“Human risk management” turned up as a label in nearly every conversation about security and people over the past two years. The term gets used freely, and often to describe exactly what used to be called awareness. The new name on its own doesn’t change much. What changes is whether the program behaves like risk management or like an annual course with an attendance sheet.
The distinction is worth drawing, because it determines which tools you need and what you’ll be able to show when somebody asks how your organization is doing.
What is human risk management?
Human risk management is the practice of continuously measuring, reducing and demonstrating the risk that people introduce into an organization’s security. All three have to be there, and continuously. A program that only trains doesn’t measure. One that only simulates doesn’t reduce. And one that leaves no record demonstrates nothing to an auditor.
Treating it as risk has a practical consequence. Risk gets measured on a scale, compared with itself over time and assigned an action. It doesn’t get completed. We wrote earlier about what human risk actually is and where it starts.
Why does a single tool fall short?
Because each piece answers one question well and none of them answers the next one.
A simulation tool tells you who clicked. It doesn’t tell you what to give that person afterwards, or whether they learned anything. A training platform delivers content and records the progress, but has no way of knowing who is genuinely exposed. A reporting dashboard shows numbers that nobody can act on from there.
The problem doesn’t show up inside each tool. It shows up in the space between them, and that space ends up being covered by somebody on the security team with exports, spreadsheets and manual cross-checks.
There’s a very concrete case. If simulations and metrics live apart, the gateways and sandboxes that “open” messages automatically pollute the statistics and nobody notices. It is why the platform includes detection and filtering of false positives.
What was SMARTFENSE when it started?
It was considerably less than it is today, and it already had the same core.
The first public version, in 2017, shipped phishing and ransomware simulations, interactive modules and newsletters with read validation. That same year brought automatic user synchronization with Microsoft Azure AD and Google, so the platform never worked as an island with its own manually loaded list of people. In 2018 came exams and Educational Moments, which reinforce at the exact instant somebody interacts with a simulation, along with the first groups built from behavior towards campaigns.
That last point is the one that counts most in hindsight. The idea of segmenting by conduct rather than by department was there from year two, and it is the direct precursor of today’s Smart Groups. The decision to integrate with the organization’s systems instead of installing software on every device also dates from that period, and we explain it in why we integrate via API and not with an agent.
Which layers were added since then?
Each layer came out of a concrete limit in the previous program, not from a roadmap written all at once.
- Metrics you can trust (2020). Detection of the automatic interactions from gateways and sandboxes, so they would stop contaminating the statistics. That same year, user anonymization and credential-free authentication, aligned with GDPR requirements.
- Engagement and risk measurement (2021). Native gamification with badges, educational videogames and leaderboards. And Risk Scoring, the platform’s first algorithm that translates the behavior of a person and of an organization into a comparable measure of exposure.
- Direct delivery and new vectors (2022-2023). Direct Message Injection for Google Workspace and Microsoft 365, which places simulations in the mailbox via API without asking anyone to configure allowlists. Alongside that, QR codes, USB drives and SMS joined phishing and ransomware as simulable vectors.
- Behavior and applied intelligence (2024-2026). Automatic interventions that fire when a risk event occurs, nudges that reinforce conduct at the right moment, a phishing report button inside Outlook, Gmail and Thunderbird, and learning paths that adjust to each person’s risk. We wrote about that layer in cybersecurity nudges at the right moment.
Why does it matter that everything lives on the same platform?
Because the value is in the cross-referencing, and that only exists if the data shares one place.
When simulation, training and measurement run on the same base, the result of one feeds the next without anyone exporting anything. Whoever clicked receives the right reinforcement that day. That person’s Risk Scoring moves. The group they belong to recalculates on its own. We develop this in the importance of data correlation in awareness, and it is why we prefer to talk about an ecosystem rather than a set of modules.
That ecosystem also looks outward. The human behavior signal travels to the tools where the security team already works, something we addressed in the human risk score as a signal for your SIEM, and in the other direction each person’s context arrives from the identity provider, the collaboration tools and the compliance platforms through the available integrations.
SMARTFENSE has four platform generations built on that idea, with version 4.37 released on 1 August 2026 and the CCN qualification for handling sensitive information under Spain’s ENS. None of that is a decision made this year.
The short answer
What does human risk management mean? Measuring the exposure that people introduce, reducing it with concrete actions and being able to demonstrate both, continuously and without anyone having to join the pieces by hand.
A single tool covers one stretch of that. The rest stays on the security team’s side, as manual work that doesn’t scale. If you want to see how each layer fits together today, they are all on the platform.
Leave a Reply