelligence require HR data?

Some workforce or organizational context can be valuable, such as role, function or relevant transitions. That does not mean the Human Risk Management system needs unrestricted access to an entire HR record. The appropriate data should be determined by the risk question and governed according to its sensitivity and purpose.

Should Human Risk Management platforms ingest security telemetry?

Security telemetry can substantially improve Workforce Risk Intelligence when it contributes relevant evidence about real threats, behaviors or controls. Events from systems such as identity, email security, DLP or SIEM still require interpretation because they were not necessarily created as direct measures of human risk.

Does more workforce data produce better Human Risk Intelligence?

Not necessarily. Additional data can improve understanding when it addresses an evidence gap, adds useful context or changes the confidence of a decision. Data that does not materially improve the analysis can add noise, complexity, privacy risk and false relationships.

At what level should workforce risk be analyzed?

The appropriate level depends on the problem. Some cases require individual analysis, while many Human Risk Management questions are better examined across roles, teams, cohorts, functions, workflows or organizational units. Mature Workforce Risk Intelligence should support more than one analytical level.

How should organizations deal with missing workforce-risk data?

Missing information should remain identifiable as unknown where appropriate. Treating the absence of evidence as evidence of low risk can create false confidence. An unknown result may indicate that further measurement or investigation is needed before the organization acts.

Why does data provenance matter in Human Risk Management?

Provenance connects an analytical conclusion to the source, timing and nature of the evidence behind it. This helps practitioners understand why a risk view changed, assess data quality, interpret corrections and distinguish directly observed events from derived conclusions.

How should privacy be handled in Workforce Risk Intelligence?

Organizations should collect and process workforce information for a defined and legitimate risk purpose, limit individual-level analysis where a population-level view is sufficient, control access to sensitive data and govern retention and reuse. Privacy is part of the design of Workforce Risk Intelligence rather than a separate consideration after the analysis has been built.

What data is useful for measuring AI workforce risk?

Useful evidence depends on the AI risk condition. It may include approved-tool usage, task context, data handling, competency, verification behavior, reliance, escalation, override, role, consequence and controls. Raw AI activity alone does not explain whether AI use is creating or reducing workforce risk.

What should companies look for in a Workforce Risk Intelligence platform?

Companies should look for more than a large integration catalog. The platform should preserve data provenance and time, connect evidence with workforce and organizational context, work across appropriate analytical levels, distinguish observation from interpretation, represent uncertainty and support governance over sensitive workforce information.