Human risk management: how organisations turn evidence into action

Learn what human risk management means, how it helps organisations and where CyberSense learning insights fit. A practical guide with examples and an exercise.

CyberPlay editorial team · Published · Updated · 7 min read

Guide and exercises in English

CyberPlay organisation learning overview with a 73.4 average, 83% measured coverage and coaching priorities, using fictional data.

Expand image · Platform screenshot · Example data · English interface

Read coverage and unmeasured members alongside the learning score. Actual CyberPlay interface with fictional example data, not customer results.

Human risk management is the ongoing work of understanding how people, work processes and security controls interact, then choosing improvements supported by evidence. In cybersecurity, it connects education with organisational decisions: which team needs support, which procedure creates avoidable pressure and whether the response helped. A training completion count can contribute, but cannot answer all of those questions.

This English guide explains the approach for security leaders, HR partners and department managers. CyberPlay’s platform interface and organisation learning insights are available in English. We use CyberSense as a concrete example of learning evidence while keeping technical exposure, employee attitudes and real incidents separate.

What you’ll take away

  • Start with a business decision, then choose the evidence needed to make it.
  • Read coverage and missing data alongside every aggregate score.
  • Use learning profiles to offer support, not to predict who will cause a breach.
  • Give every improvement an owner, a follow-up date and a clear test.

1. What does human risk management mean?

Imagine an accounts team handling an urgent supplier bank-detail change. The outcome depends on more than whether a colleague recognises phishing. Can they reach a known supplier contact? Does the payment system require approval? Will a manager accept a short delay? Human risk management examines the decision within those working conditions.

NIST SP 800-50 Rev. 1 recommends a learning lifecycle with evaluation. For your organisation, that means treating the next lesson as one possible response within an owned improvement process. Sometimes the useful action is practice; sometimes it is a clearer contact route, a corrected permission or a changed deadline.

Section sources: Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1)

2. Start with one business decision

Replace “make employees more aware” with a decision someone can observe: “Before changing supplier bank details, use the approved independent verification route.” Define who faces the situation, what safe action looks like and which obstacle currently makes that action difficult. This makes the programme useful to the finance manager as well as the security team.

The intended organisational benefit is better use of limited support time. Instead of sending another generic lesson to everyone, you can assign a relevant exercise to the affected group and ask the process owner to remove an obstacle. A purchased platform may help coordinate that work; it does not take ownership of the payment process.

3. Separate the kinds of evidence you collect

A learning result, a suspicious email report and an identity alert describe different events. They can inform the same discussion without becoming interchangeable measurements. Record the source, period, population and known gaps before drawing a conclusion. A high score with poor coverage may describe only the few people already engaged.

Hoxhunt describes combining security signals with targeted interventions. That vendor example illustrates why buyers should ask what feeds a dashboard. The following table is an editorial decision aid, not a claim that CyberPlay collects every listed signal. Choose only the sources your organisation is authorised and able to use.

3. Separate the kinds of evidence you collect
EvidenceUseful questionInterpretation boundary
Learning resultsWhich decisions need practice or explanation?Game evidence does not establish real-world resistance.
Coverage and participationWho has had a measured opportunity to learn?No score means unknown, not zero ability.
Approved incident reportsWhere does work create recurring difficulty?Report counts depend on exposure and reporting habits.
Authorised technical signalsDo access or system settings need an owner?These are separate sources, not CyberSense inputs.

Section sources: Human Risk Management

4. Where CyberSense fits

CyberSense summarises first-party game performance and progression evidence. The organisation view helps authorised users examine measured coverage, departments and priorities for coaching, baseline practice or refreshers. Its aggregate uses measured active members; a member with no measured score remains unknown rather than becoming a fabricated zero.

Use that view to ask who has an opportunity to practise and which learning discussion should come next. CyberSense is not a breach probability, an independent competency assessment or a feed of external threat and identity telemetry. The current learning insights explicitly leave threat, access and attitude signals unavailable. Analytics access depends on the organisation’s entitlement and the viewer’s permissions.

Fictional CyberPlay learning profile for Mara, with phishing, identity and data results and two unmeasured domains.

Expand image · Platform screenshot · Example data · English interface

  1. Focused support

    The phishing domain is 42/100 in this example. Explore the decision that needs explanation or practice.

  2. Unknown stays unknown

    Incident reporting and device security have no measured evidence. They are gaps to address, not zero ability.

Choose a specific learning conversation from the domain evidence. This fictional profile does not predict a real person’s behaviour.

5. Read department differences in context

Suppose one department has broad practice coverage and another has only a few measured participants. Comparing their averages alone rewards the team whose missing evidence is easiest to overlook. Check participation, role mix and recent opportunities to practise before deciding that one department needs more support. Missing evidence is a planning question, not a character judgement.

In a fictional manufacturing business, shift workers may need scheduled access to a shared device while office staff can practise at their desks. The initial action could be protected learning time, accessible instructions or an appropriate language setting. Discuss these conditions with the local manager rather than assuming that another reminder will solve the problem.

CyberPlay department table with Finance, Operations and People, using fictional learning scores and coverage.

Expand image · Platform screenshot · Example data · English interface

  1. Measured average

    Finance’s 69.7 average describes its measured active members. It is not a probability of an incident.

  2. Coverage matters

    75% means six of eight members have a score. The two remaining members are still unknown.

Compare coverage before comparing averages. The example Finance row has six measured members out of eight; these are fictional platform data, separate from the exercise below.

6. Build a loop from signal to support

NCSC recommends safe reporting routes and a culture where people can speak openly. In practice, begin the conversation with what the evidence shows and invite the colleague to explain the situation. “You have not yet had measured practice” is a different statement from “you are unsafe.” The first leads to a useful question about access, time or confidence.

Choose a small response that fits the cause. A misunderstood verification step can lead to a short scenario and a debrief. A broken reporting button needs an owner in IT. After the agreed interval, review both the learning evidence and whether the workplace obstacle was removed. Record an unresolved issue honestly instead of declaring success because the activity was completed.

Four linked stages: signal, interpretation, support and review. Each cycle retains missing information and an action owner.

Expand image

Original CyberPlay explanatory diagram. An editorial framework, not a predictive risk model.

Section sources: Cyber security culture principles: Principle 2

7. Give people a fair explanation of the programme

Tell participants what information is collected, what the score represents, who can see it and how it will be used. Keep named learning profiles with authorised people who need them for support. A management discussion may need a team summary rather than a public list of individual scores. Confirm organisational privacy and employment requirements with the appropriate owner.

Do not turn a learning band into a claim about dishonesty, employability or future incidents. Invite correction when membership, department or access information is wrong. Managers should also accept responsibility for unrealistic workflows. A programme loses value if people spend their effort managing appearances instead of explaining the difficulty that prevented a safer decision.

8. Practise the management decision

Discuss the fictional case below with a security lead and a department manager. Ask each person to distinguish an observation, an interpretation and an action. Write the chosen action before looking at the debrief. No customer information or live employee record is needed for this exercise.

9. Run a small, reviewable first cycle

Choose one team and one decision for the first cycle. Agree the intended behaviour, the available evidence and the boundaries of the interpretation. Check access and language, give people time to practise, then hold a short review with the process owner. Keep the original question visible so the discussion does not drift into whichever number increased most.

Finish with a record that someone can act on: what was observed, what remains unknown, which support was provided, who owns the remaining issue and when it will be checked again. CyberPlay’s organisation learning insights can support that conversation in English. The programme earns its value through the decisions and follow-up it enables, not through an impressive label on a dashboard.

Explore organisation learning insights in English

See how CyberPlay connects game practice, CyberSense and department learning views. Organisation analytics require an eligible plan and appropriate permissions.

Explore CyberPlay for organisations

Sources and further reading

  1. Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1) — NIST. Accessed 2026-09-13
  2. Cyber security culture principles: Principle 2 — UK National Cyber Security Centre. Accessed 2026-09-13
  3. Human Risk Management — Hoxhunt. Accessed 2026-09-13

Keep exploring

All articles

Contact · About