What is Human risk management?

Human risk management is an approach that measures and reduces cyber risk caused by employee behaviour: who clicked a phishing link, who skipped training, which department carries the most risk. It is the next step beyond awareness training.

Instead of the same training for everyone, training follows risk and results show up in numbers. Management sees a risk score per employee and department, and how it changes over time.

How to spot it

  • Training reports only say "completed / not completed"
  • Nobody knows which team is most exposed

What to do

  • Measure the baseline risk
  • Assign training by risk
  • Show management the change

Related courses

Terms on this topic

More topics

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.