Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should security teams use human risk data…
Cyber Security

How should security teams use human risk data to reduce risky behaviour without relying on blanket controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Cyber Security

Security teams should combine identity, phishing, endpoint, and training signals into a single risk view, then act on the users and behaviours that drive most exposure. The report shows the top 10% of users account for nearly three quarters of risky actions, so targeted coaching, access review, and timely nudges are more effective than broad, uniform mandates.

Human risk data should change who gets intervention, not just how much policy gets written

Human risk data is useful when it helps security teams distinguish between general awareness problems and a small set of users, roles, or behaviours that create disproportionate exposure. That makes the question less about issuing another blanket mandate and more about deciding where targeted coaching, access review, and workflow nudges will have the biggest effect. The NIST Cybersecurity Framework 2.0 is relevant here because it treats governance, protection, and improvement as connected responsibilities rather than isolated tasks, which fits a risk-based people-control model.

Blanket controls often look fair, but they usually waste effort on low-risk users while leaving the highest-risk behaviours insufficiently addressed. Security teams get better results when they combine identity, endpoint, phishing, and training data into one view and then treat repeated risky actions as a prioritisation signal rather than as a reason to punish everyone equally. In practice, many security teams discover that broad awareness programmes change reporting rates long before they change the behaviour of the few users driving most exposure.

How security teams turn human risk signals into practical intervention

The practical model is to treat human risk data as an operational triage layer. Teams start by joining the signals that already exist across identity systems, email security, endpoint telemetry, training completion, and incident response records. The point is not to build a perfect person-level score, but to identify repeated patterns that are actionable: frequent credential hygiene failures, high phishing susceptibility, unsafe access requests, ignored prompts, or repeated exceptions around sensitive workflows.

Once those patterns are visible, the response should match the behaviour, not the whole workforce. A user who clicks suspicious links may need focused phishing coaching and simulated follow-up; a user who repeatedly requests excessive access may need manager review and tighter approval steps; a role with chronic exceptions may need process redesign rather than more reminders. This is where targeted control beats blanket control, because the intervention is tied to the actual failure mode.

  • Use the combined data to rank behaviours that create the most exposure, not to label people as inherently risky.
  • Separate one-off mistakes from repeated patterns, because the response should differ.
  • Link intervention to the control point that failed, such as identity assurance, email judgement, or privileged access approval.
  • Review whether the risk is individual, role-based, or process-based before deciding on coaching or enforcement.

Where this breaks down is when the data is fragmented, stale, or used only for dashboards. If teams cannot translate signals into a specific intervention path, the model becomes surveillance instead of risk reduction.

When targeted human-risk controls need exceptions, not just enforcement

Tighter targeting often improves relevance, but it also increases the risk of false confidence, uneven treatment, and over-automation, so organisations must balance precision against explainability. Not every elevated signal should trigger the same response, and not every risky behaviour is a training problem. Some cases are governed by role, process design, or access architecture, which means the right fix may be structural rather than corrective.

One common disagreement is whether human risk should be used only for security coaching or also for access decisions. There is no universal consensus. A conservative approach is to use the data first for prioritisation and review, then apply stronger restrictions only when the behaviour is repeated, material, and tied to a sensitive workflow. That helps avoid turning every measured deviation into an immediate denial.

Targeted controls also need monitoring for fairness and drift. If the same behaviour is being flagged differently across teams, locations, or job functions, the model is probably reflecting process noise as much as human risk. The strongest programmes keep the intervention logic transparent enough that business managers can understand why a user was singled out and what improvement would end the extra scrutiny.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organisational ContextHuman-risk prioritisation should reflect business-critical exposure and role context.
GV.RM-02 — Risk Management StrategyCombining user signals into one view supports risk-based targeting over blanket rules.
PR.AA-01 — Identity Proofing and Credential BindingHuman-risk signals often reveal weak identity-related behaviours that raise access exposure.
Recommendation — Align interventions to the exposures that matter most to the organisation. Use risk-based targeting to focus controls on the highest-exposure behaviours. Tie elevated identity-related behaviour to stronger review before granting access.
CIS Controls v814 — Security Awareness and Skills TrainingBehavior-driven coaching is a prescriptive way to address repeat risky actions.
6 — Access Control ManagementHuman-risk data can justify tighter review of excessive or repeatedly misused access.
8 — Audit Log ManagementCombining signals into one view depends on reliable telemetry from multiple systems.
Recommendation — Deliver targeted training to users whose behaviour creates repeated exposure. Review and restrict access paths that correlate with repeated risky behaviour. Centralise and retain telemetry needed to spot recurring risky actions.
OWASP Non-Human Identity Top 10NHI-04 — Least Privilege and Access ScopeRisky human behaviour often manifests as excessive access requests or misuse paths.
NHI-06 — Monitoring and Anomaly DetectionHuman-risk data depends on correlating identity and behaviour signals across systems.
Recommendation — Limit access scope when behavioural signals indicate repeated misuse or overreach. Correlate identity and activity signals to detect repeated risky patterns.

Practitioner Guidance

What to prioritise: Start with the few behaviours that create the most exposure, then map each one to a specific intervention path such as coaching, approval tightening, or access review. The objective is to reduce repeat exposure, not to make every user equally monitored.

What to verify: Confirm that the signal is repeatable, recent, and tied to an actual control weakness before escalating it. A useful human-risk model should distinguish between isolated mistakes, recurring patterns, and role-driven exceptions.

Decision rule: If the data cannot explain why a user was flagged and what would change the outcome, do not use it for enforcement. Use it first to prioritise review and improve the underlying workflow.

Practitioner takeaway: Human risk data works best when it narrows security attention to the behaviours that matter most and supports proportionate action, not when it becomes a universal scoring system for the whole workforce.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org