How well does your organisation manage human risk?
Most organisations think they have human risk covered. 5 questions to find out if yours actually does, and where to focus if not.
Your results
Your rating: /5
Human risk is largely invisible, and that’s the biggest risk of all.
Right now, your organisation is likely relying on assumptions and technical controls to manage human risk. There’s limited visibility into how people actually behave, and no clear signal before incidents occur. The good news? Organisations at this stage often see fast, meaningful improvement once they establish even basic structure around awareness, reporting, and measurement.
What’s working
- Technical controls provide a floor of protection
- Compliance foundations are likely in place
Where to focus next
- Create a baseline for measuring people’s security behaviour
Awareness exists, but it’s fragile under real pressure.
Your organisation has the basics in place: training happens, some reporting exists, and people broadly know they should be secure. But the approach is reactive, largely generic, and tends to break when things get busy. Human risk is partially visible, but not well enough understood to act on confidently. The shift from ‘covered’ to ‘in control’ comes from moving beyond annual touchpoints and starting to understand behaviour, not just activity.
What’s working
- Awareness infrastructure is in place
- People have basic knowledge of security expectations
Where to focus next
- Improve ease and confidence in threat reporting
You’re ahead of most, but consistency is the next challenge.
Your organisation actively manages human risk: training runs regularly, simulations are in place, and you have real data on how people are performing. That’s a genuine advantage. The challenge now is that good outcomes still require sustained manual effort to maintain, and secure behaviour can degrade under pressure or during transitions. The next step is reducing that reliance on manual follow-up, and starting to use your data more intelligently to anticipate risk before it surfaces.
What’s working
- Regular, tracked training and simulation programmes
- Reporting mechanisms exist and are used
Where to focus next
- Focus interventions on highest-risk groups and moments
Human security is embedded, now it’s about scaling it intelligently.
Your organisation is operating at a level most haven’t reached: security behaviour is normalised, signals are used to guide action, and the programme adapts as threats and behaviour evolve. Human risk is visible, understood, and actively managed. The focus now is on scaling this consistency, prioritising where to invest attention, reducing any remaining friction, and connecting your human risk picture to the outcomes that matter most to leadership.
What’s working
- Secure habits are consistent, even under pressure
- Programme adapts to evolving threats and contexts
Where to focus next
- Scale consistency across all teams and regions








