Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Human risk management and compliance by design: what changes for teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Regulated industries are being pushed to treat compliance as a baseline for human risk management, not a ceiling, because existing frameworks lag emerging threats and insider-risk detection still moves too slowly, according to Living Security Human Risk Management Platform. The practical shift is to map controls to risk outcomes, use AI-assisted telemetry with human oversight, and design remediation so it is auditable from day one.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Human Risk Management: Balancing Innovation and Compliance

By the numbers:

Questions worth separating out

Q: How should security teams innovate in regulated environments without breaking compliance?

A: Start by mapping each new control or workflow to the regulation it supports, then build documentation and human review into the process from the outset.

Q: Why do compliance-only programmes miss human risk more often?

A: Because compliance usually captures minimum required behaviour, not the behavioural drift that precedes incidents.

Q: How can organisations tell if human-risk management is working?

A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups.

Practitioner guidance

  • Map compliance requirements to risk outcomes Translate HIPAA, FINRA, SEC, FedRAMP, or sector-specific obligations into the exact exposure they are meant to reduce, then attach each control to a measurable risk outcome.
  • Correlate identity, behaviour, and threat data Unify the signals that explain why a user is becoming high risk, rather than reviewing access events and behavioural events separately.
  • Design remediation for auditability Make every intervention generate a traceable record that shows the trigger, reviewer, action taken, and regulatory basis.

What's in the full article

Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:

  • The HRMCon 2025 panel discussion with Jon Garza, Jacob Revord, and Amjed Saffarini on regulated-industry decision-making.
  • Living Security's specific approach to translating compliance requirements into risk outcomes and documentation workflows.
  • The article's breakdown of how HRM data is used to support both audit evidence and predictive intervention.
  • The vendor's examples of piloting new approaches on low-risk populations before expanding into regulated groups.

👉 Read Living Security Human Risk Management Platform's analysis of human risk management in regulated industries →

Human risk management and compliance by design: what changes for teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Compliance by itself is not a risk strategy. Regulators define the minimum control set, but they do not guarantee that security teams are seeing current behaviour or emerging exposure. In human risk programmes, the gap between policy compliance and actual user risk is where incidents happen, especially when attackers exploit social engineering and identity-driven weaknesses. The operational conclusion is that compliance must be treated as evidence of baseline control, not proof of resilience.

A question worth separating out:

Q: Who is accountable when AI-assisted risk decisions affect regulated users?

A: Accountability should sit with the security owner responsible for the workflow, not with the model itself. Regulators and auditors expect explainability, human oversight, and traceable decisions, so the organisation must be able to show who approved the control and why it was triggered.

👉 Read our full editorial: Human risk management in regulated industries needs compliance by design



   
ReplyQuote
Share: