From Awareness Training to Human Risk Management

From Awareness Training to Human Risk Management

Somewhere on your desk is a renewal quote for security awareness training, and the line item has quietly changed its name. The vendor now sells a “human risk management platform.” That rename is not marketing noise — it marks a genuine category transition, one that Forrester formalized with its first Wave for Human Risk Management Solutions in Q3 2024 and that Gartner has been circling with its human-centric security research. The annual-training-plus-quarterly-phishing-test model that most enterprises have run since roughly 2015 is being replaced by continuous behavioral scoring, real-time intervention, and — increasingly — autonomous AI agents that decide who gets trained, on what, and when.

This brief maps the transition: what actually changed, why the old model stalled, where KnowBe4 — the category’s incumbent — now sits, and the checklist that separates a rebadged awareness tool from a genuine behavioral platform. If you buy or renew in the next twelve months, this is the decision you are actually making.

What changed

Three things converged. First, the analysts drew a new map. Forrester’s inaugural Wave for Human Risk Management Solutions (Q3 2024) evaluated vendors on behavioral data, risk quantification, and intervention — not on the size of their training-content libraries. Leaders in that first cut included behavioral-science specialists CybSafe and Living Security, a signal that the evaluation criteria had moved past where the legacy suites were strongest. Gartner, meanwhile, has pushed the same direction under its human-centric security banner, arguing that awareness alone does not change behavior.

Second, the incumbent re-platformed. KnowBe4 — taken private by Vista Equity Partners in early 2023 in a $4.6 billion deal — spent the following three years rebuilding around an AI-agent architecture it calls AIDA (Artificial Intelligence Defense Agents), culminating in the March 2026 launch of AIDA Orchestration, an autonomous agent that creates and schedules per-user phishing tests and training without an admin building campaigns. When the vendor with the largest customer base in the category stops selling seat-licensed training modules and starts selling autonomous risk agents, the category has moved.

Third, attackers automated first. AI-generated phishing collapsed the cost of producing convincing, personalized lures. A quarterly template-based simulation program is now testing employees against a threat that no longer exists in that form. The gap shows up directly in the numbers — see our companion analysis of phishing click-rate benchmarks for 2026 for where healthy programs actually land.

Why it matters

The old model produced a compliance artifact, not a risk reduction. Completion rates near 100 percent and click rates that plateau after year two are the signature of a program that has stopped changing behavior. Every breach report of the last decade says the same thing: the human element sits in the causal chain of a large majority of incidents. Spending stayed flat against that number because the tooling could only measure exposure to training, not propensity to fail.

Human risk management platforms change the unit of measurement. Instead of “percent trained,” you get a per-user, per-group risk score built from real signals — simulated and real phishing responses, credential hygiene, data-handling events, unsanctioned tool usage. That last one matters more every quarter: employees pasting source code and customer data into consumer AI tools is now a top-three human-risk vector, and it is invisible to an LMS. Our shadow AI risk and policy analysis covers why policy documents alone fail there, too. The takeaway for the boardroom: HRM turns the human layer into something you can score, trend, and defend in front of an audit committee. Awareness training never did that.

KnowBe4: the incumbent rebuilds in place

KnowBe4 is the reference point for this transition because it built the old category and is now trying to own the new one. Its strengths are real: the largest installed base in the segment, a deep and frequently refreshed content library, mature phishing simulation at enterprise scale, and — since the Vista take-private — an aggressive product cadence. The HRM+ platform bundles awareness training, cloud email security, real-time coaching, crowdsourced anti-phishing, and the AIDA agent suite into a single risk-scoring fabric. AIDA Orchestration is the most consequential piece: it moves campaign design from the admin console to an autonomous agent that adapts to each user’s risk profile. For a lean security team running a 20,000-seat program, that is a genuine operational shift, not a feature bullet.

The honest caveats. KnowBe4’s behavioral-science depth has historically trailed the specialists — CybSafe and Living Security led Forrester’s first HRM Wave on exactly that axis. Its risk scoring is strongest inside its own telemetry; organizations wanting scores fed by their EDR, IAM, and DLP stack should scrutinize integration depth rather than accept the dashboard at face value. Private-equity ownership cuts both ways: faster roadmap, but also bundle-heavy packaging and renewal pricing that rewards buyers who negotiate hard. And some long-time customers describe the culture of the product as phishing-first — if your risk model says your exposure is data handling or shadow AI rather than email, test that the platform measures what you actually care about. KnowBe4 fits enterprises that want one throat to choke and a fast path from legacy SAT to HRM. It fits less well where behavioral-science rigor or stack-wide risk aggregation is the buying criterion.

SAT vs HRM — the real differences

Strip the branding and the two models differ on six axes. The verdict: if a product cannot score individual risk from multiple live signals and intervene in the moment of risky behavior, it is SAT — whatever the datasheet says.

Security awareness training (legacy)Human risk management (current)
CadenceAnnual modules, quarterly phishing testsContinuous scoring, always-on micro-interventions
Data inputsCourse completions, simulation clicksEmail, identity, DLP, SaaS and browsing signals, real incidents
Core metricCompletion rate, click ratePer-user and per-group risk score, trended over time
InterventionAssign more training after failureReal-time nudge at the moment of risky action
AI roleContent generation, if anyAutonomous agents targeting, scheduling, adapting per user
Audit story“Everyone completed training”“Human risk decreased X percent in these cohorts”

The buyer checklist: rebadged SAT or real HRM

Every SAT vendor now uses the HRM label. Category transitions always produce this — buyers search the old term, vendors relabel, and the datasheets converge while the products do not. Ask these five questions in the demo and make the vendor show, not tell:

  • Signal breadth. How many non-simulation data sources feed the risk score today — identity provider, EDR, DLP, SaaS usage? Fewer than three live integrations means the “score” is a phishing-click average wearing a costume.
  • Real-time intervention. Can the platform nudge a user at the moment they forward a sensitive file or paste data into an unsanctioned AI tool — or does it only assign a course afterward?
  • Agent autonomy with guardrails. If AI schedules training and simulations (as KnowBe4’s AIDA Orchestration does), what does the approval workflow look like, and can you audit every decision the agent made?
  • Outcome reporting. Demand a live report showing risk-score change over 12 months for a real (anonymized) customer cohort — not a mock-up.
  • Pricing model. Per-user-per-year is standard; watch for agent features gated behind top-tier bundles. As of mid-2026, list pricing varies widely and discounts of 20–40 percent off list are routine at enterprise volume — treat the first quote as an opening position.

What to do about it

If your renewal is more than nine months out: instrument now. Get baseline per-user risk data from the signals you already own — secure email gateway, identity logs, DLP — so you can evaluate HRM platforms against your real behavior profile instead of a vendor demo. If renewal is imminent: sign short. A one-year term with an HRM pilot rider beats a three-year SAT commitment at a discount, because the category will look different again by 2028. Incumbents like KnowBe4 will argue the migration path is easiest inside their platform, and for their installed base that is often true — but make them price the agent tier against the specialists’ quotes, and benchmark your program against real numbers like the 2026 click-rate data before accepting any vendor’s definition of “improved.” The one-sentence version for your next steering meeting: stop buying training completions, start buying measured risk reduction, and make every vendor prove the difference with your data.

Frequently asked questions

What is the difference between security awareness training and human risk management?

Security awareness training delivers scheduled educational content and periodic phishing simulations, measured by completion and click rates. Human risk management continuously scores each user’s actual risk from multiple live data sources and intervenes in real time — training becomes one intervention among several rather than the whole product.

Is KnowBe4 a human risk management platform?

KnowBe4 positions its HRM+ platform squarely in the category, combining training, cloud email security, real-time coaching, and its AIDA suite of AI agents. It is the segment’s market-share incumbent; buyers should still verify integration depth and behavioral-science capability against specialists such as CybSafe or Living Security, which led Forrester’s first HRM Wave.

What are the main KnowBe4 alternatives in 2026?

The vendors most often shortlisted against KnowBe4 include CybSafe, Living Security, Hoxhunt, SoSafe, and Mimecast’s engagement offering — each with a different center of gravity, from behavioral science to adaptive phishing to email-security bundling. Shortlist on which risk signals matter most in your environment, not on brand familiarity.

Does human risk management replace phishing simulations?

No — simulations remain a core signal, but they become one input to a risk score rather than the program’s headline metric. Modern platforms increasingly generate and schedule simulations autonomously, adapting difficulty per user instead of blasting one template to everyone.

How do I justify the cost of an HRM platform to the board?

Anchor on measured risk-score reduction across cohorts, tied to incident categories the board already tracks — credential compromise, data mishandling, shadow AI usage. A trended risk metric survives audit-committee scrutiny; a training completion percentage does not.

Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.