TL;DR: Human risk management is being positioned as the operating model that helps CISOs move from technical defense to business enablement, with Livingston Security Human Risk Management Platform citing 200-plus risk indicators, 60 to 80 percent automated remediation, and Cyentia Institute findings of a 50 percent reduction in risky users. The governance shift is less about adding another dashboard and more about proving security value in financial and operational terms.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How Human Risk Management Evolves the CISO Role
By the numbers:
- The Cyentia Institute found that predictive human risk management delivers a 50% reduction in risky users.
- The same research reported a 98% decrease in data-loss exposure.
- Living Security states that its platform analyzes 200+ risk indicators across behavior, identity and access, and threat.
Questions worth separating out
Q: How can organisations tell if human-risk management is working?
A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups.
Q: Why do identity and access controls matter in human risk management?
A: Because most meaningful human-risk events become security problems when they intersect with access.
Q: What do organisations get wrong when they rely on training completion as a security metric?
A: They confuse participation with risk reduction.
Practitioner guidance
- Shift executive reporting to outcome metrics Replace training completion and alert volume reporting with risk reduction, remediation speed, and exposure change so board discussions focus on measurable security value.
- Correlate identity, behaviour, and threat data Build an operating view that ties workforce actions to identity and access context, then use it to prioritise the riskiest users and workflows first.
- Define governance for automated remediation Document which interventions AI may execute, which require approval, and which must be audit logged before changes affect user access or privilege.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- The boardroom framing for translating security telemetry into financial terms and executive risk language.
- The 200-plus indicator model across behaviour, identity and access, and threat signals used in the platform.
- The specific automation claims around 60 to 80 percent of routine remediation tasks.
- The session context from HRMCon 2025, including the practitioner examples discussed by Larry Whiteside Jr.
Human risk management and the CISO role shift , what changes now?
Explore further
Human risk management is becoming the measurement layer that boards will expect, not a niche awareness tool. The article correctly frames the shift from technical activity reporting to outcome reporting. That matters because boards do not buy patch counts or training completions as evidence of resilience. They buy evidence that risk is falling in ways the business can understand, and that makes human risk data a governance asset across identity, compliance, and resilience programmes.
A question worth separating out:
Q: How do organisations keep AI-assisted remediation from becoming over-automated?
A: By separating context gathering from execution. Let the assistant collect findings, identify files, and draft changes, but require explicit review before merge or deployment, and restrict the workflow to low-risk change classes until logging and entitlement boundaries are proven.
👉 Read our full editorial: Human risk management is reshaping the CISO mandate