Your annual phishing test isn’t the problem. It’s not knowing who’s actually at risk.

For twenty years, cyber security for most businesses has meant one thing – annual training. Like a fire drill, everyone sits through the same module, ticks the box, and goes back to their desk having learned almost nothing that will stick. It fights last year’s scams, not this year’s, and the only thing it actually measures is who clicked “complete”. Compliance met, but nobody’s any safer.

That approach is finally being replaced by something more honest.

From training everyone, to knowing who actually needs watching

Human Risk Management starts from a different question – “who in this business is actually a risk, right now, and why?” It treats behaviour as something you watch continuously from who clicks what, who has access to what, and what threats are circulating, rather than something you test once a year.
The pattern that emerges is almost always smaller than you’d expect. It’s rarely more than one in ten people who account for the overwhelming majority of the risk – usually the ones combining broad access with the wrong habits under pressure. You don’t need to watch everyone equally. You need to know which handful of people and situations actually matter.

The next shift – from managing risk to seeing it coming

If HRM is knowing where the frayed wiring is, the emerging next stage is Human Risk Intelligence which is trying to spot the next spark before it lands. The aim is to move from “detect and respond” to “predict and prevent.”

There’s a bigger shift buried in this than the name suggests, though. The definition of “human risk” is expanding. It used to mean what a person does wrong. Increasingly, it means what a person authorises an AI assistant to do on their behalf, and whether that judgment was sound. Your exposure isn’t just what your staff click anymore. It’s what they’ve delegated to tools acting on their credentials, often faster than anyone could double-check.

The fire isn’t just the one someone lights by accident. It’s the one their AI assistant starts while trying to help.

What this means if you’re not running a security team
Most of what’s written on this is aimed at enterprises with dedicated security staff and six-figure budgets. That’s not you, and it’s not most businesses reading this. You don’t need a 200-signal platform to benefit from the thinking. You need the same shift in mindset, scaled down.
Three things to do this week

Retire the “one and done” training mindset. Completion isn’t protection. Treat it as a starting point, not a finish line.

Name your “handful”, on paper. Who has access to money, sensitive data, or client systems? Write their names down. That short list deserves a direct conversation, not a generic module.

Ask the AI question out loud, in a staff meeting. Who’s using AI tools on the business’s behalf, and what have you actually authorised them to do unsupervised? If nobody in the room can answer that clearly, you’ve just found your highest-risk item.

The annual fire drill was never going to save the building. But knowing where the wiring is frayed and who’s now got a robot helping with the electrics just might!