Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should organisations do when some employees are…
Cyber Security

What should organisations do when some employees are much riskier than others?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

They should stop treating awareness as one-size-fits-all and use risk data to prioritise support. High-risk individuals or groups need targeted coaching, policies, or follow-up actions, while lower-risk users may only need light reinforcement. This approach concentrates effort where it will reduce exposure fastest and avoids wasting time on people who already perform well.

Why Risk-Based Segmentation Works Better Than Uniform Training

The core issue is not whether awareness matters, but whether everyone needs the same intervention. Risk-based segmentation treats risky behaviour as an input to support design, so the organisation can spend more time where error or compromise is most likely and less time where habits are already sound. That makes the programme more measurable and less performative.

A practical programme separates the population into action bands, then matches the intervention to the exposure signal. For example, repeated policy misses, weak reporting behaviour, or higher incident correlation may justify deeper coaching or manager follow-up, while stable low-risk groups may only need brief reinforcement. The point is to match control intensity to observed need, not to equalise attention across the workforce.

Risk-based targeting also changes how success should be measured. Completion rates alone are weak evidence because they say little about whether the highest-risk cohort actually changed behaviour. Better measures are reduction in repeat errors, improved response to simulated events, fewer escalations from the same teams, and whether the gap between high-risk and low-risk groups narrows over time.

What Organisations Need to Change Operationally

Once risk differences are visible, the operating model has to follow them. That usually means using behaviour, role, location, system exposure, or prior incident history to define cohorts, then assigning different forms of follow-up. A high-risk group may need one-to-one coaching, tighter policy prompts, or manager accountability, while a lower-risk group can be handled with lightweight nudges and periodic reminders.

It also means security teams should coordinate with HR, compliance, and line managers where the issue is persistent rather than accidental. If the same group keeps appearing in the high-risk set, the answer may be poor workflow design, confusing policy language, or a control that is too burdensome for real work. In those cases, the objective is not just more training, but removing the conditions that keep producing the same mistakes.

This is also where evidence matters. Organisations should be able to show why a person or group was classified as higher risk, what intervention was assigned, and whether the next review showed improvement. Without that loop, risk-based awareness becomes a vague label rather than a managed control.

One useful reference point for this kind of prioritisation is NHIMG’s Ultimate Guide to NHIs, which shows how concentrated exposure often comes from the entities that are least visible, least governed, or least rotated. The same logic applies to people: the highest-risk population is where focused intervention usually pays off fastest.

Risk and Threat Considerations

Uniform awareness programmes create two common failure modes, first, they over-invest in low-risk users and leave the highest-risk people under-supported, and second, they hide the real exposure pattern because every group looks equally treated on paper. If risky behaviour is concentrated in a subset of staff, the organisation’s true exposure is often more localised than broad completion metrics suggest.

Failure mechanism: The control weakens when teams assume training completion equals risk reduction, even though repeated mistakes, poor judgment under pressure, or role-specific exposure still cluster in predictable groups. That leaves the most vulnerable users with the least effective intervention.

Impact: The organisation keeps the same high-risk behaviours in circulation, which increases the likelihood of policy bypass, unsafe handling of sensitive data, or preventable security incidents. Over time, this also distorts reporting because leaders see broad coverage but not the persistent pockets of exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-01 — Awareness and TrainingRisk-based awareness segmentation directly supports training that reflects user risk and role exposure.
GV.RM-01 — Risk Management StrategyPrioritising support by risk data is a governance decision about where security effort is invested.
Recommendation — Target awareness effort by user risk and validate that training changes behaviour in the highest-risk cohorts. Use risk data to direct security spend toward the cohorts that reduce exposure fastest.
CIS Controls v814 — Security Awareness and Skills TrainingThe question is about making awareness more effective by tailoring it to observed risk.
Recommendation — Use differentiated training paths and measure whether repeat risky behaviours decline.

Practitioner Guidance

What to prioritise: Start with the cohorts that have the clearest evidence of repeat mistakes, incident correlation, or elevated exposure. If you cannot explain why a group is high risk, the segmentation is probably too coarse or not tied closely enough to operational behaviour.

What to verify: Check that each tier has a defined trigger, a specific follow-up action, and a review date. If the high-risk cohort keeps receiving the same generic module as everyone else, the programme is not truly risk-based.

Practitioner takeaway: The useful question is not how many people were trained, but whether the extra effort reached the people whose behaviour actually drives exposure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org