Human risk management (HRM) is the practice of measuring and reducing the security risk that people create through their behaviour: who clicks a phishing link, who reports it, who enters a password on a fake page, who falls for a call from the “IT helpdesk”. Instead of one annual training course, an HRM program tests people with realistic simulated attacks, measures how each person and team responds, trains them on what they actually got wrong, and tracks whether the risk is falling.
This guide covers how human risk is measured, the AI-based approach to reducing it, how it differs from HR risk management, and the steps to run a program.

Why human risk is the gap most security programs miss
The Verizon 2025 Data Breach Investigations Report found that the human element was involved in roughly 60% of the breaches it analysed: someone clicked, replied, approved or picked up the phone, and the attack moved forward because of it. Firewalls, email filters and endpoint tools reduce how many attacks reach people. They cannot decide what a person does once one does.
That is why human risk needs the same treatment as any other risk: a baseline, a metric, controls that target the weak spots, and a trend you can report on. Awareness training on its own gives you a completion rate, which tells you who watched a video, not who would hand over their password.
How human risk is measured
Human risk is measured from behaviour in realistic simulations and real reports, per person and per team, over time. These are the metrics that matter:
| Metric | What it shows | Direction you want |
|---|---|---|
| Report rate | Share of people who report a simulated (or real) phish to security | Up |
| Click rate | Share of people who click a simulated phishing link or open the attachment | Down |
| Data submission rate | Share who enter credentials or data on the simulated landing page | Down |
| Repeat clickers | People who fail more than one simulation in a period | Down, and shrinking |
| Time to report | How quickly the first reports reach the security team after a campaign starts | Shorter |
| Risk score by person and team | One score combining the signals above, weighted by recency and role | Falling over time |
Report rate deserves the most attention. In the 2025 DBIR, employees who had security training in the previous 30 days reported simulated phishing at about 21%, against a base rate of 5%, while the effect of training on click rate was much smaller. People will always click sometimes; a team that reports fast lets the security team pull the email and contain the attack before it spreads.
Time to report matters for the same reason. The first report on a real campaign is what triggers the response, so the minutes between delivery and that first report are your exposure window.
The AI-based approach to human risk reduction
Traditional programs send everyone the same template a few times a year and assign the same course to everyone who fails. An AI-based approach runs a continuous loop for each person instead: Simulate, Measure, Train, Track.
1. Simulate: adaptive attacks by role and behaviour
AI writes simulations that fit each person’s role and history. Finance gets invoice and payment-change lures, HR gets CV attachments and payroll requests, executives get board and legal pretexts, and the helpdesk gets password reset calls. Someone who spots every email lure moves on to harder ones or to another channel, such as SMS, a QR code or a voice call.
2. Measure: behaviour, not attendance
Every simulation records who clicked, who submitted data, who reported and how fast, building the per-person and per-team view described above.
3. Train: just-in-time microlearning
When someone fails, they get a short lesson on the exact cue they missed, at the moment they missed it, not a generic module weeks later. People who did well get less training, so the time goes where the risk is.
4. Track: risk falling over time
Risk scores, report rates and repeat clickers are tracked campaign over campaign, so you can show leadership whether human risk is actually going down, and which teams need more attention.
Human risk management vs HR risk management
The terms are often confused, and so are people risk management, employee risk management and human capital risk management. They overlap on people but answer different questions:
| Human risk management (cybersecurity) | HR, people or human capital risk management | |
|---|---|---|
| Question it answers | Will our people be the way an attacker gets in? | Do we have the right people, and are we managing workforce risk? |
| Typical owner | CISO or security awareness lead | HR leadership, CHRO, operations and compliance |
| Risks covered | Phishing, smishing, vishing, credential theft, social engineering, unsafe data handling | Turnover, key-person dependency, skills gaps, succession, misconduct, employment law and safety compliance |
| Typical metrics | Report rate, click rate, repeat clickers, time to report, risk score | Attrition, time to hire, engagement, absence, incidents and grievances |
| Typical tools | Phishing simulation, adaptive training, report button and triage | HRIS, performance and engagement tools, policy and case management |
Where they meet: joiners, movers and leavers. HR owns the processes; security needs them to work, because access that is not removed when someone leaves, or a new joiner who has never seen a phishing test, is human risk. A good HRM program starts new joiners on simulations and training in their first weeks and ties offboarding to access removal.
If you searched for HR risk management in the workforce sense, this guide covers only the security side. If you are a security team, everything that follows is for you.
How to build a human risk management program
- Take a baseline. Run an unannounced simulation across the whole organisation so you know today’s click, submission and report rates before any training changes them.
- Define your metrics and risk score. Agree which signals count, how recent behaviour is weighted and what a high-risk person or team looks like, then share that definition with leadership.
- Segment by role and exposure. Finance, HR, executives, IT helpdesk and anyone with admin rights face different attacks and carry different impact. Give them different simulations.
- Simulate continuously across channels. Monthly is a sensible starting rhythm. Mix email with SMS, QR codes and voice calls, because attackers do.
- Train at the moment of failure. Short lessons tied to the cue the person missed work better than long annual courses. Keep the annual course if a regulator requires it, but do not rely on it.
- Make reporting easy and thank reporters. A one-click report button and a quick, friendly acknowledgement raise report rates. Never punish clickers; it teaches people to hide mistakes.
- Review by team every quarter. Report trends, repeat clickers and time to report to leadership, and move effort to the teams whose risk is not falling.
For the learning side of the program, NIST SP 800-50 Rev. 1 (Building a Cybersecurity and Privacy Learning Program, September 2024) is a useful public reference for planning, roles and evaluation.
Common mistakes
- Measuring only click rate and ignoring report rate and time to report.
- Sending everyone the same template, so the results say more about the template than the people.
- Announcing simulations in advance, which measures the warning, not the behaviour.
- Naming and shaming repeat clickers instead of giving them more practice and support.
- Treating a completed course as reduced risk.
How PhishGrid runs human risk management
PhishGrid is our product, so read this section with that in mind. It is an AI-based human risk reduction platform built on the loop above. The phishing simulation platform writes simulations for each person across email, SMS, voice and QR code, including AI voice phishing calls. Phishing awareness training gives each employee short daily lessons chosen from their own simulation results. Reporting tracks click rate, data submission, report rate, repeat clickers, lesson completion and a risk score by person, team and over time, and a Report Phishing button for Gmail feeds a threat inbox your team can triage.
You can browse attack templates by scenario, compare plans and pricing (there is a free plan), or book a demo to see the risk dashboard on your own data.
Conclusion
Human risk management treats people as part of your attack surface that you can measure and improve, not a box ticked by annual training. Baseline behaviour, simulate continuously and by role, train at the moment of failure, reward reporting, and track the risk score falling over time. That is the difference between a training program and a human risk program.
