Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

Human Risk Management and Security Awareness

Build a security culture that empowers your people, not just your systems.

Human Risk Management

Most security incidents trace back to people, not technology: a clicked phishing link, a misjudged request, a shortcut taken under pressure. Human Risk Management addresses that directly, not by blaming staff, but by changing behaviour and building a secure culture that supports them. Your people are often your biggest vulnerability. We help you turn them into your strongest defence and create a secure culture that lasts.

Beyond tick-box training

Annual awareness training that everyone clicks through changes very little. We focus on genuine behaviour change, through targeted training, realistic phishing simulation, and addressing the specific human risks your organisation faces, so good security becomes the natural way people work.

Creating a secure culture

The goal is a workplace where security is understood and valued at every level, from the front line to leadership. Depending on the level you choose, this extends to a bespoke security culture programme, leadership coaching, and ongoing campaigns that keep awareness alive rather than letting it fade after one session.

What this reduces

Phishing and social engineering susceptibility, insider risk, and the everyday human errors that lead to breaches. The result is measurable improvement in how your people recognise and respond to threats.

We start by understanding your human risk

Effective security awareness training begins with knowing where your real risks lie. Different teams face different pressures: finance staff are targeted with payment fraud, senior people with impersonation, and busy front line teams with urgent requests that invite shortcuts. At Silver level we assess human behavioural risk in priority areas, and at Gold level across the whole organisation, looking at how people actually handle email, data, passwords and requests, and where your culture makes secure choices easy or hard. That assessment shapes everything that follows, so training focuses on the behaviours that matter most for you rather than generic content. It also gives you a starting point to measure against, so progress can be seen over time through simulations, reporting behaviour and feedback from your teams, not just course completion records.

Phishing simulation, done fairly

Simulated phishing is one of the most useful tools in human risk management, but only when it is handled with care. Delivered with our partner Citation Cyber, campaigns can reflect the kinds of messages your people genuinely receive, at a level of difficulty that suits where they are. The aim is learning, not catching people out. Someone who clicks should be met with helpful guidance, never public naming or disciplinary action. Lures that play on real distress, such as fake bonus or redundancy messages, are best avoided, because they damage trust far more than they teach. Results are reported to show trends and where extra support is needed, and follow up training can then be targeted at those areas. Handled this way, staff come to see simulations as practice rather than a trap.

Making it easy to report

A quick report is often worth more than a perfect record of never clicking. When someone spots a suspicious email or an odd phone call, or realises they have made a mistake, how fast they tell someone can decide how much harm follows. People only report quickly if it is simple to do and they trust they will be thanked rather than blamed. We help you build that reporting culture: a clear and easy route for raising concerns, a consistent and positive response when people use it, and feedback so staff can see their reports make a difference. Reporting is also a better sign of a healthy culture than training completion, because it shows people are alert and engaged in their everyday work, which is where security is really won or lost.

Leadership sets the tone

Staff take their cue from the people they report to. If senior leaders skip training, ask for exceptions to security rules or treat incidents as someone else's problem, the rest of the organisation notices. When leaders talk about security openly, follow the same rules and respond calmly to mistakes, secure behaviour becomes part of how the organisation works. Leaders are also frequent targets themselves, because their authority makes impersonation and urgent payment requests more convincing. At Gold level, our programme includes one-to-one coaching for leadership on fostering a security-first culture, alongside a bespoke culture programme and ongoing campaigns. We support organisations in Sussex, London and across the UK, and much of our work is delivered remotely, so your leadership team can take part wherever they are based.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

Behaviour change and security culture development to reduce human risk. Covers security awareness, phishing and social engineering resilience, insider risk, and building a lasting security culture. Your people are often your biggest vulnerability. We help you change that.

Pricing and tiers

Bronze
£1,500
  • One-hour online awareness training on phishing, social engineering and secure data handling
  • Template-based employee handbook on cyber security best practices
  • Email support for ad-hoc queries for three months
Silver
Enquire for pricing
  • Assessment of human behavioural risk in priority areas
  • Two 90-minute interactive sessions on advanced phishing, social engineering and insider threat
  • Tailored employee handbook with client-specific scenarios
  • One simulated phishing campaign with report and feedback, delivered with Citation Cyber
  • Access to a library of monthly security awareness materials
Gold
Enquire for pricing
  • Full human risk assessment and mitigation plan, established and implemented
  • Quarterly tailored training sessions on advanced topics
  • Multiple quarterly simulated phishing campaigns with analytics and follow-up
  • Bespoke security culture programme including gamified initiatives
  • Premium library of awareness resources and monthly campaigns
  • One-to-one leadership coaching on fostering a security-first culture

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

No. Phishing simulation is part of it, but Human Risk Management is broader: it is about changing behaviour and building a lasting security culture, covering social engineering, insider risk, and how your people handle data every day.

No, and that is important to us. The approach is supportive, not punitive. The aim is to empower your people to make good decisions, because a blame culture makes security worse, not better.

Through tools such as simulated phishing campaigns with reporting and analytics, so you can see how awareness improves over time, alongside the broader cultural change we help you build.

Human risk management is an approach to cyber security that identifies, reduces and monitors the risks created by human behaviour, such as falling for phishing, mishandling data or taking shortcuts under pressure. Rather than relying on a single annual course, it combines risk assessment, targeted training, simulation and culture change, so secure behaviour becomes a normal part of how people work.

Security awareness training is one part of human risk management. Traditional training often means an annual online module that measures completion rather than behaviour and is quickly forgotten. Human risk management starts from your actual risks, uses training, phishing simulation and culture work together, and looks for real changes in how people act. Training still matters, but it works best as part of that wider approach.

Common examples include clicking a phishing link, approving a fraudulent payment request, reusing passwords, sending personal data to the wrong person, sharing files too widely, using unapproved apps and plugging in unknown devices. Insider risk belongs here too, whether deliberate or accidental. Most of these come from pressure, habit or unclear processes rather than bad intent, which is why culture and training both matter.

Many insider incidents are accidental, so the starting point is clear processes, sensible access and a culture where people speak up. Our Silver level includes interactive sessions covering insider threat alongside social engineering, and the human risk assessment looks at where access, pressure or unclear responsibilities create exposure. We keep the approach supportive, because treating every employee as a suspect erodes the trust good security depends on.

It depends on the size of your organisation and how much support you need. Our Bronze level is £1,500 and includes online awareness training, a template employee handbook and three months of email support. Silver and Gold add behavioural risk assessment, phishing simulation, culture work and leadership coaching, and are priced to fit your organisation.

Interested in Human Risk Management?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation