Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsHuman Risk Management: CISOs’ Solution to the Security Awareness Training Paradox
Human Risk Management: CISOs’ Solution to the Security Awareness Training Paradox
CybersecurityAI

Human Risk Management: CISOs’ Solution to the Security Awareness Training Paradox

•January 30, 2026
0
CSO Online
CSO Online•Jan 30, 2026

Companies Mentioned

Gartner

Gartner

Why It Matters

HRM promises measurable reductions in real‑world incidents, giving CISOs concrete ROI beyond training completion metrics. It aligns security spending with actual human risk, a critical need as adversaries exploit AI‑driven attacks.

Key Takeaways

  • •70‑90% breaches stem from human error or social engineering
  • •Security awareness training spending projected to rise 15% annually
  • •SAT shows limited ROI, often becoming compliance checkbox
  • •Human risk management focuses on behavior, not just knowledge
  • •AI‑driven micro‑learning delivers personalized, continuous security nudges

Pulse Analysis

The security awareness training paradox has long plagued CISOs: massive budgets yield only marginal behavior change. Traditional SAT programs rely on periodic modules that employees rush through, leading to rapid knowledge decay and a false sense of security. As regulatory mandates drive spending, organizations risk mistaking compliance for resilience, especially when sophisticated AI‑generated phishing attacks outpace static curricula.

Human risk management reframes the problem by treating employee actions as data points. By embedding analytics into email gateways, web filters, and identity platforms, HRM continuously scores user risk, enabling targeted micro‑learning, real‑time simulations, and automated policy enforcement. This behavior‑centric approach not only identifies repeat offenders but also quantifies the impact of interventions, giving security leaders a clear line of sight from training to incident reduction.

Artificial intelligence amplifies HRM’s effectiveness through personalized nudges and adaptive content. AI tutors assess individual learning preferences—text, video, or interactive simulations—and deliver bite‑sized lessons precisely when a risky action occurs. Gamified challenges and competitive leaderboards further embed good cyber hygiene into daily routines. For enterprises, this translates into measurable ROI: fewer phishing clicks, lower breach costs, and compliance evidence that reflects true security posture rather than mere course completion rates.

Human risk management: CISOs’ solution to the security awareness training paradox

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...