Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Adaptive defense in HRM: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Reactive security awareness leaves teams behind, with Ponemon Institute and IBM cited in the Living Security Human Risk Management Platform post showing the average insider-threat discovery time is 73 days. The article argues that adaptive defense, using behavioral, identity, and threat signals, is now the practical model for reducing human risk before damage spreads.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Adaptive Defense in HRM: The Age of Adaptive Defense

By the numbers:

Questions worth separating out

Q: How should security teams use human risk analytics in IAM programmes?

A: Security teams should use human risk analytics to prioritise interventions where behaviour and access intersect.

Q: Why do traditional security awareness programmes miss so many human-driven incidents?

A: They usually measure completion, not risk reduction, so they cannot show whether behaviour is changing in a meaningful way.

Q: What breaks when human risk management ignores access context?

A: The programme loses the ability to distinguish a risky action from a risky action with real blast radius.

Practitioner guidance

  • Integrate identity and behaviour signals Connect IAM, SIEM, and awareness data so risk scoring can use access context, not just user activity.
  • Replace completion metrics with risk metrics Track fewer risky users, faster remediation, and lower exposure instead of training attendance.
  • Pilot predictive interventions Start with one high-risk population, monitor behavior over 90 days, and measure whether targeted interventions reduce repeat risky actions.

What's in the full article

Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:

  • The platform's 200+ risk indicator model and how it correlates behavior, identity, and threat data.
  • Examples of how Livvy guides routine remediation while keeping security teams in control.
  • The HRMCon 2025 session context featuring Ashley Rose and Edna Conway, useful if you want the leadership framing behind the model.
  • The 90-day pilot approach for validating predictive interventions in a high-risk population.

👉 Read Living Security Human Risk Management Platform's analysis of adaptive defense in human risk management →

Adaptive defense in HRM: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Adaptive defense is really identity-aware risk governance, not just smarter training. The article is strongest when it links behaviour to identity and access, because that is where human risk becomes operational. Security teams do not reduce exposure by coaching users in the abstract; they reduce it by identifying which identities, access paths, and behaviours create repeatable loss conditions. That makes HRM a governance layer across IAM and security awareness, not a separate programme.

A question worth separating out:

Q: Who is accountable when predictive human risk controls fail to reduce exposure?

A: Security leadership is accountable because the control is designed to improve governance outcomes, not just deliver training. Boards will expect evidence of risk reduction, remediation speed, and exposure decline. If the metrics do not move, the programme has not translated data into control effectiveness.

👉 Read our full editorial: Adaptive defense in human risk management shifts security from detection



   
ReplyQuote
Share: