Forrester's definition of this category contains a phrase that does more work than it appears to. These solutions identify risks posed by and to humans.
Both directions. An employee is a potential source of risk, through a clicked link, a misdirected file, a reused password, or in rare cases deliberate action. An employee is also a target, of phishing, social engineering, credential theft, and increasingly of synthetic media impersonating colleagues.
Holding both at once is what distinguishes this category from what it replaced, and it is also the source of its central difficulty. A programme that treats people primarily as a risk to be scored behaves very differently from one that treats them as a population to be protected, and the same software supports both.
What it replaced, and why
Security awareness and training was the predecessor, and Forrester stated in early 2024 that human risk management is its next evolution.
The failure of the older model is well documented and mostly structural. Training was mandated annually, delivered as modules, and measured by completion. The metrics were attendance and engagement, which are measures of whether people sat through something rather than of whether anything changed.
That made it a compliance exercise. An organisation could demonstrate to an auditor that everyone completed the training, while the actual behaviour that produces incidents remained entirely unmeasured. Simulated phishing added a behavioural metric, and quickly became its own ritual: run the campaign, report the click rate, retrain the clickers, repeat.
The critique that produced this category is that none of it was connected to real risk. The training was uniform regardless of who someone was or what they had access to, and the results were disconnected from anything the security operations function could act on.
Forrester's framing of what HRM does instead is that it detects human security behaviours, identifies the risks posed by and to people, and adapts policies, training, and technologies accordingly. The operative verb is adapt. The proposition is that the intervention should differ by person.
Inside The Forrester Wave: Human Risk Management Solutions, Q3 2024
Forrester published a Landscape mapping fifteen vendors in Q1 2024 and followed it with the first Wave evaluation of the market in Q3 2024.
Living Security placed as a Leader, on a platform that integrates with existing security tooling and measures a large number of discrete user behaviours and events across security product categories, producing an individual view of risk that triggers targeted action or training.
CybSafe placed as one of two Leaders, positioned by Forrester for organisations serious about security culture and about behavioural change driven by data rather than by campaign schedules.
Mimecast placed as a Strong Performer, credited for plans to extend human risk scoring across a large installed base and to ingest risk signals from third-party security products. Forrester noted its framing of human risk as the composition of three things: actions, meaning behaviour; attacks, meaning what is being aimed at the person; and access, meaning identity and entitlement. Forrester positioned it for organisations with a strong drive toward behavioural change that want to move past traditional awareness training.
That three-part composition is the clearest articulation of why the category exists. A person who clicks carelessly but has access to nothing is a smaller problem than a careful person with administrative rights who is being actively targeted. Behaviour alone does not describe risk. Behaviour, exposure, and privilege together do.
The scoring problem
Individual risk scoring is the mechanism that makes HRM work, and it is the part that requires the most careful handling.
A platform assigning each employee a risk score, derived from their behaviour across email, browsing, data handling, and authentication, is producing a per-person behavioural assessment held by the security function. That is a legitimate security capability and it is also, described in different vocabulary, workplace monitoring.
Three consequences follow.
The governance conversation is not with IT. In several European jurisdictions, including the Netherlands and Germany, systematic monitoring of employee behaviour brings works councils into the decision with formal consultation rights. Under GDPR, behavioural data about identifiable employees requires a lawful basis, a defined retention period, and a response to access requests. A deployment scoped without that conversation stalls.
The purpose limitation needs to be explicit and written down. A risk score that identifies who needs support is a different artefact from a risk score that appears in a performance review or informs a disciplinary process. The technical capability is identical. Only the commitment differs, and the temptation arrives later when someone with authority asks why the data is not being used.
And the programme's credibility depends on employees believing the first framing. A workforce that concludes it is being surveilled will not report the phishing email it fell for, which removes the single most valuable signal the security function gets. Reporting behaviour is fragile and it depends entirely on people believing that reporting is safe.
Does behaviour change reduce risk?
This is the question the category rests on, and the evidence is more mixed than the marketing.
The case for is intuitive and partly supported: most incidents begin with a human action, so influencing that action should reduce incidents. Targeting interventions at people who actually exhibit risky behaviour, rather than at everyone equally, should improve on the uniform approach.
The complications are real. Research on simulated phishing has produced inconsistent results on durable behaviour change, with some studies finding that click rates rebound after training and others finding that embedded training at the moment of failure has limited lasting effect. Click rate itself is a contested metric, because it is sensitive to how convincing the simulation was, which the organisation controls.
There is also a measurement problem that no vendor can solve. The outcome that matters is breaches that did not happen, and an organisation cannot observe its own counterfactual. A programme can demonstrate that click rates fell and reporting rose. Whether that translated into fewer or less severe incidents is inferred rather than measured.
None of this argues the category is useless. It argues for scepticism about specific quantified claims, and for treating behavioural metrics as intermediate indicators rather than as outcomes.
The framing problem underneath
There is a harder critique of this entire area, and it is worth stating because the category's name invites it.
Attributing incidents to human error frequently describes a system that made the error easy. A phishing email that succeeds is often a message that was indistinguishable from legitimate internal communication, arriving in an environment where nobody could verify it. A misdirected file is often a system with no confirmation step. A reused password is often an authentication scheme that made a strong unique password painful.
Safety engineering in other industries moved past individual blame decades ago, on the finding that human error is usually the last visible link in a chain of design decisions. Aviation, medicine, and industrial safety all shifted toward asking what made the error possible rather than who made it.
Security is arriving at that conclusion more slowly, and a category built around scoring individual humans risks moving in the opposite direction.
The better vendors know this, which is why Forrester's definition includes adapting policies and technologies rather than only training. If the data shows a department consistently mishandling sensitive files, the range of possible responses includes training that department, and also changing the tooling, the permissions, or the process that makes mishandling the path of least resistance.
An HRM programme that only produces training assignments has diagnosed a systems problem and prescribed an individual remedy. The data supports the better response. Whether the organisation acts on it depends on whether the security function has any influence over the systems in question, which frequently it does not.
What the AI turn changes
Two shifts since the 2024 evaluation are worth carrying into any current assessment.
On the attacker side, generative tools have removed the cues people were trained to detect. The advice to look for poor grammar, generic greetings, and awkward phrasing is now obsolete, and voice cloning has made phone-based verification unreliable in a way that undermines the standard fallback of calling the person to check. Training content written before this shift is teaching heuristics that no longer discriminate.
On the exposure side, the risk surface has expanded past what these platforms were built to observe. An employee pasting confidential material into a consumer AI tool, connecting an unapproved agent to a corporate system, or accepting an agent-generated action without review is behaving in ways that carry real risk and that most behavioural monitoring was not designed to capture.
The category will have to absorb both. The first requires rethinking what interventions actually teach. The second requires new telemetry, and it sits close to the territory Forrester covers separately under agent governance.
Where this sits
Human risk management is a better idea than what it replaced. Uniform annual training measured by completion was demonstrably ineffective, and targeting intervention at actual behaviour is a genuine improvement in principle.
What it is not is a solution to the underlying problem, which is that organisations expose people to decisions they are poorly equipped to make and then measure how often they get them wrong.
The programmes that work treat the risk data as a diagnostic that points at systems as often as at individuals, keep the purpose limitation explicit enough that employees trust it, and resist quantifying outcomes that cannot honestly be quantified.
The ones that fail turn a behavioural dataset into a scoreboard, and discover that the population being scored responds by concealing exactly the behaviour the programme was meant to surface.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of human risk management, which it identifies as the successor to the security awareness and training market. Forrester mapped 15 vendors in The Human Risk Management Solutions Landscape, Q1 2024, and published its first scored evaluation of the market as The Forrester Wave: Human Risk Management Solutions, Q3 2024.
Source research
- The Human Risk Management Solutions Landscape, Q1 2024
- The Forrester Wave: Human Risk Management Solutions, Q3 2024
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.