Human risk management is the practice of measuring employee security behaviour — phishing simulation clicks, suspicious-email reports, reporting speed and training completion — and using those measurements to decide who needs coaching next. It treats the human layer the way IT treats servers: monitored continuously, reported monthly and improved with targeted action, instead of an annual course everyone forgets by February. This guide defines the practice, shows the published evidence behind it and explains how to run it in a small team in 2026.
What is human risk management?
Human risk management is a loop, not a course. Four stages run every month:
| Stage | What happens | Output |
|---|---|---|
| Measure | A phishing simulation runs; clicks, reports and reporting speed are recorded alongside training completion | Raw behaviour data |
| Rank | The signals combine into a per-person risk score | A ranked list of who is actually risky |
| Coach | The riskiest few get targeted help — a nudge, a role-based lesson, a repeat-clicker session | Behaviour change where it matters |
| Report | Click rate and report rate trend over time into an evidence pack | Proof for insurers, auditors and clients |
The output of stage two is what separates human risk management from a course library: a named, ranked list of the handful of people who carry most of the risk. Company averages hide them; a per-person score surfaces them.
Why the annual training model stopped working
Three shifts made the old model — one long course, a completion checkbox, done — obsolete:
- The threat moved. Lures now reference real suppliers, real colleagues and real deadlines, and volume keeps climbing: KnowBe4's 2026 Phishing by Industry Benchmarking Report records a 17.1% increase in phishing attacks since the second half of 2025. Static knowledge decays faster than attack tactics change.
- The risk sits with people. The 2025 Verizon Data Breach Investigations Report puts the human element in about 60% of breaches — error, manipulation or misuse.
- The cost of one click rose. The Australian Signals Directorate's Annual Cyber Threat Report 2024-25 puts the average self-reported cybercrime cost for a small business at $56,600, up 14% on the prior year. For a ten-person business that is a year's profit.
Completion rates measure none of this. A team can post 100% training completion and still click at the industry baseline — attendance says nothing about who would click a lure tomorrow. Behaviour is the only metric that predicts the incident, so behaviour is what human risk management measures.
The evidence it works
The strongest public dataset is KnowBe4's benchmarking series, built on 67.7 million phishing simulations across 14.5 million users in its 2026 report:
- Untrained staff are risky. The global baseline Phish-prone Percentage is 33.2% — roughly one in three employees clicks a simulated phish before any training.
- The loop works. After twelve months of consistent training and simulation, susceptibility falls 79%, to a global average of 4.2%.
- Small teams start safer. Organizations with 1-250 employees show a 24.6% baseline, versus 40.5% for those with 10,000 or more — smaller teams improve faster because they start lower.
- Reporting is the other half. Published benchmark report rates sit around 21% (KnowBe4's benchmark data); a person reporting above that line is demonstrating the exact reflex the programme exists to build.
The pattern that matters: high baseline, large reduction, residual risk concentrated in a named few. That residual 4.2% is exactly what the ranking stage targets.
How to run it in a small team
You can run the loop manually with email and a spreadsheet:
- Baseline simulation (month 1). One unannounced phish to everyone. No coaching first — you need the true starting click rate, which for an untrained team lands near one in three.
- Deploy the report button (month 1). One-click reporting in every mailbox, credited from day one.
- First lesson (month 2). Ten minutes, phishing-focused, completed by everyone.
- Second simulation (month 3). A different lure. Compare click rate to your baseline and report rate to the ~21% benchmark. If neither moves in a quarter, the problem is the programme, not the staff.
- Rank and coach (from month 3). Rank people by clicks, reports and speed. Coach the top of the ranking with the smallest effective action — a two-minute nudge after a click, an invoice-fraud deep dive for finance, a targeted simulation for repeat clickers. Blanket retraining wastes everyone's time. Celebrate fast reporters publicly.
- Quarterly evidence pack. Click rate trend, report rate trend, completion — what an insurer or auditor actually asks for.
The manual version works but decays: someone must own the calendar, run campaigns and chase completion forever. Cyber Aware's security awareness training and phishing simulations automate the loop — auto-enrolment, scheduled campaigns, reminders and per-person scoring — and Cyber Aware's human risk reporting turns stage four into branded PDFs for insurers, auditors and quarterly reviews.
What it costs
Tooling in this market is priced per user per month — Cyber Aware's 2026 analysis of published anti-phishing rates puts typical tooling at $2.08-$2.40 per user per month — and set against the $56,600 average cost of a single cybercrime incident for an Australian small business, a full year of programme costs roughly 2-3% of one incident. Price in two traps: simulation add-ons charged separately from training, and onboarding fees that double the first-year bill.
The limits to know before you start
- A click rate is a signal, not a breach probability. Mature programmes plateau at 3-5%; use the trend, not the raw number.
- Scores can be gamed. A person who reports everything — including legitimate email — inflates their positive signal. Audit for it occasionally.
- Privacy and fairness matter. In Australia, keep scores behind manager-level access, frame them as coaching rather than discipline, and never use simulation results for disciplinary action — it is legally fraught and suppresses the reporting culture the score depends on.
- It does not replace technical controls. MFA, tested backups and patching do the heavy lifting; human risk management covers the attacks that arrive despite them.
Before launching the programme, run a cyber security gap assessment so the human-layer work sits alongside the technical gaps it is meant to cover.
FAQ
What is human risk management in one sentence? The practice of measuring employee security behaviour — clicks, reports and training completion — and using those measurements to target coaching where the risk actually sits, run monthly rather than annually.
Is human risk management the same as security awareness training? No. Training is one input; human risk management is the operating model around it — measure, rank, coach, report.
What data does a human risk programme use? Phishing simulation clicks, suspicious-email reports, reporting speed, repeat-click history, training completion and policy acknowledgements.
How long before results show? Click rates fall measurably within the first quarter of monthly simulations; the benchmark reduction to about 4-5% takes roughly twelve months.
Does it work for small teams? Yes — organizations with 1-250 employees show a 24.6% baseline phishing rate, lower than large enterprises, so the same loop improves them faster.
Is a human risk score fair to employees? It is when it drives coaching, not discipline. Keep scores manager-visible and no-blame; using them for disciplinary action is legally fraught and suppresses reporting.