PART 1 Introduction: Why this matters

One challenge that’s been poorly addressed for decades is:

How do we manage the cybersecurity risks associated with people?

The answer isn’t “awareness.” It never really was.

The cybersecurity industry has long acknowledged the importance of the human aspect. But the way it’s been tackled (usually through training, communications, and phishing simulations) hasn’t meaningfully reduced risk.

What matters is impact.

The focus is on designing interventions that actually change behavior. The goal is to validate whether those behaviors reduce risk. And the challenge is helping security teams do more with less, by automating what can be automated and measuring what truly matters.

This guide breaks down how we got here, why the old approach isn’t working, what’s driving the shift to HRM, and what it means for cybersecurity professionals today.

PART 2 What is security awareness, and why is it not enough?

What is security awareness, and why is it not enough?

The origin story

While the concept of educating users about security risks has been present since the early days of computing, the explicit use of the term “security awareness” in formal documentation and legislation began to solidify late ’80s, when it became clear people – not just tech – played a big role in keeping systems secure. The 1987 US Computer Security Act made awareness training mandatory for federal staff, and NIST followed up with guidance to help organizations do it properly. That’s when awareness really became “a thing” in cybersecurity.

The early response was logical:

“If people are part of the problem, let’s educate them.”

So, the field of “security awareness” was born. It focused on raising awareness of cyber risks through training, internal comms, and phishing simulations. These programs were largely driven by compliance requirements:

  • check the box
  • prove you told your staff what phishing is
  • move on

The flawed assumption

Security awareness was built on a deeply ingrained (and deeply flawed) assumption:

“If we raise awareness, people will behave more securely.”

It sounds reasonable. But as research has shown, knowing isn’t doing. You can understand a risk, be aware of the right action to take, and still behave insecurely in the moment.

The measurement gap

To make things worse, the metrics used to track “success” are often surface-level:

  • Training completion rates
  • Engagement scores
  • Phishing click and report rates
  • Sentiment or feedback from learners

These are sometimes called “vanity metrics”. High engagement doesn’t equal low risk. Someone can enjoy the training, ace the quiz, even report a phishing email…and still behave insecurely the next day.

The credibility problem

This is why security awareness, while seen as important, isn’t seen as valuable or credible by many security leaders. It’s underfunded compared to other security domains and often led by non-technical professionals who aren’t seen as peers by the rest of the security team.

PART 3 What is HRM? And what is it not?

What is HRM? And what is it not?

Let’s be clear: At CybSafe, we’re not precious about the term human risk management.

This label matters way less than the impact. What matters is the shift in mindset and method.

HRM means managing human risk the same way we manage other risks

HRM applies the same principles:

  • Visibility: Understand which behaviors are risky, who is exhibiting them, and why.
  • Intervention: Guide people at the point of risk with nudges, training, or system changes.
  • Automation: Use technology to apply fixes, reduce workload, and scale efforts.
  • Measurement: Track whether your interventions work, and adjust accordingly.

HRM uses different data, tools, and metrics, focusing on behavior, not just belief.

PART 4 What’s the difference between SAT and HRM?

What’s the difference between SAT and HRM?

SAT is about awareness. HRM is about outcomes. SAT is rooted in training and comms. The goal is to make people aware of risks and policies.

HRM is about managing cyber risk. The goal is to change the behaviors that matter, and prove that change reduces risk. It’s outcome-driven, continuous, personalized, data-led, and automated.

A side-by-side comparison

Security Awareness Training (SAT)

  • Primary goal: Educate and inform
  • Core activity: Training, comms, phishing simulations
  • Driver: Compliance

Human Risk Management (HRM)

  • Primary goal: Change behavior and reduce risk
  • Core activity: Behavior tracking, real-time interventions, automation
  • Driver: Security outcomes and operational impact

PART 5 Why has there been a transition from SAT to HRM?

Why has there been a transition from SAT to HRM?

Security leaders need more than engagement metrics; they need results. The shift from SAT to HRM is driven by:

  • Security leaders wanting stronger evidence of risk reduction.
  • Executive leadership expecting business-aligned outcomes.
  • Regulators tightening expectations.
  • The tech stack now supporting it.

PART 6 What’s with the explosion of HRM companies all of a sudden?

What’s with the explosion of HRM companies all of a sudden?

No doubt there’s something of a rush happening. Many vendors rebranding from phishing simulations or training content to redefine HRM without real change. This creates confusion and highlights the necessity of genuine behavioral insight and measurable impact.

PART 7 The three schools of thought around HRM

The three schools of thought around HRM

Even among security professionals who accept the term human risk management, there’s no single, agreed-upon definition.

  1. A: “HRM is nothing new”

    • Views HRM as simply a new name for what security awareness has always been.
  2. B: “HRM is a modest shift”

    • Sees HRM as a natural extension of security awareness.
  3. C: “HRM is fundamentally different”

    • Argues that HRM is a new discipline that focuses on real-time, tech-enabled interventions.

PART 8 Awareness is an input. HRM is the system.

Awareness is an input. HRM is the system.

Awareness doesn’t automatically lead to behavior change. HRM is a system that connects awareness inputs with behavioral data, automation, and real-time feedback loops to manage risk effectively.

PART 9 Using technology to be more human, not less

Using technology to be more human, not less

Data, automation, and AI enable deeper understanding of behaviors, allowing for more precise interventions that support human connections rather than replace them.

PART 10 As a cybersecurity professional, what are the key takeaways for me?

Security awareness is a tactic—not a strategy. The focus should be on measurable, outcome-driven, data-led behavior change that influences what truly maters.