Human Risk Management (HRM): How to Measure and Reduce Human Cyber Risk

Human risk management (HRM) measures and reduces the security risk people create. How to measure it, the AI-based approach, how it differs from HR risk management, and the steps to run a program.

Madhurendra SachanBy Madhurendra Sachan
July 14, 2023
9 min read
Updated October 7, 2026
Human Risk Management

Human risk management (HRM) is the practice of measuring and reducing the security risk that people create through their behaviour: who clicks a phishing link, who reports it, who enters a password on a fake page, who falls for a call from the “IT helpdesk”. Instead of one annual training course, an HRM program tests people with realistic simulated attacks, measures how each person and team responds, trains them on what they actually got wrong, and tracks whether the risk is falling.

This guide covers how human risk is measured, the AI-based approach to reducing it, how it differs from HR risk management, and the steps to run a program.

Human risk management: an employee at a computer surrounded by security signals

Why human risk is the gap most security programs miss

The Verizon 2025 Data Breach Investigations Report found that the human element was involved in roughly 60% of the breaches it analysed: someone clicked, replied, approved or picked up the phone, and the attack moved forward because of it. Firewalls, email filters and endpoint tools reduce how many attacks reach people. They cannot decide what a person does once one does.

That is why human risk needs the same treatment as any other risk: a baseline, a metric, controls that target the weak spots, and a trend you can report on. Awareness training on its own gives you a completion rate, which tells you who watched a video, not who would hand over their password.

How human risk is measured

Human risk is measured from behaviour in realistic simulations and real reports, per person and per team, over time. These are the metrics that matter:

Metric What it shows Direction you want
Report rate Share of people who report a simulated (or real) phish to security Up
Click rate Share of people who click a simulated phishing link or open the attachment Down
Data submission rate Share who enter credentials or data on the simulated landing page Down
Repeat clickers People who fail more than one simulation in a period Down, and shrinking
Time to report How quickly the first reports reach the security team after a campaign starts Shorter
Risk score by person and team One score combining the signals above, weighted by recency and role Falling over time

Report rate deserves the most attention. In the 2025 DBIR, employees who had security training in the previous 30 days reported simulated phishing at about 21%, against a base rate of 5%, while the effect of training on click rate was much smaller. People will always click sometimes; a team that reports fast lets the security team pull the email and contain the attack before it spreads.

Time to report matters for the same reason. The first report on a real campaign is what triggers the response, so the minutes between delivery and that first report are your exposure window.

The AI-based approach to human risk reduction

Traditional programs send everyone the same template a few times a year and assign the same course to everyone who fails. An AI-based approach runs a continuous loop for each person instead: Simulate, Measure, Train, Track.

1. Simulate: adaptive attacks by role and behaviour

AI writes simulations that fit each person’s role and history. Finance gets invoice and payment-change lures, HR gets CV attachments and payroll requests, executives get board and legal pretexts, and the helpdesk gets password reset calls. Someone who spots every email lure moves on to harder ones or to another channel, such as SMS, a QR code or a voice call.

2. Measure: behaviour, not attendance

Every simulation records who clicked, who submitted data, who reported and how fast, building the per-person and per-team view described above.

3. Train: just-in-time microlearning

When someone fails, they get a short lesson on the exact cue they missed, at the moment they missed it, not a generic module weeks later. People who did well get less training, so the time goes where the risk is.

4. Track: risk falling over time

Risk scores, report rates and repeat clickers are tracked campaign over campaign, so you can show leadership whether human risk is actually going down, and which teams need more attention.

Human risk management vs HR risk management

The terms are often confused, and so are people risk management, employee risk management and human capital risk management. They overlap on people but answer different questions:

Human risk management (cybersecurity) HR, people or human capital risk management
Question it answers Will our people be the way an attacker gets in? Do we have the right people, and are we managing workforce risk?
Typical owner CISO or security awareness lead HR leadership, CHRO, operations and compliance
Risks covered Phishing, smishing, vishing, credential theft, social engineering, unsafe data handling Turnover, key-person dependency, skills gaps, succession, misconduct, employment law and safety compliance
Typical metrics Report rate, click rate, repeat clickers, time to report, risk score Attrition, time to hire, engagement, absence, incidents and grievances
Typical tools Phishing simulation, adaptive training, report button and triage HRIS, performance and engagement tools, policy and case management

Where they meet: joiners, movers and leavers. HR owns the processes; security needs them to work, because access that is not removed when someone leaves, or a new joiner who has never seen a phishing test, is human risk. A good HRM program starts new joiners on simulations and training in their first weeks and ties offboarding to access removal.

If you searched for HR risk management in the workforce sense, this guide covers only the security side. If you are a security team, everything that follows is for you.

How to build a human risk management program

  1. Take a baseline. Run an unannounced simulation across the whole organisation so you know today’s click, submission and report rates before any training changes them.
  2. Define your metrics and risk score. Agree which signals count, how recent behaviour is weighted and what a high-risk person or team looks like, then share that definition with leadership.
  3. Segment by role and exposure. Finance, HR, executives, IT helpdesk and anyone with admin rights face different attacks and carry different impact. Give them different simulations.
  4. Simulate continuously across channels. Monthly is a sensible starting rhythm. Mix email with SMS, QR codes and voice calls, because attackers do.
  5. Train at the moment of failure. Short lessons tied to the cue the person missed work better than long annual courses. Keep the annual course if a regulator requires it, but do not rely on it.
  6. Make reporting easy and thank reporters. A one-click report button and a quick, friendly acknowledgement raise report rates. Never punish clickers; it teaches people to hide mistakes.
  7. Review by team every quarter. Report trends, repeat clickers and time to report to leadership, and move effort to the teams whose risk is not falling.

For the learning side of the program, NIST SP 800-50 Rev. 1 (Building a Cybersecurity and Privacy Learning Program, September 2024) is a useful public reference for planning, roles and evaluation.

Common mistakes

  • Measuring only click rate and ignoring report rate and time to report.
  • Sending everyone the same template, so the results say more about the template than the people.
  • Announcing simulations in advance, which measures the warning, not the behaviour.
  • Naming and shaming repeat clickers instead of giving them more practice and support.
  • Treating a completed course as reduced risk.

How PhishGrid runs human risk management

PhishGrid is our product, so read this section with that in mind. It is an AI-based human risk reduction platform built on the loop above. The phishing simulation platform writes simulations for each person across email, SMS, voice and QR code, including AI voice phishing calls. Phishing awareness training gives each employee short daily lessons chosen from their own simulation results. Reporting tracks click rate, data submission, report rate, repeat clickers, lesson completion and a risk score by person, team and over time, and a Report Phishing button for Gmail feeds a threat inbox your team can triage.

You can browse attack templates by scenario, compare plans and pricing (there is a free plan), or book a demo to see the risk dashboard on your own data.

Conclusion

Human risk management treats people as part of your attack surface that you can measure and improve, not a box ticked by annual training. Baseline behaviour, simulate continuously and by role, train at the moment of failure, reward reporting, and track the risk score falling over time. That is the difference between a training program and a human risk program.

FAQs

What is human risk management?

Human risk management (HRM) is the practice of measuring and reducing the cybersecurity risk created by people’s behaviour. It uses realistic simulations to measure how people respond to attacks, targeted training to fix what they get wrong, and metrics such as report rate and risk score to track progress.

What is a human risk score?

A human risk score combines behavioural signals, such as failed simulations, data submissions, reports and training completion, into one number per person and team. Recent behaviour and higher-impact roles usually weigh more. It shows where to focus effort and whether risk is falling.

Is human risk management the same as security awareness training?

No. Security awareness training is one control inside human risk management. HRM adds measurement, simulations, targeting by role and behaviour, and tracking, so you can show that risk is actually going down rather than that courses were completed.

What is the difference between HR risk management and human risk management?

HR risk management deals with workforce risks such as turnover, skills gaps, succession, misconduct and employment compliance, and is owned by HR. Human risk management deals with security behaviour, such as phishing and social engineering, and is owned by security. They meet in joiner, mover and leaver processes.

What is people risk management?

People risk management usually means the HR and operational view of workforce risk, the same territory as HR or human capital risk management. In security, the people side of risk is covered by human risk management, which measures and reduces how likely staff are to be tricked by attackers.

How often should you run phishing simulations?

Monthly is a sensible starting rhythm for most organisations, with higher-risk roles tested more often. Continuous, varied simulations with immediate feedback build reporting habits; a single yearly test only measures a moment.

Ready to reduce your human risk?

PhishGrid helps you run phishing simulations and build a culture of security awareness across your organisation, for free.

Start Free