Most security breaches don’t start with malware. They start with a person.
In 2023, MGM Resorts suffered a breach that disrupted systems and cost millions — all triggered by a single successful vishing attack. Around the same time, Coinbase revealed that a social engineering scam tricked an employee into giving up credentials, even though the company had robust technical defenses. Earlier this year, Marks & Spencer joined the list, as compromised credentials led to leaked customer data.
In each of these cases, the root cause wasn’t an unpatched server or misconfigured firewall. It was human behavior — exploited at just the right moment.
These stories are not outliers. They’re signals. They tell us that human risk is not just part of the problem — it’s central to it.
And for security leaders like Jordan, that realization marked a turning point.
From Awareness to Action: Jordan’s First Step
Jordan, the Head of Information Security at a global manufacturing firm, had run a solid SAT program for years. Employees completed annual training. Phishing simulations ran quarterly. Reports looked good on paper.
But deep down, Jordan knew the program wasn’t keeping up with the pace of change.
As his company embraced hybrid work and expanded its third-party ecosystem, the complexity of managing human risk ballooned. Employees weren’t just clicking on phishing links — they were forwarding sensitive files, using shadow IT, and bypassing MFA prompts. And there was no easy way to quantify those behaviors, let alone address them in real time.
Jordan didn’t want to start over. He wanted to evolve. That’s when he began building a Human Risk Management Plan.
Step 1: Foundation
Strengthening Awareness and Establishing Baselines
Jordan started where most programs begin: training. But this time, he didn’t treat it as a box-checking exercise.
Instead, he focused on establishing behavioral baselines. He deployed phishing simulations tied to real campaigns, added quiz-based engagement metrics to measure comprehension, and segmented results by department.
The goal wasn’t perfection. It was clarity — understanding where the organization stood.
Step 2: Visibility
Integrating Risk Signals from the Tech Stack
Once Jordan had a baseline, he wanted more than awareness data. He needed to know what people were actually doing.
He began integrating signals from his email security platform and DLP system. This gave him visibility into behaviors that SAT couldn’t catch — like repeated data sharing violations or click patterns during phishing simulations.
Soon, he had a heatmap of behavioral risk across departments — not based on assumptions, but grounded in real-world activity.
[Free Download] Start Building Your Human Risk Management Plan
Get a practical, 5-step framework to evolve your SAT program into a measurable, behavior-based HRM strategy. Whether you’re just getting started or ready to scale, this guide helps you move forward — one step at a time.

Step 3: Precision
Delivering Targeted, Role-Specific Training
With real signals in hand, Jordan moved away from generic training blasts.
He created targeted microtrainings based on job function and behavior. Developers received short nudges about secure code practices. Finance staff got simulated invoice scams. Executives received 90-second videos on social engineering tactics tied to their travel schedules.
This wasn’t awareness for awareness’s sake. It was behavior-specific coaching — timed and delivered to make an impact.
Step 4: Reinforcement
Real-Time Nudges, Delivered Where Work Happens
Jordan knew training wasn’t enough. People forget. Habits slip.
So he enabled nudges — brief, contextual messages — delivered through Slack and Teams whenever risky behaviors occurred. These real-time interventions turned teachable moments into action.
One employee who shared a sensitive document externally without encryption received a friendly reminder minutes later — with a quick tip on secure sharing settings.
Step 5: Intelligence
Measuring Progress and Guiding Investment
As his program matured, Jordan moved from dashboards that tracked completion rates to ones that showed risk reduction.
He could now show the board how departments were improving over time, where the top behavioral risks were emerging, and how specific interventions had reduced incidents.
He didn’t just have reports. He had insight.
Scaling the Strategy: What Jordan Learned
HRM isn’t all-or-nothing. It’s a path — one that starts with foundational SAT and grows as your organization becomes more complex.
Jordan didn’t rip and replace. He built layer by layer.
Eventually, he needed to find a platform that could support that strategy. It had to integrate with his existing stack, support real-time training delivery, and give him the analytics to prove value.
If you’re wondering what to look for, we’ve outlined key criteria for choosing the right HRM platform.
Final Thoughts: You Don’t Need to Start Over. You Just Need a Plan.
The most effective human risk programs don’t abandon SAT — they elevate it. They begin with what you already have and build toward visibility, precision, and intelligence.
That’s the heart of a Human Risk Management Plan: structured evolution, not disruption.
If you’re just beginning this journey — or wondering how to take your program further — you’re not alone. We’ve helped organizations across industries build programs that are practical, measurable, and built to scale.
✅ Start Building Your Human Risk Management Plan
Get a practical, 5-step framework to evolve your SAT program into a measurable, behavior-based HRM strategy. Whether you’re just getting started or ready to scale, this guide helps you move forward — one step at a time.



