Back to the glossary
    Human risk & behaviorCybersecurity glossary

    Human risk management (HRM)

    The discipline that measures and reduces the security risk originating in people's behavior, using continuous data instead of annual courses.

    Full definition

    Human risk management (HRM) is the discipline that continuously identifies, measures and reduces the cybersecurity risk that originates in people's behavior. It treats the human factor as an attack surface to be managed with data, just like infrastructure.

    It differs from traditional awareness in its unit of measurement: it does not count completed courses but observed behavior under real pressure, through attack simulations, monitoring of exposed credentials and validation by retest. The result is a risk profile per person and per team that changes with behavior.

    A human risk management platform typically integrates four capabilities in a cycle: monitoring of leaked credentials, personalized phishing simulations, immediate microlearning after each failure, and a retest that verifies the change in behavior. The value lies in each capability feeding the others, not in standalone modules.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.