Human Risk Management vs PsySec: What the Research Actually Says
Updated September 2026
Short answer: Human risk management is the right diagnosis and, in most products, the wrong prescription. Gartner's framing — that human risk is a culture problem rather than a training problem — is correct. But most HRM platforms implemented that framing as a scoring engine: measure individuals, rank them, and fire automated training at whoever fails. The largest independent study of phishing simulation to date found that this loop does not build resilience. PsySec keeps the measurement and drops the scoring.
What human risk management actually means
Human risk management (HRM) is the industry's successor term to security awareness training. It reflects a genuine and overdue shift: away from measuring whether people completed a course, toward measuring whether their behavior changed.
The framing comes largely from Gartner, which predicts that "by 2030, all widely adopted cybersecurity control frameworks will focus on measurable behavior change rather than compliance-based training as the critical measure of efficacy for human risk management." Its PIPE framework — Practices, Influences, Platforms, Enablers — is explicitly a security behavior and culture programme, shaped by user experience, managerial influence and organizational norms.
Read that carefully, because it matters for what follows: Gartner described a culture change initiative. It did not describe a scoring system.
Where HRM is right, and Hook agrees
It would be dishonest to argue against the diagnosis. HRM gets three things right, and any vendor still selling annual-video compliance theatre is behind:
- Completion is not competence. A finished course proves attendance, nothing more.
- Behavior is the outcome that matters, and it has to be measured over time rather than sampled once a year.
- Risk is unevenly distributed. A finance team approving payments and a warehouse team without email access do not carry the same exposure.
Hook Security has no argument with any of that. The disagreement is about what you do with the measurement once you have it.
Where the implementation went wrong
The first problem is scoring people. Most HRM platforms assign each employee a numerical risk score, then follow them around with it. The number is presented as a property of the person, when what it actually records is how often that person met a difficult simulation, in a busy week, in a role that receives more external email than most.
A risk score is a measurement of circumstance wearing the costume of a character trait. And once a number is attached to a name, it travels — into dashboards, into manager conversations, and eventually into performance reviews, whatever the vendor's documentation says about intent.
The second problem is the mechanistic loop. Simulate, detect a click, auto-assign remediation, re-score, repeat. It is satisfying to operate and easy to sell, because it produces a chart that goes down and to the right. The difficulty is that the largest independent study of the practice found that it does not do what it claims.
What the research found
Researchers at ETH Zurich ran a phishing study across more than 14,000 employees of a single organization over 15 months, tracking click rates, dangerous credential submissions and reports made through a reporting button. It remains the largest and longest independent field study of workplace phishing simulation.
Their conclusion on the industry-standard approach was blunt: embedded training during simulated phishing exercises, "as commonly deployed in the industry today, does not make employees more resilient to phishing, but instead it can have unexpected side effects."
That is not a critique of measuring human risk. It is a critique of the specific mechanism most HRM platforms are built on. A follow-up study by the same group, which won a Distinguished Paper Award at ACM CCS 2024, went further and separated embedded training into its parts. Its conclusion is uncomfortable for every vendor in this category, Hook included: the effect came mainly from the nudge — the periodic reminder that the threat exists — rather than from the training content itself. The same study found that rewards did not improve secure behavior.
Hook sells content quality, so that finding deserves to be stated rather than buried. Read fairly, it says two things. Cadence matters more than most vendors admit, which is an argument for a programme that runs continuously rather than in an annual burst. And any vendor claiming their content is the decisive variable — Hook included — is claiming more than the current evidence supports.
What the research found does work
The same ETH study found something the industry talks about far less. Using employees as a collective detection mechanism — a reporting button, used at scale — was not only effective but practical: it allowed fast detection of new phishing campaigns, the operational load on the organization was acceptable, and employees remained active reporters over long periods.
In other words: the part where you catch people failing produced questionable results. The part where you invite people to participate produced a working early-warning system.
Separately, researchers at USENIX SOUPS found that employees' ability to identify phishing emails remained significantly improved four months after training, but was no longer significantly better at six months — and that video and interactive formats sustained the effect longest. Reinforcement is not a nice-to-have; it is the difference between a program that works and a program that expired in month five.
What PsySec does differently
PsySec — psychological security — is Hook Security's methodology, and it starts from the chain the mechanistic model skips: belief shapes emotion, emotion shapes behavior, and only repeated behavior becomes habit. Most platforms attempt to force behavior directly, which is why click rates drift back up after every training cycle. Nothing underneath them changed.
In practice that produces four differences:
- Reporting rate is the primary metric, not click rate. Click rate measures failure on one simulation and is trivially gameable by sending easier simulations. Reporting rate measures the behavior that actually shortens a real incident — and it is the behavior the ETH data found scales.
- Resilience and vulnerability are measured per tactic, not per person. Whether an organization is susceptible to urgency, authority or social proof is actionable. A ranked list of employees is not.
- A click produces coaching, privately and immediately, with no leaderboard and no manager notification. People who expect coaching report quickly. People who expect blame go quiet, and a quiet click is the expensive kind.
- Training is short, continuous and made to be watched. Humor is not decoration here; it is the mechanism that gets a video finished, and an unfinished video changes nobody.
The honest limits of this argument
None of the studies above tested Hook Security, and it would be exactly the kind of claim this article is criticising to imply otherwise. What the research supports is a direction — that collective reporting works, that reinforcement has a measurable half-life, and that the simulate-and-punish loop does not deliver what the category assumes. PsySec is built on that direction. It is not proof of a specific vendor's outcomes, and no vendor citing this literature can honestly say otherwise.
There is also a legitimate case for HRM platforms. If an organization is genuinely large, genuinely mature, and needs to correlate human signal with identity, endpoint and data-loss telemetry, that integration is real work and Hook does not do it. Hook is built for SMBs and the service providers who support them, where the constraint is not telemetry breadth — it is whether the program runs at all, and whether anyone watches it.
So which should you buy
Take the HRM diagnosis. Measure behavior rather than completion. Report on trend rather than a single snapshot. Accept that risk is unevenly distributed.
Then ask the vendor two questions. What happens to an employee's score after they click, and who sees it. And whether their primary metric is the one that goes down when you make simulations easier, or the one that goes up when people start participating.
The answers will tell you whether you are buying a culture programme or a scoreboard.
Frequently asked questions
Is human risk management just security awareness training rebranded?
Partly, but not entirely. The measurement discipline is a genuine improvement — tracking behavior over time rather than course completion is the right instinct. What is often rebranding is the underlying product: the same simulate-and-train loop, with a risk score on top.
Is individual risk scoring ever useful?
It can be useful as an internal targeting signal — deciding who needs more practice — provided the number never reaches the employee or their manager. The failure mode is not measurement, it is exposure. Once a score is visible to someone with authority over the person, it stops measuring behavior and starts shaping it in ways that reduce reporting.
What should we measure instead of click rate?
Reporting rate and time-to-report, tracked as a trend, with click rate as a supporting figure rather than the headline. A program can lower click rate by sending easier simulations. It cannot fake people choosing to report.
Does Hook Security do human risk management?
By Gartner's definition of the outcome — measuring and influencing human cyber risk and improving decision-making at scale — yes. By the common product definition of scoring individuals and automating remediation against those scores, deliberately not. Hook measures resilience and vulnerability per tactic at the organizational level, and treats a click as a coaching moment rather than a mark on a record.
Training courses on this topic
From Hook Security’s security awareness training library.
- 40 minThe Too Late Show Annual TrainingHook Security's premier training is back. Grab a snack and get ready to laugh. The Too Late Show with host Kimberly Caine has games, guests, and a few extra surprises! Covering topics such as social engineering, passwords, safe web browsing, malware, and more!
- 46 minPsySec EssentialsPsySec Essentials creates a baseline knowledge for your employees, and brings new employees up to speed on Cyber Security threats. This annual training course touches on each area of security an employee should know for the year.
- 8 minPhishing with Mike Fry The Cyber GuyPhishing with Mike Fry The Cyber Guy - Security awareness training
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.