Gartner says ditch security awareness for secure behaviour management (SBM). Forrester calls it human risk management (HRM). Here's where the market is heading, and why the work matters more than the name.

On 22 September 2026, Gartner published research advising security leaders to ditch standard security awareness in favour of what it calls “secure behaviour management” (SBM): Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, by William Candrick and Alex Michaels. CybSafe is named a Representative Vendor in the report's list of SBM providers.
Since it landed, lots of people in our space have been debating what this means for human risk management (HRM), i.e. the term most of us have used for the past few years.
Here’s my take on where the market is heading (and why the wording matters much less than the work, but is helpful nonetheless).
Back in 2022, both major analyst firms reached the same conclusion; traditional security awareness training gets organisations through an audit, but does very little to demonstrably change what people do.
From there, their paths diverged slightly in name (but not in philosophy):
On paper, this looks like two competing camps. But in reality, they're singing from the same hymn sheet. Both agree that effective security programmes need:
Both said awareness training alone couldn't get you there. I agree with both of them, and FWIW, I don't think anyone has to choose between them.
There are two main areas where Gartner and Forrester do genuinely differ …and both matter to security leaders.
The name. Gartner shies away from the term ‘human risk management’. In April 2026, Gartner analyst Richard Addiscott explained why: if you open a behaviour change programme by labelling your people as ‘risks’, you make your job harder.
I get that. But Forrester never meant that people are the risk. They meant the risks posed to people and through their actions. But enough people interpret it negatively that it creates friction …and arguing about semantics won't change what they hear.
Why I prefer SBM:
N.B.: Some people will dislike the idea of managing behaviour (let’s be honest, most words trigger someone), but the point of the work is to help people and the organisations they work for, and SBM describes that directly.
Vendor risk scores. The second difference arguably matters more to buyers. For some people, human risk management seems to have become synonymous with risk scores. Yet Gartner (rightly) warns that vendor risk scores lack industry standards and often rely heavily on proprietary data. That's a fair warning. A score built mostly on phishing simulation results and module completion only tells you how well people play that vendor's specific game. Biased much? Absolutely. Useful? …Less so.
But we’re not sitting in an ivory tower over here. Far from it. CybSafe has a scoring mechanism too, in the form of our Behaviour Risk Indicator (BRI). But we build it differently:
Whatever score you use, ours or anyone else's, it's important you check that you can see why it moved and which behaviours moved it. In case you're interested, the next piece of evidence we're building is how closely BRI tracks real incidents.
Gartner's note says a lot about how to manage behaviour but leaves a gap around which behaviours to target. Nearly every example involves social engineering in some form (i.e. by email, voice, text or deepfake video). It does list integration with tools like DLP and IAM as a mark of SBM, which implies that other behaviours matter too …but that's all-too easy to miss.
The truth is that without clear guidance, you could still run security awareness activities, throw in some AI-generated social engineering simulations, send users an automated notification in Teams and call it secure behaviour management.
And against most of the criteria, it would pass …but it misses the point. Mostly because nothing in the framing makes you answer two crucial questions honestly:
Behaviour change takes more than training. Doctors know smoking causes harm, yet some still smoke. For most security behaviours, knowledge and understanding isn't what's missing either.
Behavioural science explains why. The COM-B model (developed by behavioural scientists at University College London) states that behaviour is driven by three factors: capability, opportunity and motivation. Standard training only builds capability. If the workplace environment makes the secure path cumbersome (opportunity), or if people don't care enough (motivation), training won't fix it.
Consider six employees who all reuse the same password:
In most security programmes, all six get flagged with the same data point and sent the exact same password training module. But only Person A will actually benefit.
Training is one tool among many. The Behaviour Change Wheel, from the same research group, sets out nine types of intervention, and the Behaviour Change Technique Taxonomy lists 93 techniques.
Most organisations have three major gaps in their secure behaviour management:
Gartner’s research implies a critical question that it doesn’t quite answer: How do you actually decide which behaviours to focus on?
The most reliable approach I know of, is to start with the outcomes you want to avoid and work backwards. Here’s how the chain breaks down:
By the time an incident shows up, a vulnerability has already been exploited. Behaviours show up earlier in the chain …while you can still do something about them.
Risk and behaviour aren't competing frameworks. Risk tells you where to look; behaviour tells you whether anything actually changed.
We built the Security Behaviour Database (SebDB) for exactly this. It's a research-based map of more than 100 security behaviours and how they connect to risk outcomes, so a programme can start from exactly what it's trying to prevent, instead of what its platform can simulate.
Whatever you call your programme, the goal is simple: stop the guesswork, maximise effectiveness, and drive towards specific, provable outcomes.
Most programmes still guess at four things:
To remove those four blind spots (and keep them away), follow these five steps:
Measure what people are doing, connect those actions to real-world risk, and select the vital few behaviours carrying real exposure in your organisation right now.
The same risky behaviour often stems from completely different root causes. Use behavioural science to pinpoint the most likely triggers, then validate them through telemetry, surveys, interviews and experiments.
If the gap is knowledge, standard learning works. If the issue is friction, broken processes, or conflicting incentives, training will fail – you need nudges, workflow adjustments, or direct manager intervention.
Measure what people do differently afterwards. Use controlled trials where possible to confirm that the positive change was caused by your intervention …not pure chance.
Once a targeted behaviour is safely under control (or a new threat emerges), shift your attention to the next highest-exposure area.
We’ve built CybSafe around this exact philosophy from the beginning.
Our foundation – from our early taxonomy research and SebDB, the work to promote the human security research library, randomised controlled trials (RCTs), and ongoing development of a unified behavioural ontology under Project NEXUS – all stems from a single core question:
What are people actually doing, and what genuinely helps them do it more securely?
Yes, we’re a human risk management platform. We’re also a secure behaviour management platform. But above all, we’re a behaviour change platform. Category labels describe the evolving market; changing human behaviour is the work we do inside it.
If Gartner’s next piece of research dictates which specific behaviours programmes should cover and sets clear standards for proving behavioural change, the industry will evolve once again. I’d welcome both with open arms.
In the meantime, ask yourself two questions about your own programme:
Did you find this useful? Join our Unfiltered Signals list for more insights.