Skip to main content
Trusted by Hundreds of MSPs

What is secure behavior management (SBM)?

Secure behavior management (SBM) is the practice of building and measuring the specific work behaviors that keep an organization safe, such as reporting suspicious messages and verifying unusual requests, instead of measuring training completion or scoring employees as risks.

app.hooksecurity.co/dashboard
Security Overview

Last 30 days

↓ 73% risk reduction
1,247
Simulations Sent
+12%
94.2%
Pass Rate
+8%
3,892
Trained Users
+156
Recent Activity
Phishing simulation completed
Marketing Team
2m ago
Training module finished
john.doe@company.com
15m ago
Suspicious click detected
sarah.smith@company.com
1h ago

Where did the term come from?

Gartner proposed it. In an April 2026 Analyst Take, “Why It’s Time to Drop ‘Human Risk Management’ as a Market Name,” Gartner analyst Richard Addiscott recommended the market move past “human risk management” (HRM) and ask for secure behavior management instead. The reason, in Gartner’s words: “SBM speaks directly to the CISO’s goal of fostering more secure work behaviors and a more security-conscious corporate culture to reduce employee-initiated risks.”

It fits a direction Gartner has signaled for years. Gartner predicts that by 2030, widely adopted control frameworks will “focus on measurable behavior change rather than compliance-based training.” At its 2026 Security & Risk Management Summit, Gartner analyst Elizabeth Davis put it plainly: “The goal is not security awareness, but secure habits,” and employees are “assets and not risks.”

You will also see it written as “security behavior management,” and in UK English as “secure behaviour management” or “security behaviour management.” All four mean the same thing; Gartner’s term is secure behavior management.

What SBM is, and what it isn’t

SBM isSBM isn’t
Building specific, observable behaviors (report, pause, verify)Annual compliance training with a completion certificate
Measuring what people do, like reporting rate and time to first reportMeasuring attendance and quiz scores
Treating employees as the organization's best defenseTreating employees as risks to be ranked
Short, frequent practice that builds habitsOne long session a year
Recognizing people who reportShaming or punishing people who click
A culture program owned by security and leadershipA tool you switch on and forget

What counts as a secure behavior?

A secure behavior (or security behavior) is a specific, observable action that makes an attack less likely to succeed. SBM is about building these, not just teaching facts. Examples from the behaviors catalogued on PsySec.io:

  • Reports suspicious messages, whether or not they clicked.
  • Pauses when a message pushes them to act fast.
  • Verifies unusual requests through a second channel.
  • Reports their own mistakes quickly.
  • Confirms identity before helping.

Organizations have secure behaviors too: measuring reporting first, giving simulation feedback to everyone, and never shaming people who click.

SBM vs human risk management vs security awareness training

Security awareness training (SAT)Human risk management (HRM)Secure behavior management (SBM)
Core questionDid everyone complete training?Who is our riskiest person?Are people doing the secure behaviors we need?
How it sees peopleAn audience to educateA risk to measure and reduceThe people whose habits defend the organization
Typical metricCompletion ratePer-person risk numberBehavior rates, led by reporting
Typical interventionAnnual courseAutomated training for whoever scores worstRegular practice, feedback for everyone, recognition
Who named itThe industryForrester popularized it as a categoryGartner (April 2026)

Where SBCPs fit: a security behavior and culture program (SBCP) is Gartner’s name for the program an organization runs to change behavior, combining training, simulations and other behavior-influencing practices. SBM is the name Gartner proposes for the market and discipline that program belongs to.

Why move past “human risk management”?

HRM got the diagnosis right: compliance training alone doesn’t change behavior. The trouble is the framing. When a program’s core output is a number on each person, people learn to hide mistakes rather than report them. The largest long-term field study of workplace phishing (14,000+ employees over 15 months) found that reporting worked as a fast, crowd-sourced detection system, while embedded training didn’t make people more resilient (Lain et al., IEEE S&P 2022). A behavior you want more of is easier to grow than a risk you’re trying to shrink. More in human risk management vs PsySec.

How do you measure secure behavior management?

  1. Suspicious Email Reporting Rate (SERR): the share of people who report a simulated or real phishing message. The headline SBM metric. What reporting rate measures.
  2. Time to first report: how fast the first report reaches your team. In a 2026 study of 12,511 employees, a report arrived before the first click in 36–55% of simulations (Rozema & Davis, WWW ’26). See the reporting race.
  3. Resilience by manipulation tactic: which tactics (urgency, authority, trust and others) your people find hardest, so you know what to practice next. Resilience and vulnerability by tactic is never used to rank individuals.
  4. Click rate, as a diagnostic: useful for spotting hard tactics; never a verdict on a person.
  5. Training completion: still needed for compliance, but it proves attendance, not behavior.

How PsySec delivers secure behavior management

SBM names the goal. Psychological Security (PsySec) is how it happens: secure behavior management, fully implemented and flourishing. The two go hand in glove. PsySec treats manipulation as the real threat and builds the habits that resist it: belief leads to emotion, emotion leads to behavior, and behavior repeated becomes habit.

In practice, a PsySec program:

  • Makes reporting the primary goal and recognizes every report right away.
  • Practices a little every month, because training gains fade within about six months (Reinheimer et al., SOUPS 2020).
  • Sends feedback to everyone after a simulation, not only to people who clicked (Yin et al., MIS Quarterly).
  • Measures resilience by manipulation tactic instead of scoring people.

The research behind each of these, including the studies that challenge it, is open at PsySec.io.

Secure behavior management for MSPs

For MSPs, SBM turns a phishing add-on into a managed service clients can see working: a reporting rate that goes up, a first report that lands sooner, and a quarterly review that shows behavior, not just completions. Hook Security is a security awareness training and phishing simulation platform built for MSPs and SMBs, and it runs PsySec programs on Autopilot across every client. See how it works for MSPs.

Secure behavior management FAQ

Secure behavior management: building and measuring the work behaviors that keep an organization safe. Gartner proposed it in April 2026 as the market name to replace human risk management.

They share a goal, measurable behavior change, but differ in framing. HRM centers on measuring and reducing the risk each person poses. SBM centers on the secure behaviors you want people to adopt.

Gartner recommended dropping HRM as a market name in favor of SBM. Many vendors still use HRM, so you will see both terms for a while.

All of them name the same thing. Gartner’s term is secure behavior management. "Security behavior management" is a common variant, and UK English spells both with "behaviour."

Reporting. A report is what lets a security team stop an attack, so the Suspicious Email Reporting Rate (SERR) and time to first report lead.

They go hand in glove. SBM is the goal; PsySec is how SBM happens when it is fully implemented: reporting as the primary metric, habits built through regular practice, and resilience measured by manipulation tactic.

See secure behavior management running.

Thirty minutes, a live account, and the reporting numbers that show behavior changing.