CyberPlay editorial team · Published · Updated · 7 min read
Guide and exercises in English

Expand image · Platform screenshot · Example data · English interface
Human risk management is the ongoing work of understanding how people, work processes and security controls interact, then choosing improvements supported by evidence. In cybersecurity, it connects education with organisational decisions: which team needs support, which procedure creates avoidable pressure and whether the response helped. A training completion count can contribute, but cannot answer all of those questions.
This English guide explains the approach for security leaders, HR partners and department managers. CyberPlay’s platform interface and organisation learning insights are available in English. We use CyberSense as a concrete example of learning evidence while keeping technical exposure, employee attitudes and real incidents separate.
What you’ll take away
- Start with a business decision, then choose the evidence needed to make it.
- Read coverage and missing data alongside every aggregate score.
- Use learning profiles to offer support, not to predict who will cause a breach.
- Give every improvement an owner, a follow-up date and a clear test.
1. What does human risk management mean?
Imagine an accounts team handling an urgent supplier bank-detail change. The outcome depends on more than whether a colleague recognises phishing. Can they reach a known supplier contact? Does the payment system require approval? Will a manager accept a short delay? Human risk management examines the decision within those working conditions.
NIST SP 800-50 Rev. 1 recommends a learning lifecycle with evaluation. For your organisation, that means treating the next lesson as one possible response within an owned improvement process. Sometimes the useful action is practice; sometimes it is a clearer contact route, a corrected permission or a changed deadline.
Section sources: Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1)
2. Start with one business decision
Replace “make employees more aware” with a decision someone can observe: “Before changing supplier bank details, use the approved independent verification route.” Define who faces the situation, what safe action looks like and which obstacle currently makes that action difficult. This makes the programme useful to the finance manager as well as the security team.
The intended organisational benefit is better use of limited support time. Instead of sending another generic lesson to everyone, you can assign a relevant exercise to the affected group and ask the process owner to remove an obstacle. A purchased platform may help coordinate that work; it does not take ownership of the payment process.
3. Separate the kinds of evidence you collect
A learning result, a suspicious email report and an identity alert describe different events. They can inform the same discussion without becoming interchangeable measurements. Record the source, period, population and known gaps before drawing a conclusion. A high score with poor coverage may describe only the few people already engaged.
Hoxhunt describes combining security signals with targeted interventions. That vendor example illustrates why buyers should ask what feeds a dashboard. The following table is an editorial decision aid, not a claim that CyberPlay collects every listed signal. Choose only the sources your organisation is authorised and able to use.
| Evidence | Useful question | Interpretation boundary |
|---|---|---|
| Learning results | Which decisions need practice or explanation? | Game evidence does not establish real-world resistance. |
| Coverage and participation | Who has had a measured opportunity to learn? | No score means unknown, not zero ability. |
| Approved incident reports | Where does work create recurring difficulty? | Report counts depend on exposure and reporting habits. |
| Authorised technical signals | Do access or system settings need an owner? | These are separate sources, not CyberSense inputs. |
Section sources: Human Risk Management
4. Where CyberSense fits
CyberSense summarises first-party game performance and progression evidence. The organisation view helps authorised users examine measured coverage, departments and priorities for coaching, baseline practice or refreshers. Its aggregate uses measured active members; a member with no measured score remains unknown rather than becoming a fabricated zero.
Use that view to ask who has an opportunity to practise and which learning discussion should come next. CyberSense is not a breach probability, an independent competency assessment or a feed of external threat and identity telemetry. The current learning insights explicitly leave threat, access and attitude signals unavailable. Analytics access depends on the organisation’s entitlement and the viewer’s permissions.

Expand image · Platform screenshot · Example data · English interface
- Focused support
The phishing domain is 42/100 in this example. Explore the decision that needs explanation or practice.
- Unknown stays unknown
Incident reporting and device security have no measured evidence. They are gaps to address, not zero ability.
5. Read department differences in context
Suppose one department has broad practice coverage and another has only a few measured participants. Comparing their averages alone rewards the team whose missing evidence is easiest to overlook. Check participation, role mix and recent opportunities to practise before deciding that one department needs more support. Missing evidence is a planning question, not a character judgement.
In a fictional manufacturing business, shift workers may need scheduled access to a shared device while office staff can practise at their desks. The initial action could be protected learning time, accessible instructions or an appropriate language setting. Discuss these conditions with the local manager rather than assuming that another reminder will solve the problem.

Expand image · Platform screenshot · Example data · English interface
- Measured average
Finance’s 69.7 average describes its measured active members. It is not a probability of an incident.
- Coverage matters
75% means six of eight members have a score. The two remaining members are still unknown.
6. Build a loop from signal to support
NCSC recommends safe reporting routes and a culture where people can speak openly. In practice, begin the conversation with what the evidence shows and invite the colleague to explain the situation. “You have not yet had measured practice” is a different statement from “you are unsafe.” The first leads to a useful question about access, time or confidence.
Choose a small response that fits the cause. A misunderstood verification step can lead to a short scenario and a debrief. A broken reporting button needs an owner in IT. After the agreed interval, review both the learning evidence and whether the workplace obstacle was removed. Record an unresolved issue honestly instead of declaring success because the activity was completed.
Section sources: Cyber security culture principles: Principle 2
7. Give people a fair explanation of the programme
Tell participants what information is collected, what the score represents, who can see it and how it will be used. Keep named learning profiles with authorised people who need them for support. A management discussion may need a team summary rather than a public list of individual scores. Confirm organisational privacy and employment requirements with the appropriate owner.
Do not turn a learning band into a claim about dishonesty, employability or future incidents. Invite correction when membership, department or access information is wrong. Managers should also accept responsibility for unrealistic workflows. A programme loses value if people spend their effort managing appearances instead of explaining the difficulty that prevented a safer decision.
8. Practise the management decision
Discuss the fictional case below with a security lead and a department manager. Ask each person to distinguish an observation, an interpretation and an action. Write the chosen action before looking at the debrief. No customer information or live employee record is needed for this exercise.
9. Run a small, reviewable first cycle
Choose one team and one decision for the first cycle. Agree the intended behaviour, the available evidence and the boundaries of the interpretation. Check access and language, give people time to practise, then hold a short review with the process owner. Keep the original question visible so the discussion does not drift into whichever number increased most.
Finish with a record that someone can act on: what was observed, what remains unknown, which support was provided, who owns the remaining issue and when it will be checked again. CyberPlay’s organisation learning insights can support that conversation in English. The programme earns its value through the decisions and follow-up it enables, not through an impressive label on a dashboard.
Explore organisation learning insights in English
See how CyberPlay connects game practice, CyberSense and department learning views. Organisation analytics require an eligible plan and appropriate permissions.
Explore CyberPlay for organisationsSources and further reading
- Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1) — NIST. Accessed 2026-09-13
- Cyber security culture principles: Principle 2 — UK National Cyber Security Centre. Accessed 2026-09-13
- Human Risk Management — Hoxhunt. Accessed 2026-09-13
Keep exploring
- Human risk management platforms: what should your organisation compare?
Compare Hoxhunt, KnowBe4, SoSafe, usecure and CyberPlay with an educational HRM buying checklist. Examine signals, coaching, language support and evidence in a demo.
EN · 8 min read - Human risk management metrics: turn CyberSense into a coaching plan
Read coverage, CyberSense and learning priorities by department. Use a worked example to choose employee coaching, assign practice and review the evidence.
EN · 7 min read - Security awareness training metrics: measure more than completion
Measure security awareness with a practical metric dictionary covering participation, decisions, retention and reporting, plus fair comparisons and clear limits.
EN · 8 min read - Security awareness training plan: a 12-month calendar with practical activities
Use an editable 12-month security awareness training calendar with decision objectives, role-based activities, debrief questions, owners and useful review measures.
EN · 8 min read - Security awareness training for employees: how to choose a programme
Choose security awareness training for employees with practical scenarios, accessible delivery and a clear pilot that checks learning, reporting and programme fit.
EN · 9 min read - Security awareness activities for employees: 12 practical exercises with debriefs
Run 12 practical security awareness activities with clear objectives, suggested timings, equipment, accessible alternatives and useful workplace debriefs.
EN · 10 min read