What human risk management is
Human Risk Management (HRM) is the discipline that measures, tests, and reduces the probability of a person in your organization falling for a social engineering attack. The difference with traditional awareness lies in what gets measured: an awareness program measures completed courses; an HRM program measures real behavior under simulated attack, person by person and continuously.
The starting point is not blaming anyone. People are the target of the attack, not the weakest link: the job of an HRM program is to turn the human factor into the first line of defense, with honest measurement instead of attendance certificates. The short definition lives in our glossary; this page is the full guide to the category.
Why the human factor concentrates most breaches
The human factor is involved in about 90 percent of breaches; 5 percent is explained by lack of tools and the other 5 percent by resource limitations (Cisco, the 90-5-5 framework). The operational conclusion is uncomfortable: most security investment protects the layers where the minority of the problem happens.
The entry channel is also measured: more than 90 percent of successful cyberattacks start with a phishing email (CISA). And the instrument most companies answer that fact with, the annual awareness course, does not measure whether someone stopped falling: it measures whether they finished the course. The full human risk numbers are on the blog, with their primary sources.
The four engines in a closed cycle
A complete HRM program operates as a cycle where each function's output feeds the next: detect, test, train, and validate. The value is in the cycle, not in loose modules: a simulation without immediate training is a pop quiz, and training without a retest is a certificate without evidence.
Continuous monitoring
The program monitors public breach databases and the dark web to detect employee credentials already exposed, and triggers the response in hours, not months. It is the function that delivers value from day one, without waiting for behavioral data.
Adversarial testing
Phishing simulations personalized by role, past behavior, and the company's real tools reveal each person's concrete vulnerability, to which kind of lure, and how often.
Training at the moment of error
Whoever falls for a simulation receives, within minutes, a micro-lesson specific to the exact deception they fell for. The moment right after the mistake is when a person is most receptive; an annual course cannot compete with that.
Validation retest
Weeks later, a new simulation of the same category but with a different template verifies that the person changed their behavior, not that they memorized one email. The retest is what separates a program that certifies courses from one that proves defense.
The emphasis on the retest is not a product preference: peer-reviewed evidence shows that completing training does not by itself predict fewer real failures (Lain et al., IEEE S&P 2022; Ho et al., IEEE S&P 2025). What proves behavior change is testing the behavior again. That is how Fensivo operates, and how any serious platform in the category should: here is the full cycle in our platform.
How risk is measured per person
HRM's unit of measure is the human risk score: a per-person indicator built from real behavior in simulations, credentials exposed in breaches, and role exposure. Aggregated by team and over time, it gives leadership a comparable risk curve, not a list of completed courses.
Two honest-measurement warnings. First: the click rate alone is misleading, because it drops when simulations get easy; the early signal of a working culture is the report rate. Second: individual scoring needs statistical mass, and below roughly 25 people it should be read by group or not at all.
How to get started
The order that works is measure before training: first credential monitoring and a simulation baseline, and with that real picture, the program. The phased plan is in how to build a human risk program in 90 days, and if you need to justify the investment, the business case for the board brings the arguments with their sources.
If you are evaluating platforms: real price ranges are in how much an HRM platform costs, the ten questions worth asking any vendor quickly separate marketing from evidence, and our honest comparison puts Fensivo next to the market reference, criterion by criterion. The pricing calculator shows the exact investment in seconds.
Measure your human risk with real data
A 30-minute demo with simulated data from your industry. Live in 1 day via OAuth; first executive report within 48 hours.
Go deeper
The full human risk management cluster, ordered by what you need to solve.