By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published January 9, 2026

TL;DR: AI-driven social engineering and persistent ransomware are outpacing security awareness training alone, according to Knowbe4, and 74% of CISOs still rank human error as their top cybersecurity risk while 87% are turning to AI-powered tools. The bigger shift is toward Human Risk Management as a layered governance model for measuring behaviour, reducing exposure, and linking people-centric controls to broader security outcomes.


At a glance

What this is: This is an eBook arguing that Human Risk Management should replace awareness-only approaches with a layered model for people-centric cyber risk.

Why it matters: It matters because identity and access programmes still depend on human behaviour, and HRM changes how security teams measure susceptibility, enforce process, and connect training to real control outcomes.

By the numbers:

👉 Read Knowbe4's eBook on the top four considerations for Human Risk Management


Context

Human risk management is what happens when organisations accept that awareness training alone does not change exposure at the pace attackers now exploit it. In practice, the gap is not just user judgement, but weak governance around behaviour, process, and control measurement across phishing, insider risk, and privileged access.

For identity and access teams, the relevance is direct. Human decisions still shape MFA fatigue, help desk bypasses, credential reuse, and approval quality, while NHI and workload access often inherit the same process weaknesses through shared workflows and manual exceptions.


Key questions

Q: How should security teams use human risk management instead of awareness training alone?

A: Use awareness training for baseline education and human risk management for ongoing intervention. The practical difference is that HRM should detect risky behaviour, coach the user at the point of action, and feed repeat issues back into governance workflows. If it cannot change outcomes, it is only reporting activity, not reducing risk.

Q: Why do human errors keep bypassing security controls?

A: Because many controls still depend on human judgement at the point of risk. Help desk resets, access approvals, and exception handling create opportunities for attackers to manipulate trusted processes. If the workflow is weak, a person can become the bypass. Stronger verification and tighter approval design reduce that exposure far more than awareness alone.

Q: What do security teams get wrong about human risk management?

A: They often treat it as a training completion problem instead of a resilience problem. Completion rates do not show whether users can resist realistic lures or report them quickly. The programme should be judged by behavioural signals, especially in roles where a single compromised account can lead to broader access.

Q: How do IAM and PAM controls support vulnerability management programmes?

A: IAM and PAM support the programme by controlling who can run scans, approve changes, access remediation systems, and manipulate evidence. If those roles are overbroad or poorly reviewed, vulnerability tooling itself becomes a privileged access pathway. Governance should therefore cover scanner accounts, remediation operators, and the audit trail around both.


Technical breakdown

Why security awareness training fails as a control model

Security awareness training is a content delivery mechanism, not a governance system. It can improve recognition of common threats, but it does not reliably change behaviour, validate decisions at the point of risk, or reduce the organisational blast radius of a mistaken click or approval. Human Risk Management moves the focus from one-off education to observable behaviours, process controls, and risk-based intervention. That makes it closer to an operational control loop than a training programme. The key distinction is that SAT assumes knowledge transfer is enough, while HRM treats human behaviour as a measurable attack surface.

Practical implication: measure human risk through behaviour and control outcomes, not course completion rates.

How human behaviour intersects with IAM and privileged access

Human risk is not separate from identity governance. Help desk resets, access approvals, step-up authentication, and exception handling are all human-mediated identity events that attackers routinely target. Where identity programmes rely on trust, speed, or informal escalation paths, social engineering can convert a person into an access control bypass. HRM therefore overlaps with IAM, PAM, and identity verification because it surfaces where decisions are made by humans instead of policy. The control question becomes whether the process itself is resilient, auditable, and resistant to manipulation.

Practical implication: harden identity workflows that depend on human judgement, especially resets, approvals, and exceptions.

What measurable human risk governance looks like

Measurable human risk governance requires indicators that connect behaviour to security outcomes. That includes phishing susceptibility, reporting latency, risky approval patterns, repeat exceptions, and reduction in successful social engineering outcomes. The point is not to score people for its own sake, but to identify which behaviours correlate with loss events and where interventions change results. This is where human risk management becomes comparable to other security disciplines: it needs telemetry, baselines, thresholds, and executive reporting, not just awareness content. Without that, it remains a communication exercise rather than a control framework.

Practical implication: build metrics that show whether human-risk interventions reduce incident likelihood and access abuse.


Threat narrative

Attacker objective: The attacker wants to turn human decision-making into a control bypass that yields access, persistence, or direct financial and data loss.

  1. Entry begins with AI-assisted phishing, impersonation, or another social engineering path that targets a person with access.
  2. Escalation occurs when the victim approves, discloses, or delegates access in a way that bypasses intended identity controls.
  3. Impact follows when the attacker uses that human-mediated access path to steal data, deploy malware, or reach privileged systems.

NHI Mgmt Group analysis

Human risk management is becoming an identity governance problem, not just a training problem. The article correctly frames HRM as a blend of process, technology, and culture, but the deeper issue is that identity programmes still depend on people making reliable decisions under pressure. That means identity verification, help desk workflows, privileged approvals, and exception handling all sit inside the human risk boundary. Practitioners should treat HRM as an extension of IAM and PAM governance, not a separate awareness initiative.

Awareness-only programmes create a measurement illusion. Completion rates and simulated click rates are easy to report, but they say little about whether the organisation is actually harder to compromise. The article’s emphasis on measurable outcomes is the right direction because security teams need evidence that interventions reduce access abuse, reporting delay, and approval failure. The practical conclusion is that organisations should measure behaviour change and incident reduction, not training consumption.

Identity workflow abuse is the real control gap behind many human-risk events. Attackers rarely need to defeat policy if they can persuade a person to reset a password, approve access, or trust a fake escalation. That is why human risk management should be aligned with least privilege, strong verification, and auditable approval chains. The practitioner lesson is to redesign the workflows attackers target, not just educate the people who use them.

HRM will increasingly be evaluated through enterprise risk and resilience lenses. As AI-driven social engineering scales, boards will expect evidence that human-facing controls reduce actual loss events and recovery cost. That pushes HRM toward the same discipline as fraud prevention and zero trust, where telemetry, thresholds, and response paths matter more than slogans. Security leaders should prepare to defend human risk with operational metrics that executives can use.

What this signals

Human risk programmes are moving from awareness campaigns to measurable control systems, and that shift will change how security leaders justify budget. The teams that win here will be the ones that can show behaviour change tied to fewer successful social engineering events, not just higher training completion rates.

Behaviour-to-control drift: when people are trained but workflows remain easy to manipulate, risk simply moves from the user to the process. That makes identity verification, help desk procedures, and privileged approval chains the real optimisation target for programmes that sit adjacent to IAM and PAM.

For identity leaders, the practical signal is that human-risk telemetry will increasingly feed access reviews, step-up logic, and fraud-style anomaly detection. The more mature programmes will connect people risk with broader security frameworks such as the NIST Cybersecurity Framework 2.0, because the control problem is governance, not content delivery.


For practitioners

  • Define human-risk metrics that map to loss events Track reporting latency, repeat susceptibility, risky approval behaviour, and exception frequency, then correlate them with phishing, fraud, and access abuse outcomes.
  • Harden identity workflows that rely on people Review password resets, MFA recovery, privileged approvals, and help desk escalation paths for opportunities where attackers can manipulate a human into bypassing policy.
  • Replace awareness-only reporting with control reporting Report to leadership on changes in failed social engineering attempts, reduced exception volume, and faster detection of suspicious requests rather than training completion alone.
  • Align HRM with IAM and PAM governance Treat human risk findings as inputs to access reviews, step-up authentication rules, and privileged access controls so behaviour data changes the control environment.

Key takeaways

  • Human risk management reframes people-related security from a training issue into a measurable governance problem.
  • The strongest evidence in the article is that CISOs see human error as a top risk, yet most organisations still rely on awareness techniques that do not control the workflow attackers exploit.
  • Security teams should tie human-risk signals to IAM, PAM, and identity verification controls so behaviour data changes how access is granted, reviewed, and challenged.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-1The article focuses on awareness and behavioural risk, which maps to training and competence.
NIST SP 800-53 Rev 5AT-2Security awareness training is central to the article’s subject and control model.
MITRE ATT&CKTA0001 , Initial Access; TA0006 , Credential AccessThe article’s threat context includes phishing and social engineering leading to access compromise.
NIST AI RMFGOVERNHRM needs accountability, metrics, and oversight, which the AI RMF governance function supports conceptually.

Map human-risk scenarios to ATT&CK tactics and prioritise controls that block initial access and credential theft.


Key terms

  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
  • Security Awareness: A programme that teaches people how to recognise and respond to common security risks. In identity security, awareness is only useful when it changes behaviour around authentication, verification, reporting, and safe handling of access requests. Message repetition alone does not create measurable risk reduction.
  • Human-Mediated Access: Human-mediated access is any identity event that depends on a person making a judgment or taking an action to grant, restore, or expand access. Examples include password resets, approval workflows, and exception handling, all of which attackers can target through manipulation or impersonation.

What's in the full article

Knowbe4's full eBook covers the operational detail this post intentionally leaves for the source:

  • A fuller comparison of traditional security awareness training and Human Risk Management, including how the operating model changes.
  • Specific metrics and ROI indicators that can be used to report human-risk performance to executives and stakeholders.
  • Practical guidance for building a layered programme that combines process, technology, and culture without relying on training alone.

👉 Knowbe4's full eBook adds the program design detail, measurement approach, and stakeholder framing behind Human Risk Management.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, and secrets management for practitioners who need stronger identity controls. It helps security teams connect lifecycle discipline to the broader risk and governance programmes they already run.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org