Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Human risk management and the governance gap security teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Human factors contribute to 68% to 90% of security breaches, and KnowBe4’s whitepaper argues that Human Risk Management shifts organisations from awareness campaigns to continuous identification, measurement, and mitigation of people-related risk. The strategic question is no longer whether users make mistakes, but whether security programmes can operationalise human-risk controls fast enough to keep pace with AI-amplified social engineering.

NHIMG editorial — based on content published by KnowBe4: A Strategic Framework for Human Risk Management

By the numbers:

Questions worth separating out

Q: How can organisations tell if human-risk management is working?

A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups.

Q: Why does AI make human risk harder to control?

A: AI increases scale, personalisation, and speed.

Q: What do security teams get wrong about phishing awareness training?

A: They often treat training as a replacement for technical containment.

Practitioner guidance

  • Define human-risk indicators tied to control outcomes Track measurable behaviours such as phishing susceptibility, report rates, policy exceptions, and repeat exposure by role.
  • Connect awareness to enforcement and escalation Use human-risk signals to trigger step-up verification, restricted access, or mandatory review when behaviour crosses a defined threshold.
  • Prioritise high-risk roles first Focus on users whose mistakes create disproportionate blast radius, including finance, administrators, executives, and identity approvers.

What's in the full article

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • A practical DEEP model breakdown showing how Defend, Educate, Empower, and Protect map to programme actions.
  • Guidance on building an integrated, AI-driven HRM platform to support behaviour measurement and response.
  • Examples of how organisational behaviour principles can be used to improve security culture over time.
  • The source's framing of HRM as a strategic operating model rather than a one-off awareness exercise.

👉 Read KnowBe4's whitepaper on strategic human risk management →

Human risk management and the governance gap security teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Human risk is a governance problem, not a training problem. Awareness campaigns have value, but they do not by themselves change how organisations detect, constrain, and respond to risky human behaviour. When the same mistakes recur, the issue is usually control design, measurement, or accountability. For IAM and security leaders, the practical conclusion is that human-risk management must be treated as an operational discipline, not an annual exercise.

A question worth separating out:

Q: How can security teams reduce human error without blaming users?

A: Use design and governance instead of blame. Tighten verification steps, reduce unnecessary exceptions, improve reporting paths, and apply stronger controls to high-impact roles. Human error will always exist, so the programme should limit how far one mistake can travel.

👉 Read our full editorial: Human risk management is closing the gap in breach prevention



   
ReplyQuote
Share: