IMPACT 2026: The findings are in. Your cheat sheet to the biggest human cyber risk takeaways – no fluff, just the good stuff.
07 October 2026

Shifting sands: The move from HRM to secure behaviour management

Gartner says ditch security awareness for secure behaviour management (SBM). Forrester calls it human risk management (HRM). Here's where the market is heading, and why the work matters more than the name.

On 22 September 2026, Gartner published research advising security leaders to ditch standard security awareness in favour of what it calls “secure behaviour management” (SBM): Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, by William Candrick and Alex Michaels. CybSafe is named a Representative Vendor in the report's list of SBM providers.

Since it landed, lots of people in our space have been debating what this means for human risk management (HRM), i.e. the term most of us have used for the past few years.

Here’s my take on where the market is heading (and why the wording matters much less than the work, but is helpful nonetheless).

‍

One shift, two names

Back in 2022, both major analyst firms reached the same conclusion; traditional security awareness training gets organisations through an audit, but does very little to demonstrably change what people do.

From there, their paths diverged slightly in name (but not in philosophy):

  • Forrester set out human risk management (HRM) as the direction it expected the market to take. In 2024, it formally retired the name ‘security awareness and training’ and adopted ‘human risk management’ instead.
  • Gartner defined the security behaviour and culture programme (SBCP) and published its accompanying PIPE framework (which included practices, influences, platforms and enablers), both of which it continued to develop. By 2026, it had coined its technology category: ‘secure behaviour management’ (SBM).

On paper, this looks like two competing camps. But in reality, they're singing from the same hymn sheet. Both agree that effective security programmes need:

  • Observed behaviour over course completion rates.
  • Targeted interventions at specific moments for specific people.
  • Measurable real-world outcomes and an eye on organisational security culture.

Both said awareness training alone couldn't get you there. I agree with both of them, and FWIW, I don't think anyone has to choose between them.

‍

Where they part ways

There are two main areas where Gartner and Forrester do genuinely differ …and both matter to security leaders.

The name. Gartner shies away from the term ‘human risk management’. In April 2026, Gartner analyst Richard Addiscott explained why: if you open a behaviour change programme by labelling your people as ‘risks’, you make your job harder.

I get that. But Forrester never meant that people are the risk. They meant the risks posed to people and through their actions. But enough people interpret it negatively that it creates friction …and arguing about semantics won't change what they hear.

‍

Why I prefer SBM:

  • It states the mission clearly: This is self-interest and there are no two ways about it, because managing, changing, and improving security behaviour is literally what CybSafe exists to do.
  • It scales into the future: As AI agents increasingly act on behalf of humans, ‘human’ starts to strain as a label. ‘Behaviour’, on the other hand, seamlessly covers both human employees and AI agents without missing a beat.

N.B.: Some people will dislike the idea of managing behaviour (let’s be honest, most words trigger someone), but the point of the work is to help people and the organisations they work for, and SBM describes that directly.

Vendor risk scores. The second difference arguably matters more to buyers. For some people, human risk management seems to have become synonymous with risk scores. Yet Gartner (rightly) warns that vendor risk scores lack industry standards and often rely heavily on proprietary data. That's a fair warning. A score built mostly on phishing simulation results and module completion only tells you how well people play that vendor's specific game. Biased much? Absolutely. Useful? …Less so.

But we’re not sitting in an ivory tower over here. Far from it. CybSafe has a scoring mechanism too, in the form of our Behaviour Risk Indicator (BRI). But we build it differently:

  • It estimates the likelihood of a security incident given a person's role and access permissions.
  • It ingests actual behavioural data from your existing security stack, combined with survey data.
  • It weights risk by blast radius (as in how much damage someone could cause if compromised), so executives with high access can't hide behind a sea of low-risk entries. (Sorry, not sorry.)

Whatever score you use, ours or anyone else's, it's important you check that you can see why it moved and which behaviours moved it. In case you're interested, the next piece of evidence we're building is how closely BRI tracks real incidents.

‍

What the new name doesn't force

Gartner's note says a lot about how to manage behaviour but leaves a gap around which behaviours to target. Nearly every example involves social engineering in some form (i.e. by email, voice, text or deepfake video). It does list integration with tools like DLP and IAM as a mark of SBM, which implies that other behaviours matter too …but that's all-too easy to miss.

The truth is that without clear guidance, you could still run security awareness activities, throw in some AI-generated social engineering simulations, send users an automated notification in Teams and call it secure behaviour management.

And against most of the criteria, it would pass …but it misses the point. Mostly because nothing in the framing makes you answer two crucial questions honestly:

  1. Are you working on the right range of behaviours? Reusing breached passwords, pasting sensitive company data into unapproved AI tools and sharing files through personal apps carry real (massive) exposure in most organisations, and none of these show up in a simulation.
  2. Are you actually changing anything? Are you doing something new, or just using shiny new(ish) AI technology to repeat the same old loop: i.e. simulate an attack, then assign training to anyone who didn't respond the way you hoped?

‍

Why training alone fails. (Strap in for the behavioural science)

Behaviour change takes more than training. Doctors know smoking causes harm, yet some still smoke. For most security behaviours, knowledge and understanding isn't what's missing either.

Behavioural science explains why. The COM-B model (developed by behavioural scientists at University College London) states that behaviour is driven by three factors: capability, opportunity and motivation. Standard training only builds capability. If the workplace environment makes the secure path cumbersome (opportunity), or if people don't care enough (motivation), training won't fix it.

‍

A quick example: password reuse

Consider six employees who all reuse the same password:

  • Person A doesn't understand the risk (capability gap).
  • Person B can't memorise dozens of logins (capability gap).
  • Person C doesn't have a password manager (opportunity gap).
  • Person D has a password manager, but finds it frustrating to use (opportunity gap).
  • Person E is under high pressure and takes the fastest route (motivation gap).
  • Person F understands the risk, but doesn't think they'll be targeted (motivation gap).

In most security programmes, all six get flagged with the same data point and sent the exact same password training module. But only Person A will actually benefit.

Training is one tool among many. The Behaviour Change Wheel, from the same research group, sets out nine types of intervention, and the Behaviour Change Technique Taxonomy lists 93 techniques.

Most organisations have three major gaps in their secure behaviour management:

  1. They don't know which behaviours are most likely to cause a breach in their organisation.
  2. They can't prove that any behaviour they target improves because of what they did.
  3. They can't act on a new behavioural risk in hours rather than weeks, and only focus on the people who need it.

‍

Start with the harm

Gartner’s research implies a critical question that it doesn’t quite answer: How do you actually decide which behaviours to focus on?

The most reliable approach I know of, is to start with the outcomes you want to avoid and work backwards. Here’s how the chain breaks down:

  • Risky behaviours contribute directly to vulnerabilities.
  • Threats exploit vulnerabilities, increasing the likelihood of an incident.
  • Likelihood combined with potential impact equals your overall risk.
  • When that risk materialises, it becomes an incident.
  • Incidents trigger the outcomes board members care about: financial loss, regulatory fines, operational disruption, and reputational damage.

By the time an incident shows up, a vulnerability has already been exploited. Behaviours show up earlier in the chain …while you can still do something about them.

Risk and behaviour aren't competing frameworks. Risk tells you where to look; behaviour tells you whether anything actually changed.

We built the Security Behaviour Database (SebDB) for exactly this. It's a research-based map of more than 100 security behaviours and how they connect to risk outcomes, so a programme can start from exactly what it's trying to prevent, instead of what its platform can simulate.

‍

What I think every organisation should be doing

Whatever you call your programme, the goal is simple: stop the guesswork, maximise effectiveness, and drive towards specific, provable outcomes.

Most programmes still guess at four things:

  • Which behaviours to focus on
  • Why those behaviours are happening
  • What intervention will change them
  • Whether the intervention actually caused the change

‍

To remove those four blind spots (and keep them away), follow these five steps:

1. Find the behaviours that matter

Measure what people are doing, connect those actions to real-world risk, and select the vital few behaviours carrying real exposure in your organisation right now.

2. Work out why they're happening

The same risky behaviour often stems from completely different root causes. Use behavioural science to pinpoint the most likely triggers, then validate them through telemetry, surveys, interviews and experiments.

3. Choose a fix that matches the cause

If the gap is knowledge, standard learning works. If the issue is friction, broken processes, or conflicting incentives, training will fail – you need nudges, workflow adjustments, or direct manager intervention.

4. Prove it worked

Measure what people do differently afterwards. Use controlled trials where possible to confirm that the positive change was caused by your intervention …not pure chance.

5. Measure again and move right along

Once a targeted behaviour is safely under control (or a new threat emerges), shift your attention to the next highest-exposure area.

‍

Where that leaves us

We’ve built CybSafe around this exact philosophy from the beginning.

Our foundation – from our early taxonomy research and SebDB, the work to promote the human security research library, randomised controlled trials (RCTs), and ongoing development of a unified behavioural ontology under Project NEXUS – all stems from a single core question:

What are people actually doing, and what genuinely helps them do it more securely?

Yes, we’re a human risk management platform. We’re also a secure behaviour management platform. But above all, we’re a behaviour change platform. Category labels describe the evolving market; changing human behaviour is the work we do inside it.

If Gartner’s next piece of research dictates which specific behaviours programmes should cover and sets clear standards for proving behavioural change, the industry will evolve once again. I’d welcome both with open arms.

In the meantime, ask yourself two questions about your own programme:

  • Which behaviours carry the most exposure in your organisation right now?
  • Could you prove to your board whether any of them actually changed?

Did you find this useful? Join our Unfiltered Signals list for more insights.