By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published January 9, 2026

TL;DR: Human factors contribute to 68% to 90% of security breaches, and KnowBe4’s whitepaper argues that Human Risk Management shifts organisations from awareness campaigns to continuous identification, measurement, and mitigation of people-related risk. The strategic question is no longer whether users make mistakes, but whether security programmes can operationalise human-risk controls fast enough to keep pace with AI-amplified social engineering.


At a glance

What this is: This whitepaper frames Human Risk Management as a continuous, data-driven way to identify, measure, and reduce people-related cyber risk.

Why it matters: It matters because IAM, security awareness, and incident-prevention programmes all depend on reducing the human error path that attackers increasingly exploit, including in phishing-led identity compromise.

By the numbers:

👉 Read KnowBe4's whitepaper on strategic human risk management


Context

Human Risk Management, or HRM, is the attempt to turn people-related security exposure into something measurable and governable rather than anecdotal. The article argues that traditional awareness alone does not close the gap, because users make mistakes and AI-amplified social engineering increases both attack volume and believability. That makes human behaviour part of the security control surface, not just a training problem.

For identity and access programmes, the important shift is governance. Human error often becomes the entry point for credential theft, MFA fatigue, rogue approvals, and data-handling mistakes, which then cascade into broader IAM, PAM, and incident-response failures. The starting position described in the article is typical for organisations that still treat human risk as a communications issue rather than an operational control domain.


Key questions

Q: How can organisations tell if human-risk management is working?

A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups. If the programme only reports attendance or click rates, it is measuring activity, not security improvement.

Q: Why does AI make human risk harder to control?

A: AI increases scale, personalisation, and speed. That means attackers can produce more convincing messages, test more variants, and target the same user repeatedly until a lure succeeds. Human-risk programmes need adaptive controls because static awareness cannot keep pace with automated persuasion.

Q: What do security teams get wrong about phishing awareness training?

A: They often treat training as a replacement for technical containment. Awareness can reduce clicks, but it does not stop every mistake, especially under pressure or when attackers use convincing workflow-based lures. Training should be measured by lower incident impact, faster reporting, and fewer successful follow-on actions.

Q: How can security teams reduce human error without blaming users?

A: Use design and governance instead of blame. Tighten verification steps, reduce unnecessary exceptions, improve reporting paths, and apply stronger controls to high-impact roles. Human error will always exist, so the programme should limit how far one mistake can travel.


Technical breakdown

What human risk management actually measures

HRM treats human behaviour as a set of observable security signals, such as susceptibility to phishing, risky clicks, weak reporting behaviour, and repeated policy exceptions. The goal is not to classify people as good or bad, but to identify patterns that indicate where controls are failing. In practice, HRM combines telemetry, training outcomes, and behavioural indicators to prioritise interventions by exposure, role, and recurrence.

Practical implication: build a measurement model that links human-risk indicators to specific controls, not just training completion.

Why awareness alone does not reduce breach likelihood

Awareness programmes inform users, but they do not reliably change behaviour in the moments attackers exploit. Social engineering succeeds because it compresses decision time, uses trusted channels, and creates urgency, while AI makes content more convincing and more scalable. HRM therefore sits between education and control enforcement, using measured risk to decide where nudges are insufficient and stronger protections are needed.

Practical implication: supplement awareness with conditional controls such as reporting friction, step-up verification, and tighter access checks for high-risk roles.

How DEEP maps to a human risk programme

The DEEP model described in the article, Defend, Educate, Empower, and Protect, is a practical way to organise human-risk work. Defend and Protect relate to guardrails and technical controls, while Educate and Empower focus on enabling better decisions and faster reporting. The value is in sequencing: human-risk programmes fail when they stop at education and never connect to protective mechanisms.

Practical implication: map each DEEP stage to a measurable control owner, KPI, and escalation path so the programme can be operationalised.


NHI Mgmt Group analysis

Human risk is a governance problem, not a training problem. Awareness campaigns have value, but they do not by themselves change how organisations detect, constrain, and respond to risky human behaviour. When the same mistakes recur, the issue is usually control design, measurement, or accountability. For IAM and security leaders, the practical conclusion is that human-risk management must be treated as an operational discipline, not an annual exercise.

AI-amplified social engineering changes the attack economics. Attackers can now scale persuasion, personalise lures, and iterate faster than most organisations can retrain users. That shifts the burden from static awareness content to adaptive controls and behavioural telemetry. The right response is to reduce attacker leverage, not assume users will reliably outthink increasingly automated deception.

Verification trust gap: modern attacks exploit the time between a person receiving a message and the organisation verifying whether it should be trusted. That gap widens when identity, access, and communication controls operate separately. HRM is therefore strongest when linked to identity governance, phishing-resistant authentication, and risk-based escalation, because human behaviour becomes part of the wider trust architecture.

HRM should be measured like any other control domain. If an organisation cannot show reduction in repeat risky behaviour, faster reporting, or lower successful social-engineering rates, the programme is performative. Security teams should expect the same discipline they apply to access reviews or endpoint coverage: define signals, assign ownership, and test whether interventions actually change outcomes.

What this signals

Human-risk programmes will increasingly be judged by whether they reduce identity compromise pathways, not whether they improve awareness metrics. That brings HRM closer to IAM, PAM, and phishing-resistant authentication, because the real test is whether a human error still turns into a valid access event.

Verification trust gap: as social engineering becomes more AI-assisted, organisations need a tighter link between behavioural signals, access decisions, and incident triage. In practice, that means aligning human-risk telemetry with identity governance and risk-based verification rather than running awareness, IAM, and SOC operations in separate lanes.

The programme signal to watch is whether high-risk cohorts show lower repeat exposure and faster reporting after targeted interventions. If the numbers stay flat, the organisation has a content problem, not a human-risk management programme.


For practitioners

  • Define human-risk indicators tied to control outcomes Track measurable behaviours such as phishing susceptibility, report rates, policy exceptions, and repeat exposure by role. Tie each indicator to a named control owner so the programme can drive action rather than reporting.
  • Connect awareness to enforcement and escalation Use human-risk signals to trigger step-up verification, restricted access, or mandatory review when behaviour crosses a defined threshold. This stops HRM from becoming a content-only programme.
  • Prioritise high-risk roles first Focus on users whose mistakes create disproportionate blast radius, including finance, administrators, executives, and identity approvers. Human-risk work should follow exposure, not headcount.
  • Measure repeat behaviour over completion rates Completion of training is not the outcome. Reduce repeated risky actions, shorten reporting time, and lower successful compromise rates if the programme is working.

Key takeaways

  • Human risk management shifts cybersecurity away from blame and toward measurable control of behaviour, exposure, and response.
  • Human factors appear in 68% to 90% of breaches, which makes people-related risk a core security issue rather than a side programme.
  • The most effective HRM programmes connect measurement to enforcement, escalation, and identity controls, not just awareness content.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-1Human-risk management directly depends on security awareness and role-based education.
NIST SP 800-53 Rev 5AT-2AT-2 governs security awareness training and supports measurable human-risk programmes.
NIST AI RMFMANAGEThe article's AI-amplified social engineering angle calls for active risk treatment and monitoring.

Link HRM outcomes to awareness coverage, reporting behaviour, and role-specific education effectiveness.


Key terms

  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
  • AI-amplified social engineering: AI-amplified social engineering is the use of generative or automated systems to make deception more convincing, scalable, and personalised. It increases the volume and realism of lures, which raises the pressure on users and weakens traditional awareness-only defences.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.

What's in the full article

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • A practical DEEP model breakdown showing how Defend, Educate, Empower, and Protect map to programme actions.
  • Guidance on building an integrated, AI-driven HRM platform to support behaviour measurement and response.
  • Examples of how organisational behaviour principles can be used to improve security culture over time.
  • The source's framing of HRM as a strategic operating model rather than a one-off awareness exercise.

👉 The full KnowBe4 whitepaper expands the DEEP model, programme design, and HRM operating concepts.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle fundamentals. It helps practitioners connect identity control design to the broader security programme they are responsible for.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org