Human Risk Management is acquiring a great deal more data. Security teams can increasingly connect learning records, phishing and social-engineering activity, reporting behavior, identity and access information, security events, workforce attributes, culture assessments and other forms of evidence that were once scattered across the organization.
That solves an important visibility problem. It does not automatically solve the harder problem of understanding workforce cyber risk.
Knowing that an event happened is different from knowing what it means. Knowing that one population produces more security alerts than another does not tell us whether the difference comes from capability, exposure, role, technology, working conditions, organizational culture, threat activity or simply the way the data was collected. Even a well-designed human risk score can tell us where to investigate without being able to explain, by itself, what the organization should change.
This is the problem Workforce Risk Intelligence is intended to address.
At Cybermaniacs, we use the term to describe the continuous collection, connection and interpretation of relevant evidence about workforce-related risk so an organization can understand what is happening, where, to whom or what, under which conditions, why it may matter and how those conditions are changing.
The important word is not workforce. It is intelligence.
Workforce Risk Intelligence (WRI) is the capability to collect, connect and interpret evidence about workforce-related risk so an organization can understand what is happening, where it is happening, who or what is affected, the conditions contributing to it, why it matters and how those conditions are changing.
In cybersecurity, that can include evidence about:
The objective is not to build the largest possible employee dataset. It is to create enough governed, relevant and interpretable evidence to make better decisions about workforce cyber risk.
That means Workforce Risk Intelligence should eventually help answer a more useful sequence of questions:
What is happening? Where? To whom or what? Under which conditions? Why might it matter? What should we do? Did it work?
Much of cybersecurity's human-risk language still gravitates toward the individual.
We identify risky users, assign employee risk scores, record phishing failures and trigger personalized interventions. Individual-level evidence can be useful, particularly when a decision genuinely concerns one person. The trouble starts when the unit of measurement quietly becomes our explanation for the risk itself.
People do not make security decisions in a vacuum.
They work inside processes, teams and hierarchies. They use particular devices and systems. They experience deadlines, incentives and operating pressures. Their roles provide different levels of access and authority. Some populations are more attractive to attackers. Managers and peers establish norms about whether security procedures are taken seriously, ignored, challenged or quietly circumvented when they interfere with getting the job done.
The same person can behave very differently when those conditions change.
That makes workforce a useful level of thinking. It moves the analysis beyond an employee as an isolated source of risk and toward people operating inside an organizational and technological system.
This wider connection between workforce and cyber risk is beginning to appear in formal risk guidance as well. NIST's 2026 Cybersecurity Framework quick-start guide brings cybersecurity risk management, enterprise risk management and workforce management into the same process. It explicitly describes workforce decisions as risk-informed and calls for continuous adaptation as threats, technologies and organizational requirements change.
NIST is addressing cybersecurity workforce management rather than defining Workforce Risk Intelligence as we use the term here, so the concepts should not be conflated. The underlying principle is nevertheless important: workforce decisions and cybersecurity risk decisions are not separate universes.
The workforce is part of the system through which cyber risk is created, controlled and changed.
A useful intelligence capability needs to do more than rank employees from green to red.
We think six questions provide a useful public test of whether the organization is actually creating intelligence.
| Question | What the organization is trying to understand |
|---|---|
| What is happening? | The relevant events, behaviors, conditions, changes or outcomes being observed |
| Where? | The roles, functions, teams, workflows, locations, technologies or populations in which the condition appears |
| To whom or what? | The people, systems, information, processes or business outcomes potentially affected |
| Under which conditions? | The context surrounding the evidence, including role, workload, technology, culture, process, authority, exposure or organizational change |
| Why might it matter? | The plausible consequence, threat relationship, business relevance or risk implication |
| How is it changing? | Whether the condition is persistent, improving, deteriorating, moving between populations or responding to intervention |
These questions are deliberately broader than the metrics an awareness platform can generate by itself.
A phishing simulation may provide useful evidence for the first question. Identity and access information may help with the third. Organizational information can change our interpretation of the second and fourth. Threat data may alter the fifth. Longitudinal measurement and intervention evidence become important for the sixth.
No single source has to answer everything.
The intelligence comes from understanding what different evidence can reasonably tell us, connecting it where appropriate and resisting the urge to infer more than the data supports.
Organizations do not need to collect every possible dimension of workforce activity in order to understand risk. More data can improve visibility, but it can also create more noise, more privacy risk and more opportunities to mistake correlation for explanation.
The appropriate evidence depends on the question.
A mature Workforce Risk Intelligence capability may draw selectively from several different domains.
Does the workforce know what to do, and can people apply that knowledge under realistic conditions?
That might include knowledge, applied skill, recognition, judgment or role-specific capability. This is one reason training completion alone has always been a weak proxy for risk: it tells us that an activity occurred, not necessarily that useful capability exists.
Human cyber risk is influenced by more than knowledge.
Confidence, perceived norms, authority, trust, risk perception, cognitive load, self-efficacy and other factors can affect whether someone acts on what they know. Different psychological constructs require different forms of evidence, and they should not be reduced casually to personality labels or employee profiling.
Observable behavior provides important evidence about what people actually do.
Phishing and social-engineering responses, security reporting, use of controls, policy-related events and other observable activities can all contribute. As our Guide on how to measure human cyber risk argues, however, an event is evidence rather than an automatic diagnosis. How to Measure Human Cyber Risk
Some risk patterns belong less to an individual than to the environment around them.
Does a team feel able to challenge an unusual request from a senior executive? Are mistakes surfaced quickly or quietly hidden? Is bypassing a particular control so routine that it has become part of how work gets done? Do managers reinforce the same expectations the security program communicates?
Culture can change the meaning of otherwise identical individual behavior.
The significance of an action depends partly on what can happen next.
An employee with little access to consequential systems does not necessarily present the same risk as somebody authorized to release funds, change production systems, access sensitive data or act on behalf of executives.
Exposure matters too. Some functions are targeted more heavily because attackers understand precisely what those employees can do.
Workforce cyber risk can change because the organization changes.
Reorganizations, acquisitions, layoffs, rapid hiring, leadership changes, new systems, outsourcing, role transitions and changes to operating processes can alter capability, access, workload, trust relationships and established ways of working.
Those changes may matter even when no individual's underlying propensity to behave securely has changed at all.
Human Risk Management increasingly has access to evidence from the wider security environment.
Identity platforms, email security, DLP, SIEM, UEBA, collaboration tools and other enterprise systems may help illuminate workforce-related patterns. The important question is not merely whether a Human Risk Management platform can integrate with another system. It is what relevant evidence that system can contribute to the risk question under investigation.
Risk is not produced by people alone.
A population operating inside a well-designed verification process with useful technical controls may present very different residual risk from an identical population relying entirely on vigilance.
Workforce Risk Intelligence therefore needs to understand protective conditions as well as problematic ones. Otherwise it risks attributing to people what is actually being produced by the system around them.
Finally, intelligence should learn from what the organization does.
If the organization responds to a diagnosed risk condition with targeted learning, communications, a process change, a new control, managerial support or another intervention, the resulting evidence should feed back into the intelligence process.
Did the condition change?
Did only the metric change?
Did an improvement persist?
Did the problem move elsewhere?
Was the original diagnosis wrong?
Without that feedback loop, Workforce Risk Intelligence risks becoming very sophisticated observation without much risk management attached to it.
This is where organizational context stops being an interesting extra and becomes central to interpretation.
Consider a hypothetical example involving two populations with unusually poor verification behavior during simulated business-email-compromise scenarios.
The first population works in a newly centralized finance function. Employees score well on relevant knowledge assessments and can explain the verification policy correctly. Further investigation shows that the new purchasing workflow has created considerable time pressure, approval paths are unclear, mobile working is common and senior-looking requests are difficult to verify without delaying legitimate transactions.
The second population consists largely of recently hired employees in operational roles. They have limited familiarity with the organization's verification process, weaker assessment results and relatively little exposure to previous social-engineering education.
The observable behavior is similar, but the risk condition is not.
The second population may benefit significantly from focused capability development and realistic practice. Training the first group again may do very little because lack of knowledge is not the central problem. The organization may need to redesign part of the workflow, establish a practical verification route, clarify escalation or change the expectations created by senior leadership.
This is one of the reasons a single behavioral event should not be treated as a property of the person who generated it.
Workforce Risk Intelligence is useful when it helps distinguish similar symptoms with different plausible causes.
We see Workforce Risk Intelligence as closely related to, but more specific than, Human Risk Intelligence.
Human Risk Intelligence is the broader capability for collecting, connecting and interpreting evidence about human-related cyber risk.
Workforce Risk Intelligence applies that intelligence discipline specifically to the workforce and the organizational system in which work happens.
The distinction is useful because not every human-related cyber threat originates inside the workforce. Human Risk Intelligence may also include external people-related threat information, executive targeting, online exposure, hostile social-engineering activity or other intelligence about human actors and threats surrounding the organization.
Workforce Risk Intelligence concentrates on the people performing work for the organization and the changing conditions in which that work occurs.
| Human Risk Intelligence | Workforce Risk Intelligence |
|---|---|
| Broad human-related risk intelligence capability | Focused on workforce-related risk |
| May include external human threats and exposures | Concentrates on people performing organizational work |
| Can span internal and external human actors | Emphasizes workforce, work and organizational context |
| Helps explain human-related cyber risk | Helps explain where workforce cyber risk arises and changes |
| Supports wider Human Risk Management decisions | Supports workforce-focused diagnosis, prioritization and intervention |
Neither replaces Human Risk Management.
They help Human Risk Management know more about the risk it is trying to manage.
There is another semantic boundary worth drawing because the phrase workforce risk already exists outside cybersecurity.
HR, talent and enterprise-risk disciplines have long examined workforce issues such as retention, capability, absenteeism, wellbeing, workforce supply and organizational resilience. Deloitte, for example, has argued for a broader conception of workforce risk that considers what work is performed, how and where it happens, and the wider conditions affecting workers and organizations.
That work is relevant to cybersecurity more often than security teams sometimes realize. Workforce change, labor conditions, role design and organizational pressure can all alter cyber risk.
But Workforce Risk Intelligence in cybersecurity has a different primary purpose.
It is concerned with understanding how workforce conditions, actions, capabilities and exposures contribute to cybersecurity and technology-related risk.
There will be overlap. There should be.
A restructuring that appears in HR analytics as a retention or capability issue may also create access, knowledge, process-continuity or insider-risk concerns. An AI transformation program may simultaneously be a productivity initiative, a workforce-change program and a source of new cyber risk.
The point is not to claim that security owns the workforce.
It is to ensure that cybersecurity can reason about workforce conditions when those conditions materially affect cyber risk.
As organizations connect more security and workforce information, this distinction becomes increasingly important.
The existence of data does not create an obligation to ingest it.
A serious Workforce Risk Intelligence program should be governed by purpose, proportionality and relevance. Organizations should be able to explain why particular evidence is needed, what decision it supports, at what level it should be interpreted, who can access the result and what conclusions the data can legitimately support.
Individual-level analysis may be justified in some circumstances. It should not automatically be the default grain for every question.
Many workforce-risk questions are better answered at the level of a team, role, function, cohort, workflow or organization. Patterns at those levels can sometimes reveal the conditions generating risk without converting an enterprise security program into a mechanism for monitoring employees one by one.
This is both a governance issue and an analytical one.
If the problem is structural, measuring everybody individually can simply produce a more precise way of misunderstanding it.
There is obvious overlap between the two fields, but their purposes are not identical.
Insider-risk programs are typically concerned with harm involving trusted access, including malicious, negligent or compromised insiders. They may investigate indicators associated with data theft, misuse of privilege, sabotage, fraud or other high-consequence events.
Workforce Risk Intelligence is broader in a different direction.
It may examine conditions that have nothing to do with malicious intent: weak capability, ineffective controls, poor verification processes, unhelpful organizational norms, changes in role, AI over-reliance, security fatigue or a mismatch between policy and actual work.
Insider-risk evidence may contribute to Workforce Risk Intelligence where relevant. Workforce Risk Intelligence should not turn every workforce cyber-risk problem into suspicion about the employee.
Cybermaniacs has argued elsewhere that Human Risk Management needs a measurement program rather than simply a collection of HRM metrics. What Should Human Risk Management Actually Measure?
The same principle sits underneath Workforce Risk Intelligence.
A useful progression might look something like:
evidence → measures → signals → patterns → interpretation → risk condition → decision
That is deliberately not a proprietary scoring formula. Real-world risk analysis is rarely tidy enough to fit a universal sequence, and different questions require different evidence.
The important distinction is between observing something and concluding what it means.
Suppose a business unit generates a rising number of DLP events. That might matter. Before interpreting it as deteriorating workforce behavior, the organization might need to understand whether the population changed, a new system was introduced, policy rules were adjusted, data volume increased or legitimate work now produces events that were not previously captured.
Likewise, an improving phishing score can be encouraging without proving that the organization's susceptibility to real social engineering has fallen by an equivalent amount.
Human Risk Management becomes much more useful when it can preserve these distinctions rather than turning every available event into evidence for the same story.
Workforce and human-risk scores can perform valuable analytical work.
They can normalize information, make relative differences visible, support prioritization, show movement and provide a manageable interface over more complex evidence.
The question buyers should ask is what happens after the score changes.
Can the organization explore what contributed to the movement?
Can it distinguish underlying factors?
Can it see whether the pattern is concentrated in a meaningful population?
Can it examine role, organizational or threat context?
Can it assess how confident it should be in the interpretation?
Can it choose a proportionate intervention?
Can it subsequently establish whether the targeted condition changed?
If not, the organization has useful scoring capability. It may not yet have useful Workforce Risk Intelligence.
Intelligence creates value when it improves action.
In mature Human Risk Management, the path should increasingly resemble:
evidence → intelligence → explanation → decision → intervention → outcome → learning
The intervention does not automatically have to be training.
Depending on what the intelligence reveals, the appropriate response might involve learning, practice, communications, manager involvement, process redesign, workload, technical controls, access, verification, escalation, role clarity, AI enablement or further investigation.
Sometimes the correct conclusion will be that there is not yet enough evidence to intervene confidently.
That is also useful intelligence.
A mature risk discipline should prefer a defensible “we do not know yet” to a highly precise answer manufactured from insufficient evidence.
This connection between understanding and action is why Cybermaniacs' public Human Risk Management Capability Map treats understanding and diagnosis, evidence and context, intervention, measurement and adaptation as connected capabilities rather than isolated platform features. The Human Risk Management Capability Map
As the language spreads, Workforce Risk Intelligence will inevitably become a product feature.
Enterprise buyers therefore need to look underneath the label.
A Human Risk Management platform capable of supporting meaningful Workforce Risk Intelligence should be able to help an organization: