Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Human risk management: are your controls measuring behavior or completion?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Human risk management is framed here as a move beyond awareness training toward measurable behavior change, with the DEEP framework, four personas, and integration guidance intended to unify existing security controls around people-focused risk reduction, according to KnowBe4. The core issue is that completion metrics do not prove reduced exposure, so governance must track behavior, not participation.

NHIMG editorial — based on content published by KnowBe4: Whitepaper A Practical Guide to Human Risk Management

By the numbers:

Questions worth separating out

Q: How should security teams measure whether human risk management is actually reducing risk?

A: Use outcome metrics, not just participation data.

Q: Why do persona-based controls matter in human risk programmes?

A: Because different users create different risk surfaces.

Q: What do organisations get wrong about awareness training and human risk?

A: They often treat training completion as the same thing as reduced risk.

Practitioner guidance

  • Define behaviour-based success metrics Replace completion-only reporting with measures such as phishing reporting rates, risky click rates, policy exception frequency, and secure workflow adherence by persona.
  • Segment human-risk controls by persona Map roles, exposure, and workflow differences to targeted education, monitoring, and friction levels so high-risk groups do not receive generic treatment.
  • Tie HRM signals to identity governance Feed human-risk findings into access reviews, approval workflows, and exception handling so behaviour data changes IAM decisions rather than sitting in a separate dashboard.

What's in the full article

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The DEEP framework guidance for turning Defend, Educate, Empower, and Protect into a working programme structure
  • Persona-based segmentation examples that show how different user groups should receive different security treatment
  • Measurement guidance for tracking behaviour change instead of relying on completion metrics alone
  • Integration ideas for embedding human-risk signals across your existing security stack

👉 Read KnowBe4's practical guide to human risk management and the DEEP framework →

Human risk management: are your controls measuring behavior or completion?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Human risk management becomes credible only when it produces control outcomes, not engagement metrics. Awareness-first programmes often confuse communication activity with risk reduction. The DEEP framing is useful because it links human behaviour to defendable control points, but the discipline still fails if completion is treated as success. Security leaders should judge HRM by whether it reduces risky behaviour in ways IAM, PAM, and monitoring can verify.

A question worth separating out:

Q: Should human risk management sit inside IAM and GRC programmes?

A: Yes, because human behaviour directly affects access approvals, MFA use, password handling, and exception requests. When HRM is isolated, teams can see risky behaviour but cannot change the access controls that shape it. Integrated governance makes the programme more actionable and much easier to prove.

👉 Read our full editorial: Human risk management is shifting from awareness to measurable behavior



   
ReplyQuote
Share: