More than six years after the General Data Protection Regulation (GDPR) took effect, many organizations have established mature compliance programs. Employees complete security awareness training, policies are documented and acknowledged, and Data Protection Officers regularly monitor and report on compliance. Yet data breaches continue to stem from the same underlying challenge: human risk. Whether through compromised credentials, excessive access privileges, or risky user behavior, people remain one of the greatest sources of cybersecurity risk to an organization's cybersecurity risk.
GDPR was never intended to be a documentation exercise. While training, policies, audits, and compliance records are essential components of a compliance program, the regulation also requires organizations to identify, assess, and reduce the risks associated with the people who access and process personal data. Compliance should not only demonstrate that security controls exist, but also that they effectively reduce risk.
This is the challenge Human Risk Intelligence (HRI) is designed to solve. By providing a continuous, data-driven view of human risk, HRI enables organizations to identify high-risk users, prioritize remediation efforts, and proactively reduce risk before it leads to a security incident.
In this blog, we'll explore how HRI gathers insights from security awareness training, phishing simulations, policy management, and dark web monitoring and helps organizations move beyond checkbox compliance and build a more proactive, risk-driven approach to GDPR.
Why Compliance Activities Aren't Enough
Recent cyberattacks demonstrate that documented compliance alone is not enough to prevent security incidents.
- In October 2023, a genetic testing company disclosed that attackers had compromised approximately 6.9 million user accounts through a credential stuffing attack. Rather than exploiting a firewall or leveraging a zero-day vulnerability, the attackers used credentials exposed in previous data breaches to access accounts where passwords had been reused. Multi-factor authentication (MFA) was not consistently enforced across the organization, and there was no continuous process for identifying employee or customer credentials already exposed on criminal marketplaces before attackers exploited them.
Despite maintaining a privacy program and a dedicated security team, the company faced regulatory investigations in the United Kingdom and Canada, as well as a settlement exceeding $30 million in the United States. - A similar pattern emerged the previous year during attacks against two major Las Vegas casino and resort operators. In those incidents, attackers never needed to steal a password. Instead, they contacted the internal help desk, convincingly impersonated an employee, and persuaded a help desk representative to reset MFA on a privileged account. One of the organizations reportedly suffered losses exceeding $100 million as a result of the attack.
In both cases, the root cause was not an unpatched system or a sophisticated technical exploit. It was human risk that had not been identified, prioritized, or addressed before attackers exploited those weaknesses. These incidents highlight an important reality: organizations can demonstrate strong compliance on paper while remaining vulnerable in practice, but without continuous visibility into human risk, organizations may overlook the very individuals and behaviors most likely to contribute to the next breach.
What Human Risk Intelligence Actually Measures
HRI provides organizations with a continuous, data-driven view of human risk. Rather than treating training completion, password hygiene, account activity, and access levels as separate reports maintained in separate tools, it correlates these signals into a single, continuously updated exposure profile for every individual in the organization. This profile is typically organized around four pillars.

No single pillar is inherently dangerous. An executive with broad access privileges is not unusual. Most employees will fail a phishing simulation at some point, and overdue password changes are common in large organizations. Individually, these factors may warrant attention, but they do not necessarily indicate elevated risk.
Risk becomes far more significant when multiple indicators converge around the same individual. For example, an employee with privileged access, poor password hygiene, repeated phishing failures, and outdated security training presents a substantially higher level of risk than any one of those factors would suggest on its own.
Understanding risk as the combination of multiple behavioral and technical factors is what separates a proactive risk reduction strategy from a traditional compliance program. As the following sections demonstrate, this principle underpins several of GDPR's key requirements and highlights why continuous visibility into human risk is essential for effective compliance.
Human Risk Intelligence · Article 32 & Recital 83

Article 32 is one of the GDPR provisions most frequently referenced during data breach investigations. It requires organizations to implement technical and organizational measures that are appropriate to the level of risk. In determining what is appropriate, organizations must take into account factors such as the state of the art, implementation costs, and the nature, scope, context, and purpose of their processing activities.
Recital 83 reinforces this requirement by stating that organizations should continuously evaluate the risks associated with processing personal data and implement measures to mitigate those risks. Together, these provisions make one thing clear: GDPR does not prescribe a static set of security controls. It expects organizations to continuously assess their risk and adapt their security measures as that risk evolves.
Recent breaches illustrate the consequences of failing to do so.
- In mid-2024, a series of cyberattacks impacted more than 100 organizations using a shared cloud data platform, including a major telecommunications provider and a global ticketing company. The platform itself was not compromised. Instead, attackers gained access by using credentials stolen in unrelated breaches against customer accounts where MFA had not been enforced. Most of the affected organizations likely had documented security policies. However, far fewer maintained a continuous view of which accounts lacked MFA while also having access to sensitive systems or data. This type of ongoing visibility into risk is precisely what Recital 83 expects organizations to establish.
- Another example occurred in January 2024, when a state-sponsored threat group linked to Russian intelligence compromised corporate email accounts at a major technology company, including those belonging to senior executives. The attackers gained initial access through an aging test account protected by weak security controls before exploiting excessive OAuth application permissions to maintain long-term access. The incident demonstrates that appropriate security measures must extend beyond production systems. Dormant accounts, forgotten test environments, legacy identities, and excessive application permissions can all create significant organizational risk if they are not continuously monitored and managed.
Perhaps the most overlooked aspect of Article 32 is that identifying risk is only the beginning. A risk score alone does not satisfy GDPR. Organizations demonstrate compliance when identified risks trigger concrete, measurable remediation actions, such as enforcing MFA for high-risk users, disabling dormant accounts, removing unnecessary OAuth permissions, or reducing excessive access privileges.
Equally important is the ability to demonstrate that those actions were completed and that the associated level of risk was reduced. This continuous cycle of identifying risk, prioritizing remediation, and verifying measurable risk reduction transforms HRI from a reporting dashboard into evidence of effective GDPR compliance.
Security Awareness Training & Phishing Simulations · Article 39
Security awareness training is a fundamental component of effective data protection in GDPR. Article 39(1)(b) identifies security awareness and employee training as one of the Data Protection Officer's core responsibilities, alongside monitoring GDPR compliance and conducting related audits. This reinforces an important principle: protecting personal data depends not only on technology but also on ensuring employees understand how to recognize and respond to security risks.
Despite this requirement, many organizations continue to rely on a one-size-fits-all approach to security awareness training. Annual training sessions delivered to every employee, regardless of their role or level of risk, may satisfy a compliance checklist, but they rarely produce lasting behavioral change. The key is not whether training exists, but whether it is relevant, timely, and reinforced often enough to influence behavior. Equally important is measuring its effectiveness through realistic phishing simulations rather than relying solely on knowledge-based quizzes.
Not every employee faces the same threats. A finance employee targeted by business email compromise (BEC) and invoice fraud requires different guidance than a new marketing hire or an IT administrator with privileged access. While Article 39(1)(b) does not prescribe a specific training methodology, it clearly expects organizations to demonstrate that employees become more security aware over time.
HRI transforms security awareness training from a compliance activity into a measurable risk-reduction strategy. It evaluates whether training is changing behavior by combining phishing simulation results, security awareness performance, and other risk indicators into an individual's overall risk profile. Training is considered successful not when it is completed, but when it leads to a measurable reduction in risk.
Policy Management · Article 24 & Recital 78
Article 24 places accountability for data protection squarely on the controller. It requires organizations to implement technical and organizational measures that are appropriate to the risks associated with their processing activities, taking into account the nature, scope, context, and purpose of processing. Importantly, these measures must include appropriate data protection policies.
Recital 78 builds on this requirement by encouraging organizations to establish internal policies that support the principles of data protection by design and by default. Together, these provisions make one thing clear: GDPR is not satisfied by simply documenting policies. Organizations must be able to demonstrate that those policies are embedded in day-to-day operations and evolve alongside changing risks.
This is where many policy management tools fall short. Policies are published, employees acknowledge them, and those acknowledgments are recorded. While this provides evidence that a policy exists, it does not demonstrate that the policy is being followed or that it remains appropriate as the organization's risk landscape changes. Article 24 expects organizations to ensure their policies actively support risk reduction.
HRI transforms policy management from a static compliance exercise into an operational security control. Rather than treating policy acknowledgments as isolated records, HRI correlates them with other indicators of human risk, including access privileges, security awareness performance, password hygiene, and user behavior. This enables security and compliance teams to identify not only who has acknowledged critical policies, but also whether high-risk individuals have failed to do so.
Policies also become dynamic rather than static. They can be reviewed and reinforced when an employee changes roles, receives elevated privileges, begins processing new categories of personal data, or exhibits behaviors that increase organizational risk. In this way, policies become living controls that adapt as the organization evolves. This distinction between documenting a policy and demonstrating that it influences employee behavior is central to the intent of Article 24 and Recital 78.
Dark Web Monitoring · Article 33 & 34
Early detection is critical to meeting GDPR's 72-hour notification requirement. Articles 33 and 34 of GDPR establish clear expectations for breach notification. Article 33 requires organizations to notify their supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the incident. Article 34 requires organizations to notify affected individuals without undue delay when a breach is likely to result in a high risk to their rights and freedoms.
Both obligations depend on one critical factor: timely detection. The 72-hour notification window does not begin when a breach occurs, it begins when an organization becomes aware of it. For many organizations, that is where the greatest challenge lies. In many cases, organizations learn about compromised accounts from external sources such as law enforcement agencies, security researchers, or customers reporting suspicious activity.
Continuous dark web monitoring helps close this visibility gap by providing early warning when corporate credentials appear in known breach repositories or criminal marketplaces. Instead of waiting for an attacker to exploit exposed credentials, organizations can identify potentially affected accounts, investigate the exposure, and take corrective action before the risk escalates.
This proactive approach supports GDPR compliance in two important ways. First, it enables organizations to identify potential incidents much earlier, improving their ability to meet the intent of Article 33's 72-hour notification requirement. Second, by detecting exposed credentials before they are used, organizations can often remediate the issue before it develops into a personal data breach that requires notification under Article 34.
Ultimately, dark web monitoring provides organizations with earlier visibility into credential exposure, enabling faster response, reducing organizational risk, and strengthening their ability to meet GDPR's breach detection and notification requirements.
Bringing GDPR Requirements Together Through Human Risk Intelligence

Although Articles 24, 32, 33, 34, and 39 address different aspects of GDPR, they all support the same objective: helping organizations continuously identify, manage, and reduce risk.
Rather than emphasizing one-time compliance activities, these provisions promote an ongoing, evidence-based approach to protecting personal data. Article 24 requires policies to be reflected in day-to-day operations. Article 32 requires organizations to continuously assess and mitigate security risks. Articles 33 and 34 require organizations to detect and respond to incidents quickly. Article 39 requires organizations to demonstrate that security awareness efforts are improving employee behavior.
Meeting these requirements depends on a common capability: maintaining a continuous, unified view of human risk across the organization. HRI provides that capability by bringing together security awareness, phishing performance, identity and access data, password hygiene, policy compliance, and other behavioral indicators into a single, continuously updated view of organizational risk. Instead of relying on disconnected reports from multiple security tools, organizations gain the visibility needed to prioritize remediation, measure improvements, and demonstrate that their security program is actively reducing risk, not simply documenting compliance.
Human Risk Intelligence: The Missing Layer in GDPR Compliance
GDPR was never intended to prescribe a fixed set of security controls. It was designed to remain relevant as technology and cyber threats evolve. More than six years of enforcement decisions have made the regulation's intent increasingly clear. Organizations are expected to continuously understand their risk, adapt their security measures accordingly, and reduce that risk before it results in a security incident.
HRI provides the operational capability to meet that expectation. It continuously correlates signals from security awareness training, phishing simulations, policy management, identity and access controls, password hygiene, and credential exposure to create a unified view of human risk across the organization. More importantly, it turns those insights into measurable remediation actions, enabling organizations to identify high-risk users, prioritize intervention, and demonstrate that risk has been reduced over time.
Ultimately, Human Risk Intelligence bridges the gap between regulatory compliance and operational security, transforming GDPR from a framework for demonstrating compliance into one for continuously reducing risk.
Ready to Reduce Human Risk?
If your organization is looking to move beyond checkbox compliance and build a more proactive approach to GDPR, Human Risk Intelligence can help. Discover how continuous visibility into human risk enables you to identify high-risk users, prioritize remediation, and demonstrate measurable risk reduction across your organization.
Learn more about Human Risk Intelligence or book a demo to see how it can strengthen your GDPR compliance strategy.
Subscribe to newsletter
Discover how professional services firms reduce human risk with usecure
See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.
Related posts
Explore more insights, updates, and resources from usecure.



