Guide | Human Risk Management

Reducing human cyber risk: a practical guide for Australian businesses

68% of data breaches involve the human element. Whether it is a phishing email that fools the wrong person, a password reused across accounts or a policy nobody has read, people are behind most incidents.

This guide explains what Human Risk Management (HRM) is, why traditional annual training is not enough, and how a structured, ongoing programme reduces the risk of a breach in your business.

68%
of breaches involve the human element
Verizon DBIR 2024
95%
of incidents involve human error or misuse
IBM Security 2024
36%
of breaches involve phishing
Verizon DBIR
220%
increase in dark web credential listings since 2022
usecure research
The problem

Why employees are an insider threat

Most incidents are not caused by sophisticated technical attacks. They are caused by ordinary people making ordinary mistakes, and by attackers who know exactly how to exploit that.

55%

Negligent insiders

Employees who make honest mistakes, like misdirecting an email, attaching the wrong file, or clicking a phishing link. The most common category, accounting for just over half of all security incidents.

25%

Compromised credentials

Employees whose usernames and passwords have been exposed on the dark web, often through a third-party breach. Attackers can use stolen credentials to access business systems without anyone noticing.

20%

Malicious insiders

Employees or former employees who intentionally misuse their access, from leaking data to selling credentials. Less common but often the most damaging.

Human error

A simple typo, the wrong recipient on an email, or an accidental file attachment can expose sensitive data and trigger a notifiable breach under the Australian Privacy Act. The consequences can include regulatory fines, loss of client trust and reputational damage.

Sending data to the wrong person
Attaching the wrong file
Reusing passwords across accounts
Failing to apply updates or patches

Phishing attacks

Phishing is the most common entry point for attackers. Modern phishing is increasingly convincing, with attackers using AI-generated messages, brand spoofing and targeted spear phishing to fool even cautious employees.

Spear phishing targeting senior staff
Business email compromise (BEC)
Domain spoofing and lookalike addresses
MFA fatigue and push notification attacks

Credential misuse

When employees reuse passwords across multiple accounts, one third-party data breach can give attackers access to business systems. Corporate credential listings on the dark web increased by 220% since 2022.

Password reuse across services
Credentials sold on dark web marketplaces
Shared accounts without individual tracking
Weak or default passwords left unchanged

No policies or processes

Without documented security policies, employees do not know who to report phishing to, who can access sensitive data, or what the rules are around personal devices. Policies are also required evidence for frameworks like SMB1001 and ISO 27001.

No acceptable use policy
No incident response procedure
No mobile device or BYOD rules
Staff unaware of their responsibilities
What is HRM?

Human Risk Management: going beyond annual training

Annual training on its own cannot keep pace with how fast threats evolve. HRM is the approach that replaces the one-off tick-box exercise with a continuous, measured programme covering four key areas.

Security awareness training

Short, regular courses assigned automatically to each staff member based on their individual risk profile. Courses cover phishing, passwords, remote work, social engineering and more. Automated reminders chase up anyone who has not completed their module.

User-tailored courses
Covers essential security topics
Automatic enrolment and reminders
Tracks completion and grades per user

Simulated phishing exercises

Realistic phishing emails sent to your staff on a rolling basis. When someone clicks, they receive immediate follow-up training rather than just a notification. Over time, your team gets measurably better at spotting and reporting attacks.

Identifies high-risk users
Tests a range of attack techniques
Automated campaigns and scheduling
Instant follow-up for anyone who clicks

Dark web monitoring

Continuous scanning for your business email addresses and credentials on dark web marketplaces. If a staff member's details appear, you find out before an attacker can use them to access your systems.

Detects breached credentials early
Identifies the source of exposure
Shows what data has been exposed
Flags early-stage threats before they escalate

Policy management

Security policies your staff actually read and sign. Ready-made templates for the essentials, delivered electronically with trackable acknowledgement. Automated reminders follow up anyone who has not yet signed.

Ready-made policy templates
Trackable electronic signatures
Automated reminders for unsigned policies
Centralised policy library
How it works

Tailored. Measured. Effective.

1

Evaluate

Every staff member completes a short gap analysis assessment. This identifies where each person's knowledge is weakest and creates an individual risk profile that drives what they are trained on first.

2

Educate

Training is automatically assigned based on each person's results, prioritising their highest risk areas first. New short courses roll out on a regular cadence, typically monthly, keeping knowledge current.

3

Calculate

Human risk scores are tracked over time, combining training completion, phishing simulation results and dark web exposure into a single ongoing measure. You can see exactly where risk is improving.

4

Demonstrate

When your insurer, auditor, or procurement team asks for evidence of staff security training, the reports are ready to go. No scrambling or manual collation needed.

Real-world results

What a proper HRM programme delivers

A 250-person construction business ran a managed HRM programme for seven months. Here is what changed.

Overall risk score

Start
270/900
Medium risk
7 months
118/900
Low risk

Key metrics

-152
Overall risk score
-100
Phishing risk score
97%
Course completion
92%
Average course grade

Phishing simulation performance

SimulationSentOpenedVisited linkCompromised
1st simulation14674409
2nd simulation17234 -74%4 -163%2 -127%

Between the first and second phishing simulations, the number of compromised staff dropped from 9 to 2. Phishing click and visit rates fell by over 74% and 163% respectively. Staff were completing courses within an average of 3 days of enrolment.

Best practices

Nine tips for reducing long-term human risk

These are the practices that separate a programme that compounds over time from one that gets forgotten after the first module.

Key training topics

  • Phishing attacks and social engineering
  • Passwords and authentication
  • Working securely from home
  • Secure internet and email use
  • Physical security
  • Mobile device security
  • Public Wi-Fi risks
  • Data handling and privacy

Phishing simulations to run

  • Microsoft Teams request from unknown contact
  • Office 365 password expiration notice
  • Deactivation of OneDrive account
  • Parcel delivery notification
  • HR policy update requiring acknowledgement
  • Fake bonus or gift card offer
  • IT helpdesk credential verification request
  • DocuSign document requiring signature

Essential security policies

  • Acceptable Use Policy
  • Confidential Data Policy
  • Email Policy
  • Mobile Device Policy
  • Incident Response Policy
  • Network Security Policy
  • Password Policy
  • Physical Security Policy
Culture change

Building a security-minded culture

Training and tools help, but lasting change requires the right culture. A security-minded workplace means every employee, from the receptionist to the CEO, understands that security is their responsibility.

Get support from leadership

Security programmes that start and stay with the IT team rarely get traction. Leadership needs to visibly back the initiative, communicate it regularly and allocate the budget.

Make it everyone's responsibility

Staff need to understand that cyber security is not just an IT problem. Every person with access to a system or a mailbox is part of the risk, and part of the solution.

Consistency over intensity

Consistent training over 12 months has been shown to reduce phishing susceptibility from 60% down to 10%. One-off sessions do not produce the same result.

Go beyond awareness training

Training reduces vulnerability, but you also need policies that are signed, simulations that test real skills, and monitoring that catches threats before they become incidents.

Time is the real barrier

Research consistently shows that security professionals who spend more time on awareness get better outcomes. The barrier is usually not budget, it is prioritisation.

Treat it as a long-term investment

HRM is not a project with an end date. It is an ongoing programme that sits alongside your technical controls, just like patch management or vulnerability scanning.

The platform we use

Powered by usecure

We run our managed HRM service on usecure, an MSP-first platform purpose-built for security awareness training, phishing simulations, policy management and dark web monitoring. It is the platform behind the results in this guide.

usecure|Human Risk Management platform

Security awareness training

Automated, personalised courses in 20+ languages. Assigned based on each user's individual risk profile.

Simulated phishing

Auto-campaigns with custom builder, message injection and regional templates. Instant follow-up for anyone who clicks.

Policy management

Ready-made templates with automated workflows, electronic signatures and a centralised policy library.

Dark web monitoring

Continuous domain-level breach monitoring. uBreach Pro available for advanced detection and domain scans.

Integrates with Microsoft 365 and Google Workspace with automatic user sync
Monthly billing, no seat minimums, flexible MSP pricing
Full white-label UI, domain and report branding
True multi-tenant MSP portal for managing all clients in one place
Zero installs, fast automated cloud setup
24/5 live chat support with approximately 5-minute average response time

G2 ratings (usecure)

92%
Usability
92%
Product implementation
96%
Ease of partnership
92%
SAT results score

"Being able to create custom training and content for my clients sets usecure apart. The uPolicy feature is a game changer for automated policy deployment, and no other product offers these features at this price."

Jason H. — via G2

"usecure is a dream for MSP management, with seamless M365 integration, user-friendly client management features and more."

Patrick K. — via G2

Ready to start?

Get a managed HRM programme running for your team

We run usecure HRM as a fully managed service, which means training, phishing simulations, dark web monitoring and policy management are all handled for you. No extra admin, no chasing staff manually, and real reporting you can show to auditors and insurers.