We gathered here the questions security leaders at midsize companies in the region ask us most often when they evaluate a [human risk management](/en/gestion-del-riesgo-humano) program. Each answer opens with the conclusion and stands on its own, so it works as a quick reference.
What human risk management is and how it differs from traditional awareness
Human risk management (HRM) is the discipline that measures and reduces the likelihood of a person being deceived during an attack, based on real behavior rather than on what they say they know. The difference from traditional awareness runs deep: awareness aims to have the employee understand what phishing is through talks and courses, while human risk management watches how that person acts when they receive a realistic deception and works on that behavior.
The shift in focus reflects where the risk sits. Cisco's 90-5-5 framework, which estimates that around 90 percent of breaches involve a human factor, places people as the main attack surface (source: Cisco). We say human factor and not human error on purpose: the person is the target of the attack, not the one to blame. Knowing what phishing is does not tell you how someone will behave under pressure, and that gap between knowledge and conduct is exactly what traditional awareness fails to close.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
How often phishing simulations should be sent
A reasonable cadence is monthly for most of the workforce and every two weeks for high-exposure roles, such as finance, leadership, and people with access to critical systems. Sending a single simulation a year does not measure behavior, it measures luck: what we want is a continuous signal, not an annual exam.
The underlying reason is the speed of the risk. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email, so exposure is constant and measurement has to be constant too (source: CISA). Even so, frequency matters less than variation: repeating the same template teaches someone to recognize one specific email, not to resist the technique. That is why it helps to change the pretext, the channel, and the difficulty on each send, and to concentrate every simulation where it truly reveals risk instead of sending the same email to the whole company.
How to know whether an employee really learned after falling for phishing
The only way to know is to test them again: send another simulation of the same type and difficulty weeks later, with a different pretext, and watch whether they resist this time. Completing the course after the failure is not enough as proof, because passing a module is not the same as changing behavior under pressure.
This is not an opinion. Peer-reviewed evidence shows that completing training does not on its own predict a reduction in real failures (studies published at the IEEE Symposium on Security and Privacy). What proves the change is re-observing behavior in an equivalent situation, a practice often called retest: not that the person remembers an email, but that they resist a technique. If you want to understand why training alone does not change conduct, we go deeper in why your security training program is not working.
How many employees you need to measure human risk
You need a minimum sample of around 25 people for the aggregate risk score to be statistically meaningful. Below a couple of dozen employees, individual variation dominates and the score becomes noise: a handful of people who fall or resist move the average too much, and the trends stop being reliable.
The logic is the same as any measurement: the more observations, the more stable the signal. With 25 people or more you can tell a real pattern, such as a more exposed department or a pretext that works, from a coincidence. That is why human risk management fits naturally in companies of 25 to 500 employees, where there is enough mass to measure without the complexity of an organization with tens of thousands.
How AI agent risk differs from human risk
Human risk is the likelihood of a person being deceived; AI agent risk is the likelihood that autonomous software, acting with its own credentials and permissions, executes a harmful action with no human judgment behind it. These are two different surfaces: one exploits psychology, the other exploits the lack of judgment and the broad permissions of a system that operates on its own.
The confusion comes from both ending in the same place, an improper access or transfer, but they are governed differently. We prepare the person to recognize and resist a deception; the agent needs limited permissions, a record of what it does, and validation of its actions before they take effect. Treating an agent as if it were just another employee, or ignoring that it widens the attack surface, is the mistake we are starting to see. We analyze it in detail in AI agent risk and human risk.
At Fensivo we address this use case by closing the full loop: we detect real credential exposure, test each person with simulations matched to their role, deliver training at the moment of the failure, and validate with a retest that the behavior changed, not that the employee remembered an email. That last step, testing again weeks later with a different template of the same type, is what separates measuring behavior from measuring attendance. You can see how we apply it in our use cases.
Does your current program tell you your employees completed the training, or does it prove they would resist the next attack today?
Sources and references
- Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. blogs.cisco.com
- CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov
- Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy. ieeexplore.ieee.org
- Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy. ieeexplore.ieee.org
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
