Yes, when the goal is measurable risk reduction rather than compliance alone. Awareness campaigns still have value, but they do not tell teams who is most likely to cause an incident or when intervention is needed. Predictive analytics helps security teams focus limited resources on users, roles, and behaviors that present the highest near-term risk.
Why This Matters for Security Teams
Security leaders are increasingly judged on whether awareness programs change behaviour, not just whether training was delivered. Traditional campaigns are useful for baseline hygiene, but they usually treat the workforce as a single audience. Predictive human risk analytics shifts the question toward exposure, likelihood, and intervention timing, which is more operationally useful when phishing, credential abuse, and policy exceptions drive incidents. That approach also fits the broader control model in the NIST Cybersecurity Framework 2.0, where risk management should be tied to measured outcomes rather than activity volume alone.
The practical value is prioritisation. A security team with limited time can target high-risk users, repeated behaviours, or departments with recurring control failures instead of sending the same message to everyone. That does not make awareness obsolete. It means awareness becomes one input into a risk-based program, not the program itself. Current guidance suggests that the strongest results come from combining behavioural signals, incident history, and contextual exposure rather than relying on completion rates or annual click-through tests.
In practice, many security teams discover the limits of awareness only after a recurring incident pattern has already been normalised into business-as-usual.
How It Works in Practice
Predictive human risk analytics usually combines telemetry from email, identity, endpoint, and user activity sources to estimate which people or groups are most likely to create security exposure. The objective is not to label employees as unsafe, but to identify where the next control failure is most likely to appear. Useful signals often include repeated phishing susceptibility, privileged access use, unusual login patterns, policy bypasses, and changes in role or workload that correlate with mistakes.
A workable program generally follows three steps. First, define the behaviours that matter, such as credential sharing, unsafe file handling, or approval anomalies. Second, connect those behaviours to measurable signals from SIEM, IAM, HR, and training records. Third, use the results to trigger proportionate interventions such as targeted coaching, step-up verification, temporary access review, or manager escalation. The aim is to reduce risk without turning analytics into surveillance theatre.
- Use awareness campaigns to set baseline expectations for all users.
- Use predictive scoring to focus interventions where incidents are most likely.
- Validate models against actual incident outcomes, not training completion.
- Review for bias, false positives, and overcollection before operational rollout.
For organisations building a defensible program, the NIST Cybersecurity Framework 2.0 is useful for linking people-risk decisions to governance, protection, and detection outcomes, while CIS and identity telemetry can supply the behavioural evidence that makes the scoring actionable. These controls tend to break down in highly decentralised environments with poor identity hygiene and fragmented logging because the model cannot distinguish normal variation from actual risk.
Common Variations and Edge Cases
Tighter human risk scoring often increases privacy, labour-relations, and governance overhead, requiring organisations to balance better targeting against acceptable monitoring boundaries. That tradeoff is especially visible in regulated sectors, where analytics may be permissible but still need clear purpose limitation, retention controls, and transparent escalation paths.
There is no universal standard for how predictive a human risk model must be before it becomes trustworthy. Best practice is evolving, and organisations should treat the score as decision support rather than an automated verdict. In mature programs, the score informs coaching, access reviews, and segmentation of awareness content. In less mature environments, it can create noise if the underlying data is incomplete or if managers use it punitively.
Edge cases matter. High turnover teams, contractors, shared accounts, and sparse telemetry can all distort the signal. If identity data is weak, the analytics may overfit to easy-to-measure behaviour rather than meaningful risk. That is why awareness campaigns still matter: they provide broad coverage for baseline threats, while predictive analytics provides precision for the cases that warrant intervention. The best operating model is usually hybrid, with awareness for scale and analytics for prioritisation, rather than an either-or choice. For organisations also handling identity assurance or user verification workflows, the governance expectations in NIST Cybersecurity Framework 2.0 should be paired with clearly documented human review thresholds.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Risk management should drive whether predictive analytics or awareness gets priority. |
Tie human-risk analytics to governance outcomes and use the score to guide targeted controls.
Related resources from NHI Mgmt Group
- Should organisations prioritise zero standing privilege over traditional PAM checkout?
- Should organisations prioritise data awareness over manual tagging?
- Should organisations prioritise IGA coverage over point-tool access analytics?
- When should organisations prioritise behavioral analytics over more logging?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org