Skip to main content

Beyond Human Risk: A Better Way to Build Secure Behavior

September 23, 2026

Behavior change, not compliance, must be the goal. 

From the Product Desk — Lee Martin, Senior Director of Product Management

A large company once showed me its annual eLearning compliance module. Six figures to build. Ninety minutes to complete. Mandatory for everyone, worldwide. The learning objectives were spot-on. Someone who understood the work had clearly built-in what employees needed to learn.

What got built on top of those learning objectives was a slog.

Every group with a stake had its minutes on screen. Regional requirements. Interviews. Policies. The learning itself came second. 

They asked me what I would change. I told them. Then they explained why they couldn’t change it. The same stakeholders protected it. No one in the room thought the program was working particularly well, but they could prove completion.

That distinction has bothered me ever since.

We became very good at measuring security activity: completion, participation, simulation click rates and eventually risk scores. Those measures tell us something, but they don’t answer the question I care about most:

Are people actually getting better at recognizing and responding to phishing?

From awareness to risk

There’s a version of this argument that throws security awareness training under the bus. That isn’t my argument.

Awareness training has taken a beating during the last decade because proving its impact was hard. If someone clicked a real phish, the training must have failed. If nobody clicked, you still couldn’t prove which attacks the training prevented.

Human risk management was a logical response. Instead of measuring only training activity, organizations began bringing together more signals to understand where risk concentrated.

That was progress. Understanding risk matters, but identifying risk and changing behavior are different jobs. A risk score can tell you where to look. It cannot, by itself, tell you what someone needs to learn, whether they learned it, or whether they are getting better.

That is where I believe Secure Behavior Management changes the conversation.

We’re trying to build safer cars

Risk scoring has always reminded me of insurance.

Insurance is very good at measuring danger. Insurers study crashes, price outcomes and rate vehicles. But cars became safer because engineers used what they learned to build better cars: crumple zones, airbags, anti-lock brakes and countless improvements most drivers never think about.

Measurement created insight. Engineering turned it into improvement.

Our goal in security shouldn’t be to build increasingly sophisticated ways to label people as risky. Instead, the goal should be to understand where people are capable, where they have gaps, and what we can do to make them better prepared for the threats they actually face.

We’re trying to build safer cars.

Start with what people need to know

If behavior change is the goal, the first question isn’t Who is risky?

It’s What does someone need to know to recognize a threat?

Phishing emails reveal themselves through patterns: urgency, requests for sensitive information, mismatched sender details, suspicious language or a business process that feels almost right because an attacker has learned enough to imitate it.

Some indicators appear across many types of phishing. Others belong to a specific attack. Knowing the difference is what separates someone who remembers one phishing example from someone who can recognize threats they haven’t seen before.

At Cofense, we think about that as competency.

Competency gives us a way to understand what someone knows across the phishing threats and indicators we are preparing them for. And our instructional design team knows exactly what they are, across twenty-six threat topics. At an organizational level, it can show where knowledge is strong, where gaps exist and where a security program should focus next.

That is considerably more useful than knowing what percentage of people completed a campaign.

But competency is still only one part of the picture.

Simulation and real behavior are not the same thing

This distinction between simulation and behavior matters because our industry has blurred it for years.

A phishing simulation is training.

It is a rehearsal we run intentionally so someone can practice recognizing a threat and learn when they miss one. Rehearsals are valuable, but simulations are not the same as observations of behavior when a real malicious email reaches the inbox. Those are different, equally important, signals.

Competency tells us what someone has demonstrated that they know. Real-world behavior tells us what happens when phishing gets through.

Did someone recognize the threat? Did they report it? What actually reached the inbox? What did the organization do next?

Understanding both is essential if the goal is genuinely to improve phishing defense.

This is where Cofense approaches SBM differently

That distinction is particularly important to us because Cofense already operates on both sides of that equation. We help organizations prepare employees using phishing simulations and education informed by the kinds of threats they actually face. 

And when real phishing bypasses preventative controls and reaches employee inboxes, Cofense helps organizations see what was reported, understand the threat and remediate it.

Historically, those have been separate pictures. One showed what happened during training. The other showed what happened during an attack.

Our approach to Secure Behavior Management connects them.

Cofense delivers measurable competency so organizations can understand what employees know and where gaps exist, while bringing that understanding together with the real-world phishing and remediation signals generated across the Cofense platform.

The goal isn’t another score. It is a more definitive answer to a much more useful set of questions:

What do our people know? Where are the gaps? What happens when a real threat reaches them? And what should we do differently as a result?

Measurement should lead somewhere

There are two principles I keep coming back to as we build Cofense solutions.

First, measurement needs context. A percentage without the underlying count can mislead as easily as it informs.

Second, every measurement should help somebody make a better decision.

If someone is struggling to recognize a particular type of phishing attack, that may be a learning problem. If someone is being bombarded with sophisticated real-world threats, that may be a protection problem.

Those are not the same problem, and assigning more training to both people isn’t an answer.

The measurement exists to produce an action. Otherwise, we have simply built a more sophisticated way to describe risk.

The next step

The remediation side of Cofense has always been able to show its work. A threat landed in an inbox. We identified it. We investigated it. We took a remediation action.

Training has historically had a harder measurement problem. We could show activity and simulation outcomes, but it was much harder to show what people actually knew and where they were less susceptible.

That is changing.

Competency measurement gives us a stronger foundation for understanding whether people can recognize phishing. Connecting that view with real-world phishing and remediation signals will give organizations a richer, actionable understanding of their phishing defense program performance.

That is how we approach Secure Behavior Management. It’s the way to measure what people know, understand what happens when real threats reach them, and use those signals to strengthen phishing defense over time.

It’s why I’m excited about the Cofense Command Center. In October, I’ll go deeper into the first part of that work: how we are measuring competency, what the Competency Dashboard tells security teams, and where we are taking it next.

Because ultimately, the question isn’t whether we measured more.

It’s whether anyone got better.