Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should organisations combine awareness training with targeted…
Governance, Ownership & Risk

When should organisations combine awareness training with targeted interventions and risk scoring?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Organisations should combine the two when a broad training-only model no longer matches the complexity of their digital environment. If employees face email, chat, collaboration tools, and different privilege levels, generic instruction is usually too blunt. Risk scoring and targeted interventions help prioritize the highest-risk users, improve relevance, and support measurable behavior change over time.

When does training stop being enough on its own?

Training-only programs work best when user behaviour is relatively uniform and the environment is simple. Once people interact with multiple channels, varied data, and different levels of access, the same message no longer fits every audience. At that point, awareness becomes a baseline control, not the full control model.

The practical trigger is not just “more users,” but more variation in exposure and decision-making. If some users are more likely to approve payments, handle sensitive data, or receive high-volume social engineering, a single annual module cannot distinguish between low-impact and high-impact behaviour.

How risk scoring changes the intervention model

Risk scoring lets organisations move from broad instruction to prioritized action. Instead of assuming every user needs the same nudge, the organisation can identify who is more exposed, who is more likely to make a costly mistake, and where a small change in behaviour would reduce the most risk.

That shift matters because targeted interventions are not a replacement for awareness, they are a way to make awareness actionable. In practice, that can mean focused coaching, just-in-time prompts, phishing follow-up, manager escalation, or additional review for users whose role, history, or access profile suggests higher exposure. The point is to change behaviour where it matters most, not to increase training volume.

What makes the combined approach worth using?

The combined model is most defensible when the organisation can measure difference in risk, not just completion of training. If the same intervention is delivered to everyone, the program may look comprehensive while still missing the people and behaviours that drive loss, fraud, or compromise.

Used well, the combination improves relevance, reduces fatigue, and gives security teams a better signal for progress. It also helps leadership treat user intervention as part of a control system, where observed behaviour, exposure, and follow-up activity can be tracked over time rather than assumed from attendance records alone.

Risk and Threat Considerations

Without targeting, awareness programs often create blind spots: high-risk users receive the same light-touch messaging as low-risk users, while risky behaviour can persist because the program has no mechanism to distinguish exposure levels. Attackers benefit from that gap because they do not need every user to fail, only one well-placed user with the wrong access or decision path.

Failure mechanism: Generic training produces uneven protection when role, privilege, and exposure differ. Risk scoring fails if it is based only on completion data or static profiles and does not reflect actual behaviour, recent incidents, or current access patterns.

Impact: The organisation can overinvest in low-value awareness activity while under-protecting the users most likely to cause material loss, delay detection of unsafe behaviour, and miss the chance to intervene before risky actions repeat.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyRisk scoring is a user-risk prioritization method that belongs in a formal risk strategy.
ID.RA-01 — Risk IdentificationThe question is about identifying which users need targeted treatment based on risk.
PR.AT-01 — Awareness and TrainingAwareness training remains the baseline control being augmented by targeted interventions.
Recommendation — Define user-risk thresholds that trigger targeted interventions and follow-up. Identify exposure and behaviour indicators that justify targeted awareness actions. Tailor awareness content to the risks most likely to affect each user group.
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingThe subject directly concerns how awareness training should be adapted and reinforced.
CIS-6 — Access Control ManagementHigher-risk users are often those with more privileged or sensitive access.
Recommendation — Use role-based awareness and reinforce it with targeted user interventions. Prioritise additional monitoring and review for users with greater access.

Practitioner Guidance

What to prioritise: Start with users whose mistakes can create immediate business impact, such as those handling payments, customer data, or privileged workflows. If the risk score cannot explain why someone is being targeted, the intervention model is probably too opaque to defend or improve.

What to verify: Check that the risk model reflects behaviour and exposure, not just HR category or training history. Good programs can show why a user was selected, what intervention they received, and whether the follow-up changed the measured outcome.

Practitioner takeaway: Combine awareness training with targeted interventions when you need control precision, not just broad coverage; the program should direct effort toward the users and behaviours most likely to change the loss profile.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org