Human risk management (HRM)
Human risk management is the discipline that measures and reduces the risk born in people's behavior, using data instead of annual courses.
Full definition
Human risk management (HRM) is the discipline that continuously identifies, measures and reduces the cybersecurity risk that originates in people's behavior. It starts from a measured fact: the human factor is involved in about 90 percent of breaches (Cisco, 90-5-5 framework), so it is managed with data, just like infrastructure.
It differs from traditional awareness in its unit of measurement: it does not count completed courses but observed behavior under real pressure, through attack simulations, monitoring of exposed credentials and validation by retest. The result is a risk profile per person and per team that changes with behavior.
That risk profile is dynamic, not a snapshot: it updates with every simulation passed or failed, with every exposed credential that appears and with every retest. A person who fell in March and proved in April that their behavior changed does not carry the same risk all year, and one who fell again does not lower it by finishing a course. A score calculated once describes the past; a profile recalculated from behavior describes present risk, which is the one that gets managed.
A human risk management platform typically integrates four capabilities in a cycle: monitoring of leaked credentials, personalized phishing simulations, immediate microlearning after each failure, and a retest that verifies the change in behavior. The value lies in each capability feeding the others, not in standalone modules.
Related terms
Human factor
The human dimension of cybersecurity risk: the decisions and habits of people that an attacker can exploit. It is not a synonym for blame.
Retest
A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.
Human risk score
An indicator that summarizes the security risk of a person or team based on observed behavior: simulations, exposed credentials, retests.
Security awareness
Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.