Skip to content
Aspire SAT
ASAT · Human risk management

Human risk management that shows who’s at risk, and brings it down

ASAT scores every employee on how they handle real-world attacks, from phishing and texts to cloned voices, deepfakes and leaked passwords. Then it assigns the right training automatically and shows your board the number falling.

30 days · 5 users · No credit card
Human risk overview · Enhanced presentation with sample data
  • Seven observed signals
  • Behavior-triggered learning
  • Leadership-ready reporting

Trusted by security teams at

  • BAE Systems
  • City of Burbank
  • Cloud Himalaya
  • Midland Bank
  • Mutual Trust Bank
  • ONY
  • Special Security Force, Bangladesh
  • Technuf
  • Washington County, Maryland
Definition

What is human risk management?

Human risk management (HRM) is the continuous process of measuring how employees respond to cyber threats, stepping in with the right training or action when someone’s risk rises, and tracking whether risk falls over time. It replaces “who finished the course” with “who would fall for the attack.”

See it in practice
One human
risk picture
Observed behavior + exposure
  • 01Email clicks & credentials
  • 02SMS responses
  • 03Voice requests
  • 04Deepfake responses
  • 05Threat reports
  • 06Training & exams
  • 07Credential exposure
Built around the work

What goes into every
human risk score.

Seven signals in, four actions out, updated continuously. Every input is something the employee actually did, not a guess from their job title.

01 / 06

Seven signals in one score

Measure email clicks and credential submissions, SMS taps, compliance with voice requests, actions on deepfake video, threat reports, training and exams, and dark-web credential exposure. Update scores continuously from observed behavior and exposure, not assumptions based on job titles.

Put the idea into practice
INSIDE THE WORKFLOWObserved behavior, connected
  1. 01

    Simulation responses + threat reports

  2. 02

    Learning completion + exams

  3. 03

    Exposed work credentials

Illustrative workflow
How it works

From an awareness program
to human risk management.

  1. 01

    Measure

    A live risk score for every person and department, built from how they handle simulated attacks and whether their credentials have leaked.

  2. 02

    Intervene

    Lessons, learning paths and escalations that trigger automatically when someone’s behavior says they’re needed.

  3. 03

    Prove

    Trends and board-ready reports that show human risk falling, quarter by quarter.

From a feature to a decision

A realistic situation.
A chance to practise.

Explore a sample scenario and the reasoning behind a safer response.

Risk-driven follow-up

A repeat clicker needs a focused learning path.

An employee clicks three simulations in 30 days. A configured playbook checks whether a focused path is already in progress before assigning credential-safety lessons.

Repeated simulation clicksLearning statusDepartment context
Illustrative learning scenario
A moment to practise

What would you do next?

Choose a response to see the learning behind the decision.

The habit to build

Assign the relevant path, follow up with the manager and review how learning and reporting change the score.

What the program builds

From a risk signal
to a useful next step.

01

For the employee

Focused learning explains the behavior that needs to change, with a clear path toward safer decisions.

02

For the security team

Individual scores and department context help prioritize support and avoid repeating work already in progress.

03

For leadership

Connect the score, its movement and the interventions taken in a report that explains what happens next.

Designed for your team

Where this fits.

  • CISOs and IT or security program owners
  • Risk and compliance teams reporting to leadership
  • Banks, healthcare organizations and managed service providers
A closer look

Good questions.
Clear answers.

Understand the details, the learning objectives and how human risk management fits your program.

Talk to our team
What is human risk management?

Human risk management (HRM) is the continuous process of measuring how employees respond to cyber threats, stepping in with the right training or action when someone’s risk rises, and tracking whether risk falls over time. It replaces “who finished the course” with “who would fall for the attack.”

How is the Human Risk Management calculated?

Seven inputs contribute: email simulation clicks and credential submissions; SMS taps; compliance with simulated voice requests; acting on deepfake videos; threat reporting; training completion and exams; and leaked work credentials. Reporting attacks and passing exams move the score toward safer groups. Risky actions and credential exposure raise the need for support. Read the contributing behaviors and trends rather than treating someone’s job title as a risk prediction.

What do High, Average, Low and Safe mean?

High: New or untrained, or showing risky behavior. Focused path + manager informed. Average: Some training done; still needs follow-up. Monthly lessons + harder simulations. Low: Most training complete; spots fakes most of the time. Lighter touch, monitored. Safe: All training done; reports what they see. Advanced scenarios to stay sharp. Behavior moves people between groups; Safe does not mean immune to attack.

Can follow-up happen automatically?

Yes. For the repeat-clicker playbook, the trigger is three simulation clicks in 30 days across email, SMS or QR. Check that the employee is not already on a focused path, then assign four short credential-safety lessons and an exam. Inform the manager at 80% of the training deadline and copy HR at 90% if it remains open. Scores respond as learning and reports arrive; once the learner returns to Low, use harder simulations. Separate playbooks can respond to a breached password or a vishing failure.

How does dark-web exposure affect the risk picture?

Training completion cannot tell you whether a work password has leaked. Continuous scans of public breach data and dark-web sources find exposures, including password hashes in third-party breach datasets. A match raises the person’s score, triggers an immediate alert and password-reset request, and assigns a password-hygiene lesson for follow-up.

Are all simulation channels and integrations included in every plan?

No. Available channels and integrations depend on the package. SIEM events are available on Diamond plans. Check the pricing page or confirm requirements with the team before choosing a plan.

What actions can a risk signal trigger?

Four responses connect measurement to action: a two-minute lesson at the moment of a mistake, a new learning path matched to the behavior, escalation to a manager, HR or leadership, and events delivered to your SIEM on Diamond plans. Available simulation channels vary by package.

Which behaviors explain why someone needs support?

Look for credential submissions, breached work passwords, compliance with a cloned-voice request, three or more simulation clicks in 30 days, and unverified QR scans. Combine those with overdue learning. For example, an Accounts Payable employee who clicks invoice lures, has an exposed password and has an overdue course can receive a payment-fraud path with manager follow-up.

What can leadership see in a quarterly report?

A one-page report brings together the organization’s risk score, the change from the previous quarter, reporting and click rates, the riskiest department, the number of people who moved out of High, and the interventions taken. A six-month department heat map shows where risk concentrates. Next-quarter actions can include payment-fraud training for Finance and voice-clone verification for executives.

How does human risk management expand an awareness program?

Move from who finished to who is at risk and why; from generic courses to behavior-triggered training; and from email-only tests to supported email, SMS, voice and deepfake simulations plus leaked credentials. Continuous scoring replaces an annual review, automated playbooks replace manual chasing, and a board-ready risk report complements the completion export.

Can we try human risk scoring before choosing a plan?

Yes. Start a 30-day free trial with no credit card to see your organization’s Human Risk Management. Risk scoring is included in published plans; compare the pricing page for the simulation channels, support and integrations your team needs.

Your next step

Understand the risk.
Know where to act.

Bring your team’s priorities. We’ll walk through the scenarios, learning and insights that fit your program.

A useful conversation.
Built around your team.

  • Discuss your audience and goals
  • Explore relevant product workflows
  • Confirm the right plan and next steps
Compare published plans