The Human Side of Cybersecurity

The Human Risk Assessment

How to measure the human behavior in cybersecurity and how to differentiate it from knowledge about cyber-risky situations?

The Human Risk Assessment

The human side of cybersecurity in focus

About the author: Dr. Maria Bada is a lecturer in Cyberpsychology at Queen Mary university in London and a RISCS Fellow in cybercrime. Her focus is the human aspect of cybercrime and cybersecurity.

Cybersecurity knowledge

Cybersecurity knowledge

It can vary widely between individuals and teams within an organization.

Hackers can target anyone

Hackers can target anyone

Employees’ vulnerability to being targeted is not necessarily dependent on their position or level of access to company systems.

One size doesn't fit all

One size doesn’t fit all

Selecting the right training that changes behavior can be difficult.

How to identify behaviors and employees in need of training?

Identify those who need more training or specific training by collecting insights about employee behavior. The Human Risk Assessment considers the risk perception of employees and offers valuable information regarding employees’ perceptions of how their behaviors can impact their organization’s assets.

Make informed decisions about internal policies, procedures and training

This data-driven, interactive, and easy-to-administer solution allows businesses to assess their current state of human cyber-resilience, identify the specific vulnerabilities in their employees’ security knowledge and behavior, and implement a more focused and engaging approach to training.

Download free whitepaper

Learn about the human side of cybersecurity and the methodology behind the Human Risk Assessment

Learn about the human side of cybersecurity and the methodology behind the Human Risk Assessment

Also in this series Stakeholder Analysis: Motives, Needs and Drivers for Security Awareness Training

The 2nd whitepaper presents the findings of a stakeholder analysis with over 160 participants presenting their opinions and experience on the status of cybersecurity training in modern work environments Learn more

Free whitepaper The need for human-centered security awareness training

The human factor in cybersecurity has become the primary way for hackers to establish a foothold within critical infrastructure. The broad impact of these attacks is not only financial and reputational, but also social, and psychological. Learn more

Protect your company against cyber attacks preying on your employees

Try AwareGO, the only complete solution for cybersecurity awareness, from assessment to training — it’s simple, efficient and employees love it

Stay on top of cybersecurity threats

Managed Cybersecurity Awareness Services: A Strategic Guide to Human Risk Management in 2026

What if your employees weren't your biggest vulnerability, but your most effective security sensor? You're likely tired of the monthly treadmill of......

The Ultimate SCORM Content Library for Cybersecurity Awareness in 2026

What if the biggest threat to your 2026 security posture isn't a zero-day exploit, but the fact that 60% of your workforce is currently...

Security Awareness Training for Compliance: A Guide to Human Risk Management

The 2023 Verizon Data Breach Investigations Report found that 74% of all breaches involve the human element, yet many organizations still treat...

How to Quantify Employee Risk: A Data-Driven Guide for Modern CISOs

The 2023 Verizon Data Breach Investigations Report reveals that 74% of all breaches involve a human element, yet most security leaders still treat...

Social Engineering Techniques: A Deep Dive into the Psychology of the Human Hack

What if your most sophisticated technical filters are looking in the wrong direction? While IT teams invest heavily in perimeter defense, the 2023...

Human Risk Management Software: The 2026 Guide to Behavioral Resilience

What if your most expensive security tool isn't a firewall, but the collective habits of your workforce? Even with massive investments in tech, the......

How to Spot the Signs of Phishing in 2026: A Human-Centric Guide

What if the most dangerous part of a cyberattack isn't the malicious code, but the specific way it makes you feel? You've likely sat through dozens......

Gamification in Cybersecurity: Boosting Engagement and Reducing Human Risk

What if the most dangerous part of your security strategy is actually the "Next" button on your compliance slides? You’ve likely seen the data:...

Reporting Cybersecurity Metrics to the Board: A Narrative of Resilience

Your board doesn't care about the 15,000 malicious emails your firewall blocked last Tuesday. While those numbers feel like progress to a technical......

How to Measure Security Culture: A Data-Driven Guide for 2026

Why are 74% of data breaches still linked to human error when your team completes their training every single year? It's a common struggle for...