Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Human risk management and the CISO role shift , what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Human risk management is being positioned as the operating model that helps CISOs move from technical defense to business enablement, with Livingston Security Human Risk Management Platform citing 200-plus risk indicators, 60 to 80 percent automated remediation, and Cyentia Institute findings of a 50 percent reduction in risky users. The governance shift is less about adding another dashboard and more about proving security value in financial and operational terms.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How Human Risk Management Evolves the CISO Role

By the numbers:

Questions worth separating out

Q: How can organisations tell if human-risk management is working?

A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups.

Q: Why do identity and access controls matter in human risk management?

A: Because most meaningful human-risk events become security problems when they intersect with access.

Q: What do organisations get wrong when they rely on training completion as a security metric?

A: They confuse participation with risk reduction.

Practitioner guidance

  • Shift executive reporting to outcome metrics Replace training completion and alert volume reporting with risk reduction, remediation speed, and exposure change so board discussions focus on measurable security value.
  • Correlate identity, behaviour, and threat data Build an operating view that ties workforce actions to identity and access context, then use it to prioritise the riskiest users and workflows first.
  • Define governance for automated remediation Document which interventions AI may execute, which require approval, and which must be audit logged before changes affect user access or privilege.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • The boardroom framing for translating security telemetry into financial terms and executive risk language.
  • The 200-plus indicator model across behaviour, identity and access, and threat signals used in the platform.
  • The specific automation claims around 60 to 80 percent of routine remediation tasks.
  • The session context from HRMCon 2025, including the practitioner examples discussed by Larry Whiteside Jr.

👉 Read Living Security Human Risk Management Platform's analysis of how human risk management is changing the CISO role →

Human risk management and the CISO role shift , what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Human risk management is becoming the measurement layer that boards will expect, not a niche awareness tool. The article correctly frames the shift from technical activity reporting to outcome reporting. That matters because boards do not buy patch counts or training completions as evidence of resilience. They buy evidence that risk is falling in ways the business can understand, and that makes human risk data a governance asset across identity, compliance, and resilience programmes.

A question worth separating out:

Q: How do organisations keep AI-assisted remediation from becoming over-automated?

A: By separating context gathering from execution. Let the assistant collect findings, identify files, and draft changes, but require explicit review before merge or deployment, and restrict the workflow to low-risk change classes until logging and entitlement boundaries are proven.

👉 Read our full editorial: Human risk management is reshaping the CISO mandate



   
ReplyQuote
Share: