Human-Centric Security Strategy: Designing for the People You Actually Have
Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.
Over 90% of employees who took unsafe actions knew the risk. See why the awareness-action gap is a design problem, where friction sits, and what to measure.
A human-centric security strategy puts the individual at the centre of control design, rather than the technology or the threat. Gartner’s research explains why. More than 90% of employees who admitted taking unsafe actions at work already knew those actions raised risk. They did them anyway.
Table of Contents
ToggleThe term gets used loosely, so it is worth pinning down. Human-centric security design models controls around the individual rather than around the technology, the threat, or the location.
That is a design principle, not a training programme. It asks a different question when a control is built. What will this cost the person using it forty times a day? And will they route around it?
Gartner predicted in 2023 that through 2027, half of CISOs would formally adopt human-centric design practices to minimise operational friction and maximise control adoption. By 2030, it projected, 80% of enterprises would run a formally defined and staffed human risk management programme. In 2022 that figure was 20%.
Neither prediction is about awareness content. Both are about how security is built. Related ground appears in why people remain the largest attack surface.
One Gartner finding should reshape most security budgets, and it rarely gets quoted.
Of employees who admitted undertaking a range of unsecure actions during work activities, more than 90% knew those actions would increase risk to the organisation. They did them anyway.
Sit with that. The gap is not a knowledge gap. Nine out of ten people who did the risky thing understood it was risky at the time they chose it.
So the instinctive response, more training, addresses a constraint that was not binding. You can raise knowledge from 90% to 95% and change almost nothing, because knowledge was never what stopped them.
The situation stopped them, or failed to. A deadline. A broken process. A secure path that took eleven minutes when the insecure one took ten seconds. Dark Reading’s summary of the human-centric model makes the same point about meeting people where they are.
Discover how Threatcop protects your workforce from modern cyber threats.
The distance between what employees know and what they do has a name and, now, a number. It also has a cause that most programmes misdiagnose.
Treat it as an education failure and you buy more content. Call it a motivation failure and you add consequences, which suppresses reporting. Diagnose it as a design failure, however, and you start asking why the secure option loses.
The third diagnosis fits the evidence. When someone who knows better still takes the shortcut, the shortcut was winning on something they were measured against, usually speed.
That reframing has a practical edge. Security teams control the friction in their own processes far more directly than they control anyone’s diligence at 3 pm on a Friday.
Most organisations have never inventoried this, and the exercise is cheap.
| Secure path | Common friction | What people do instead |
|---|---|---|
| Reporting a suspicious email | Multiple clicks, no feedback, fear of wasting analyst time | Delete it and move on |
| Requesting access properly | Ticket queue measured in days | Borrow a colleague’s credentials |
| Using the approved file transfer | Size limits, external recipients blocked | Personal cloud drive |
| Verifying an unusual payment request | No defined callback procedure | Act on the email |
| Getting a tool approved | Procurement cycle longer than the project | Install it anyway |
| Reporting their own mistake | Unclear whether it triggers discipline | Say nothing and hope |
Scoring approaches for spotting these patterns appear in why an employee risk score matters. Every row is a place where the organisation made the safe option expensive. None is fixed by a module.
The last row deserves separate attention, because it is the one that compounds. An employee who stays quiet about a mistake removes the organisation’s cheapest source of early detection, and they do it for a rational reason.
Three shifts follow, and all are operational rather than cultural.
Measure friction alongside compliance. If you track how many people completed training, also track how long it takes to report a suspicious message and how many clicks it costs. The second number predicts behaviour better than the first.
Remove controls that no longer earn their place. Every control has an ongoing cost paid in attention, and controls accumulate faster than they get retired. An annual cull is a security measure, not an administrative one.
Design the reporting path to be faster than the alternative. When reporting takes one click and ignoring takes zero, you have roughly parity. When reporting takes four clicks, you have chosen the outcome. Mechanics appear in why employees stay silent about mistakes.
Gartner framed a related change: the CISO moving from control owner to risk-decision facilitator.
The reasoning is unavoidable. Gartner also expected three-quarters of employees to acquire, modify, or create technology beyond IT’s visibility by 2027, up from 41% in 2022. A function that owns every control cannot hold that line, because most technology decisions now happen outside it.
Facilitating risk decisions means something specific. The business unit chooses, with the security consequences made legible, and the choice is recorded. Security stops being the department that says no and becomes the one that makes the trade-off visible.
That is a harder job, not an easier one. It requires the security team to quantify what a decision costs, which is the work most programmes skip.
Order matters, because each step makes the next cheaper.
Step 3 is the one that gets skipped, and skipping it means the training competes against the same broken process that produced the behaviour.
Threatcop’s TSAT covers step 1, scoring exposure per employee across email, voice, SMS, and QR vectors. The population you train is then the population the evidence names. Measurement approaches sit in what simulation results actually tell you.
Completion rate describes administration. These describe the strategy.
The fourth is unusual and worth adopting. A friction backlog makes visible the work that human-centric design actually consists of, and it gives a board something to fund that is not another content library.
Pick the process you most want employees to follow, and time it end to end as an ordinary employee experiences it. Count the clicks. Then time the insecure alternative.
If the second is faster, you have found the reason your training is not landing, and no amount of additional content will close that gap.
Fix that one path first. Then train the population your measurements name rather than the whole workforce, because targeting only works once the secure route is worth taking.
A human-centric security strategy designs controls around the individual rather than around the technology, threat, or location, with the aim of minimising operational friction and maximising control adoption. Gartner predicted in 2023 that through 2027, 50% of CISOs would formally adopt these practices. It is a design approach rather than a training programme.
Because knowledge is usually not the binding constraint. Gartner research found that more than 90% of employees who admitted taking unsecure actions at work knew those actions increased organisational risk and took them anyway. Where people already know and still choose the shortcut, additional content addresses a gap that was not causing the behaviour.
The awareness-action gap is the distance between what employees know they should do and what they actually do under time pressure. Evidence suggests it is primarily a design problem: the secure path costs more time or effort than the insecure one, so people route around it. Reducing that cost changes behaviour more reliably than raising awareness further.
Measure behaviour and friction rather than completion. Useful metrics include time and clicks required to report a suspicious message, and reporting rate including self-reported mistakes. Track exposure score distribution across the workforce too. Add the backlog of secure paths slower than their insecure alternatives, and controls retired per year.
Human risk management absorbs it. Training remains one component, alongside behavioural measurement, friction reduction, reporting design, and control retirement. Gartner projected that by 2030, 80% of enterprises would have a formally defined and staffed human risk management programme, up from 20% in 2022, which implies a function rather than a course.

Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.
One vendor's ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack,...
AI writes half of all code and fails security tests 44% of the time. See the failure profile, why...
AI-to-AI communication already runs on MCP and A2A, and neither mandates an audit trail. See how each fails, and...
Table of Contents
×