
Human Risk Management is now Secure Behavior Management. We think Gartner is right.
Sep 24

Flavius Plesu
Founder & CEO, OutThink | Former CISO (Bank of Ireland) | Pioneering Human Risk Management | Author, "The End of Security Awareness As We Know It" & the HRM Maturity Model
View ProfileIn March 2026, Gartner introduced “Secure Behavior Management” (SBM) as its name for the market the industry had been calling human risk management (HRM): the platforms organizations use to understand how their people behave, influence those behaviors, and reduce the risk that follows. Richard Addiscott, VP Analyst, set out the reasoning on 30 April 2026 in the Analyst Take “Why It’s Time to Drop ‘Human Risk Management’ as a Market Name”.
OutThink was among the first vendors to call its platform an HRM platform. We think Gartner is right. Here is why.
What Gartner actually changed
One point gets lost in most retellings: HRM was never Gartner’s term. Forrester introduced it, and the market picked it up. Gartner’s own formal name for this space was security awareness computer-based training, or SACBT. So the change in March was not Gartner overturning its own label. It was Gartner choosing a name for a market that had spent several years labeling itself, and declining to adopt the one the industry had settled on.
Gartner’s objection to HRM is one it has stated publicly, and it is the right one. If the goal is to get employees to adopt more secure behaviors, opening by describing them as risks works against you. Addiscott has been blunter in public, calling HRM “a great example of how the cybersecurity industry sometimes gets in its own way.”
When I started writing this, the name was the only thing that had changed. That is no longer true. On 22 September 2026 Gartner published research under the new label: Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management, by William Candrick and Alex Michaels. It treats security awareness and training as antiquated and commoditized, positions SBM as what replaces it, and includes a representative list of SBM vendors. We wrote about that recognition separately.
And the ground was prepared years ago. Gartner developed the Security Behavior and Culture Program concept, an enterprise-wide approach to reducing incidents connected to employee behavior, then built the Gartner PIPE Framework (practices, influences, platforms and enablers) as the model for running an SBCP, and has kept publicly publishing tooling and research around both. SBM is not a new idea looking for substance. It is the market name arriving to sit on top of work that was already there.
Why I think Gartner is right
We called OutThink an HRM platform when almost nobody else was using the term. Seven years on, the analyst firm that shapes how CISOs build shortlists has decided that name is the wrong one for this market. On the face of it, we have more to lose from that than most. But I think Gartner has made the right call.
We did not adopt HRM because it was the most ideal category name. We adopted it because it was the only one (at the time) that described what we were building. The alternative was security awareness training, which described the thing we were arguing against: courses, completion rates, an annual tick. HRM at least moved the conversation from what people had been taught to what they actually did. So we took the label, with reservations about the label that I never quite lost. The work was always right. The words were always wrong. Employees are not liabilities to be risk-managed away. They are the people whose behavior we are trying to influence, support and equip, and language that casts them as the threat works against the thing we are asking them to do. You cannot open a multiyear change program by telling people they are the problem and then ask for their cooperation.
Angela Sasse, OutThink’s chief scientific advisor, published a paper with Anne Adams in Communications of the ACM in 1999 called “Users Are Not the Enemy.” Its argument was that when people work around security controls, the fault usually sits in the design of the control rather than in the character of the person. Peer reviewed, twenty-seven years ago. My own MSc thesis on human factors in cybersecurity followed in 2013. The case Gartner has now adopted has been in the literature for a generation. The market name is finally catching up to it.
Then there is the part that matters more than the semantics.
HRM made risk the unit of measurement. But risk is not something you observe. It is something you construct: you take a set of inputs, weight them, and produce a number that did not exist until you built it. Two HRM platforms can look at the same workforce and disagree entirely, and both be internally consistent.
Whatever goes in, what comes out is an estimate. And there is nothing wrong with an estimate. Security runs on probability. The problem is when the estimate is the only thing the platform can show you, because then there is no path back to a fact.
SBM makes behavior the unit, and a behavior is deterministic. It either happened or it did not. Someone shared the file or they did not. Reported the email or did not. Changed how they handled a request after being nudged, or carried on as before. That is a less forgiving thing to measure, because you cannot assemble it out of assumptions. But you have to be able to “see” it!
Which is where this stops being a naming exercise. The label changing is the easy part. The architecture is the harder one, because a platform that cannot “see” behavior cannot manage it.
One market, four names
Some of the confusion here has nothing to do with the rename. This space has accumulated vocabulary for over a decade, and almost nothing has ever been taken out. Two analyst firms cover it, each with its own market taxonomy, and one term in wide circulation is not a market name at all.
| Term | Origin | Introduced | What it names | Status |
|---|---|---|---|---|
| SACBT - security awareness computer-based training | Gartner | In use well before 2020 | The market for platforms delivering training and simulated phishing | Legacy, superseded by SBM |
| SA&T - security awareness and training | Forrester | In use well before 2020 | Forrester's name for broadly the same market | Retired in 2024 |
| HRM - human risk management | Forrester | Vision published 2022, formal market name from 2024 | A market of platforms that detect and measure security behaviors and quantify the risk attached to them | Current, Forrester's market name |
| SBM - Secure Behavior Management | Gartner | March 2026 | Gartner's market name for the platform category, replacing SACBT | Current, Gartner's market name. Research published September 2026 |
| SBCP - Security Behavior and Culture Program | Not a market name. A program your organization runs, using the Gartner PIPE Framework as its operating model. Introduced by Gartner in November 2022 and unaffected by the rename. SBM is the software category you buy to run it. | |||
SBCP is the one people conflate with the rest, so it is worth being explicit. It is the program; SBM is the software category you buy to run it. An organization runs an SBCP and procures an SBM platform. Nothing about the rename changes that relationship, and if you have built your program around PIPE, none of that work is affected.
The other useful thing to read off the table is that both firms have been describing the same shift for years, in their own vocabulary: away from training people and reporting on completion, toward changing behavior and measuring whether it changed. Forrester made that argument under the HRM banner from 2022. Gartner made it through SBCP from the same year. The disagreement is about what to call the market, not about where the market is going. Practically, that means anyone maintaining a vendor shortlist will be working with both terms for a while.
What this changes if you are buying
Less than you might expect, at least in the short term. Your requirements do not need rewriting because a label changed. Capability requirements are unaffected. Evidence expectations are unaffected. A vendor that met your criteria in February still meets them.
What has changed is the standard of proof. I was going to argue that the market is further behind than the rename implies, and I should have declared an interest before doing it, because we sell into this market. Gartner got there first.
The September research is blunt about it: AI hype, startup funding and refreshed roadmaps from established vendors generate more marketing noise than reliable signal, and buyers are told to treat vendor risk scores with caution because those scores are biased toward the data and features the platform itself offers. It recommends live proofs of concept over vendor assurance, and warns that adopting the wrong solution or switching on AI features too early can backfire badly.
This is not new for Gartner either. Its 2022 research on Security Behavior and Culture Program capabilities described the training market as having settled into a stable, largely commoditized set of features that satisfied compliance without sufficiently influencing behavior. Four years on, the newer research says the gap is now being filled faster with marketing than with capability.
None of which means reopening a live procurement. It means the rename is a reasonable moment to ask the field a harder question than the one most RFPs contain. Not what can you simulate, but what behavior can you show me changed, in what system, on whose evidence.
Beyond that, what changes is language, in three places. Your own documents will increasingly read as dated in HRM terms, and one line noting the market is also called Secure Behavior Management saves explaining later. Vendor responses will be inconsistent for a while, and that inconsistency tells you nothing about capability. And analyst tooling, peer review sites and directories will lag the rename, so searching one term gives you an incomplete field.
Worth expecting the term to reach you from your analyst and your peers before it reaches you from most of your suppliers. Category names travel down from research and across from other buyers faster than they travel up from vendors, most of whom have a website, a deck and a category page to rewrite before they can move.
What the new name actually asks of a platform
I want to be careful not to overclaim the rename. A market name obliges nobody to build anything.
But it is a more accurate name. Human risk management described an output: a number, produced by a vendor, about a person. You can deliver that from phishing results and training records without ever observing a real behavior. Secure behavior management describes something harder. A behavior happens, in a system, at a particular moment, and either the platform can see it or it cannot.
That problem is not new. It has been the gap in this market for a decade, long before anyone changed the name. The platforms that defined the awareness era were built to test compliance and report on it, and they did that well. A secure behavior management platform has to do four things:
Understand each person. Not their department and their language, but their role, their exposure, what is actually being aimed at them, and what they have done before.
Adapt to them. Content, difficulty and timing that respond to that individual rather than to an annual calendar.
Intervene at the moment that matters. Correction delivered close enough to the behavior to be connected to it. A quarterly module is not an intervention.
Feed behavioral signal back into the security stack. Into self-remediation, the SOC, GRC, conditional access. A behavioral measure that only exists inside the vendor’s own dashboard has not entered the security program.
None of that is far-fetched. It is what the research literature has been asking for since long before this market had a name it could agree on. What has changed is that the name no longer gives anyone cover for not doing it.
The gap shows up most clearly in what a platform can answer. Most can tell you who completed training. Very few can tell you that forty-two people in Finance stopped using an unapproved file sharing service this month, because they never had the signal to know. That is the difference between measuring activity and measuring outcome, and it is why the honest answer to “is human risk falling” has for years been that nobody could say.
I wrote the long version of this argument, level by level, in The End of Security Awareness As We Know It. If you want the practitioner’s view of what closing this gap involves, start there.
The scoring problem
There is a third thread in this, and it is the one I most want to engage with.
Gartner has put an open invitation to CISOs and the vendor community: to work out a universally adopted way of measuring an individual’s contribution to their organization’s security posture. Not a vendor’s proprietary index. Something the industry could agree on.
It is the right question, and the reason it is worth asking is that the scores we have now do not work.
The problem is what feeds them. Most vendor risk scores are built almost entirely from data that vendor’s own product generated: phishing test results, training completion, reporter rates, maybe role or whether an email turned up in a breach dump. That is a closed loop. People are being scored on how they performed on tests administered by the platform doing the scoring. It measures behavior in artificial conditions and reports it as risk. It is like assessing someone’s driving from how well they play a racing game.
Gartner now says a version of this to buyers directly, warning that there is no industry standard for these scores and that they are biased toward the data and features the vendor’s own platform provides. Which is also why they get ignored where it counts. No SOC will triage on them. No IAM team will gate access with them. No GRC function will put them in a risk assessment. The security awareness manager ends up with a number that is hard-won, defensible nowhere, and acted on by nobody.
A measure that deserved to be adopted industry-wide would need to draw on what actually determines exposure: real behavior from the security stack, the attitudes behind it, how much access the person has, how heavily they are actually targeted, the state of their device, the conditions they work under. And it would need to be framed so the person can see it, understand what moves it, and want to move it. Most scores are built to be reported. Very few are built to be improved.
That is what we built CyberQ for. A cybersecurity quotient, unique to the individual, designed to be improved rather than merely reported. We have been working on it for years, long before the rename. And I am not going to pretend it is the industry-wide standard Gartner is asking for. It cannot be. A universal measure cannot be one vendor’s product, by definition.
But the questions underneath it are the ones worth arguing about in public, and they are the practitioner’s questions rather than the vendor’s. What data feeds the score? Can I trust it enough to act on it? And how do you stop yourself measuring what is easy to measure rather than what actually matters?
And then there are the agents
Right now this market is about people. That will not hold. Organizations are deploying AI agents that plan, act and make decisions across workflows, and every one of them operates on authority delegated by a human. They can reach data, invoke tools, and take consequential actions in sequences that are difficult to reconstruct afterwards.
The tools being built for this today work at the infrastructure layer: runtime firewalls, identity governance for non-human identities, agent discovery. They can tell you that an agent accessed a database at three in the morning. What they cannot tell you is whether that was normal, given who the agent was acting for, what that person’s own risk portrait looks like, and what the pattern of behavior around it has been. That is not an infrastructure question. It is a behavioral one, and it will need answering with the same discipline we apply to people.
Try describing that under the old name. Human risk management can just about stretch to cover an employee. It cannot stretch to cover a software agent acting on that employee’s behalf, because there is no human in the loop to be the risk. The phrase runs out. Secure behavior management does not, because the thing being managed is the behavior.
Where we go from here
We agree with the new name and we are adopting it. From here, when we write about where this market is going, we will write about secure behavior management.
We are not renaming everything overnight. Buyers are mid-procurement with HRM in their requirements documents, Forrester still uses HRM as its market name, and most of the search traffic in this category still goes to the old term. So you will see both from us for a while, and the reason is that you are probably working with both too.
One last thing, since this is a piece about a name and I would rather not pretend the name is what matters. We spent seven years arguing that this category was about behavior rather than about labelling people as risks. An analyst firm has now put that argument in the market’s own vocabulary, and published research telling CISOs to act on it. There is more coming: the vendor evaluations, and the arguments about what should count as evidence. We intend to be in all of them.
One of our four company values is eternally pioneering. This is what that looks like in practice: agreeing with the person who just told us our own category name was wrong, and getting on with the work.
Common questions
Sources
Gartner
Analyst Take: Why It’s Time to Drop “Human Risk Management” as a Market Name. Richard Addiscott, 30 April 2026, ID G00853891. Gartner subscription required.
Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management. William Candrick and Alex Michaels, 22 September 2026, ID G00860839. OutThink is included in its representative list of SBM vendors. Gartner subscription required.
Innovation Insight on Security Behavior and Culture Program Capabilities, 16 November 2022, ID G00776704. Subscription required. OutThink was named a representative provider in this research.
Gartner’s public overview of Security Behavior and Culture Programs and the Gartner PIPE Framework is available at gartner.com.
Forrester
Forrester introduced its vision for human risk management in 2022 and formalized HRM as a market name in 2024, retiring security awareness and training (SA&T). See The Human Risk Management Solutions Landscape, Q1 2024, and The Forrester Wave: Human Risk Management Solutions, Q3 2024.
Research
Adams, A. and Sasse, M.A. (1999) Users Are Not the Enemy. Communications of the ACM, 42(12), 40 to 46.
Speak with our HRM Specialists
Related Articles

OutThink Recognized in Gartner's Secure Behavior Management Research
Read More
Cybersecurity Simulation Training: Attack Types, Best Practices, and Metrics That Prove It's Working
Read More