Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Human risk management: what changes for security teams now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI-driven social engineering and persistent ransomware are outpacing security awareness training alone, according to Knowbe4, and 74% of CISOs still rank human error as their top cybersecurity risk while 87% are turning to AI-powered tools. The bigger shift is toward Human Risk Management as a layered governance model for measuring behaviour, reducing exposure, and linking people-centric controls to broader security outcomes.

NHIMG editorial — based on content published by Knowbe4: CISO's Guide: Top 4 Considerations for Human Risk Management

By the numbers:

Questions worth separating out

Q: How should security teams use human risk management instead of awareness training alone?

A: Use awareness training for baseline education and human risk management for ongoing intervention.

Q: Why do human errors keep bypassing security controls?

A: Because many controls still depend on human judgement at the point of risk.

Q: What do security teams get wrong about human risk management?

A: They often treat it as a training completion problem instead of a resilience problem.

Practitioner guidance

  • Define human-risk metrics that map to loss events Track reporting latency, repeat susceptibility, risky approval behaviour, and exception frequency, then correlate them with phishing, fraud, and access abuse outcomes.
  • Harden identity workflows that rely on people Review password resets, MFA recovery, privileged approvals, and help desk escalation paths for opportunities where attackers can manipulate a human into bypassing policy.
  • Replace awareness-only reporting with control reporting Report to leadership on changes in failed social engineering attempts, reduced exception volume, and faster detection of suspicious requests rather than training completion alone.

What's in the full article

Knowbe4's full eBook covers the operational detail this post intentionally leaves for the source:

  • A fuller comparison of traditional security awareness training and Human Risk Management, including how the operating model changes.
  • Specific metrics and ROI indicators that can be used to report human-risk performance to executives and stakeholders.
  • Practical guidance for building a layered programme that combines process, technology, and culture without relying on training alone.

👉 Read Knowbe4's eBook on the top four considerations for Human Risk Management →

Human risk management: what changes for security teams now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Human risk management is becoming an identity governance problem, not just a training problem. The article correctly frames HRM as a blend of process, technology, and culture, but the deeper issue is that identity programmes still depend on people making reliable decisions under pressure. That means identity verification, help desk workflows, privileged approvals, and exception handling all sit inside the human risk boundary. Practitioners should treat HRM as an extension of IAM and PAM governance, not a separate awareness initiative.

A question worth separating out:

Q: How do IAM and PAM controls support vulnerability management programmes?

A: IAM and PAM support the programme by controlling who can run scans, approve changes, access remediation systems, and manipulate evidence. If those roles are overbroad or poorly reviewed, vulnerability tooling itself becomes a privileged access pathway. Governance should therefore cover scanner accounts, remediation operators, and the audit trail around both.

👉 Read our full editorial: Human risk management is replacing awareness-only security models



   
ReplyQuote
Share: