HUMAN RISK & COMPLIANCE REPORT

The 2026 Human Risk and Compliance Outlook Report

5 Human Risk and Compliance Blind Spots You Need to Know

TL;DR

2026 Human Risk and Compliance Outlook, in Sixty Seconds

The problem

Training records, phishing simulation results, identity data, and access data typically reside in separate systems, making it difficult to demonstrate that human risk is actually decreasing. Yet today's leading cybersecurity laws, frameworks, and standards, including ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, Cyber Essentials, and Essential Eight, increasingly expect organizations to provide evidence of measurable risk reduction

The fix: Human Risk Intelligence

Target ValueWho attackers want
AwarenessWho may miss threats
HygieneWho is easiest to hit
AccessWhat damage is possible

5 blind spots to watch in 2026

01The Visibility Gap: signals stay scattered across disconnected systems.
02The Compliance Evidence Gap: passing an audit does not mean risk went down.
03Toxic Combinations: individually tolerable risks compound when combined.
04Identity and Access Sprawl: shadow admin and OAuth consent outpace manual review.
05The Outcome Gap: activity metrics do not prove reduced risk.
0%
of breaches involve a non-malicious human element
Verizon, 2026 Data Breach Investigations Report
0
major frameworks now require proof, not just policy
A Human Risk Intelligence solution unifies training, identity, hygiene, and access signals into one prioritized, audit-ready view of who actually matters most.
01 · Executive Summary

Executive Summary

While technology accounts for the largest share of security spending in most organizations, the majority of security breaches still originate with people: a misplaced click, a compromised password, an inappropriate approval, or a simple oversight. Security and compliance teams are not short of data about their workforce, instead, they lack the ability to connect it in a meaningful way.

At the same time, the regulatory landscape has never been more explicit about the need to demonstrate that connection. Frameworks and regulations including ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, Cyber Essentials, Essential Eight, and the CIS Controls all require organizations, in different ways, to demonstrate that the individuals who present the greatest risk to the business are also those receiving the most appropriate security controls, training, and oversight.

This report outlines five human risk and compliance blind spots expected to widen in 2026 as these frameworks converge on that same underlying requirement, and how a Human Risk Intelligence solution, built to unify fragmented signals into a single prioritized view, can turn a training program into audit-ready evidence of reduced risk.

of breaches in 2025 involved a human element

EU entities now fall within the expanded scope of the NIS2 Directive

0%
of breaches in 2025 involved a human element
Source: Verizon, 2026 Data Breach Investigations Report
0+
EU entities now fall within the expanded scope of the NIS2 Directive
Source: European Commission, NIS2 Directive overview
02 · The Compliance Pressure

The Compliance Pressure Behind Human Risk in 2026

Ten of the cybersecurity-related laws, frameworks, and standards organizations are held to most often, spanning information security, financial services, healthcare, payments, and national cybersecurity baselines, no longer accept a signed policy as proof that human risk is under control. Each now asks, in its own language, for evidence that the program actually works.

The next three sections map ten major laws, frameworks, and standards to the human risk evidence each one actually requires.

Mapping Human Risk to Major Compliance Frameworks

Cross-Sector Laws, Frameworks & Standards

FrameworkApplies ToWhat It Requires on Human RiskHRI Pillar
ISO/IEC 27001:2022Any organization pursuing certification, worldwide
  • Clause 7.3 requires personnel to understand the security policy and their role in it.
  • Annex A 5.18 requires organizations to implement procedures and controls to grant, modify, and revoke access to information systems in accordance with their access control policy.
  • Annex A 6.3 requires security awareness, education, and training.
Awareness, Access
SOC 2 (AICPA Trust Services Criteria)Service organizations and SaaS vendors, US-driven but globally referenced
  • Common Criteria CC1 requires evidence that competence and control commitments operated effectively across the audit period, not only at one point in time.
  • CC6 requires organizations to manage digital permissions, passwords, user registration, multifactor authentication (MFA), role-based access control (RBAC), and user deprovisioning.
Awareness, Hygiene, Access
NIS2 Directive (EU 2022/2555)Essential and important entities across 18 EU sectors; transposed October 17, 2024
  • Article 20 mandates that management bodies approve risk-management measures and complete mandatory training themselves.
  • Article 21(2)(g) requires essential and important entities to implement basic cyber hygiene practices and staff training.
Target Value, Awareness, Hygiene
DORA (EU 2022/2554)EU financial entities and critical ICT providers; applicable since January 17, 2025Article 13 requires digital operational resilience training for all staff and senior management, proportionate to role-based ICT risk.Target Value, Awareness
UK Cyber Essentials (NCSC)UK organizations; required for most UK government contractsUser Access Control section requires documented access control, administrative privilege restrictions, and multifactor authentication for cloud services.Hygiene, Access
GDPR (EU 2016/679)Any organization processing personal data of EU residents; fully enforceable since May 25, 2018
  • Article 32 requires organizational measures including staff awareness.
  • Article 5(2) requires demonstrating compliance, not merely asserting it.
Awareness, Access
Scroll the table sideways to see every column

Sector and Technical Control Frameworks & Standards

FrameworkApplies ToWhat It Requires on Human RiskHRI Pillar
PCI DSS v4.0.1Any organization storing, processing, or transmitting payment card data
  • Requirement 8.4.2 mandates multifactor authentication for all access to the cardholder data environment.
  • Requirement 12.6 mandates a formal awareness program covering phishing and social engineering.
Awareness, Hygiene
HIPAA Security Rule (45 CFR 164)US healthcare providers, health plans, and their business associates; fully enforceable since April 20, 2005
  • Section 164.308(a)(5) requires a security awareness and training program for the entire workforce.
  • Section 164.312 requires access safeguards such as unique user IDs and automatic logoff.
Awareness, Access
Australia’s Essential Eight (ACSC)Australian government entities and increasingly regulated industry, maturity levels 0 to 3
  • Two of the eight mitigation strategies require:
  • restricting administrative privileges and
  • enforcing multifactor authentication.
Hygiene, Access
CIS Controls v8.1Voluntary benchmark, widely adopted across sectors worldwide
  • Control 5 requires managing the lifecycle of user, administrator, and service accounts.
  • Control 6 requires managing credentials and privileges through multifactor authentication and account lifecycle management.
  • Control 14 requires security awareness and skills training.
Awareness, Access

Ten frameworks. Four recurring requirements: awareness, hygiene, access, and, less consistently, whether the people who matter most to the business are actually the best protected. That last gap is where most human risk programs still fall short.

Every Framework Points Back to the Same Four Pillars

FrameworkTarget ValueAwarenessHygieneAccess
ISO/IEC 27001:2022
SOC 2
NIS2 Directive
DORA
UK Cyber Essentials
GDPR
PCI DSS v4.0.1
HIPAA
Australia’s Essential Eight
CIS Controls v8.1
The Gap

Compliance effectively governs awareness, hygiene, and access. However, regulation has not caught up to the one blind spot attackers already exploit: which person, if targeted, would deliver the most value?

A Human Risk Intelligence solution adds Target Value as a standing pillar, so audit evidence reflects who would actually cause the most damage, not just who failed to complete a training course or pass a phishing simulation.

03 · 5 Blind Spots

5 Human Risk and Compliance Blind Spots Set to Increase Enterprise Exposure in 2026

Security awareness programs, identity platforms, and compliance frameworks have each matured on their own. Attackers, however, do not respect those boundaries. They combine access, behavior, and hygiene signals into a single plan of attack faster than most organizations can connect the same signals into a single plan of defense.

The following blind spots reflect patterns observed across human risk and compliance programs heading into 2026.
04 · Blind Spot 01

The Visibility Gap: Human Risk Signals Are Scattered Across Disconnected Systems

  • Security awareness tools track who completed a course. Identity tools track who has privileged access. Email security tools track who clicked a phishing link.
  • None of these systems talk to each other, and none of them alone can answer the question that matters most: which specific people represent the greatest risk to the organization right now.
  • Most organizations still measure human risk using activity metrics, such as training completion, rather than exposure metrics, such as who has access, who is vulnerable, and who is likely to be targeted.
Prediction: through 2026, organizations that measure security awareness only by completion rate and click rate will struggle to answer basic questions, such as which of our people, if compromised today, would cause the most damage.

Illustrative Scenario

A mid-size logistics company runs quarterly phishing simulations and completes annual security awareness training at 96% completion, a rate the security team proudly reports to the board.

What the completion dashboard does not show: the company’s three highest-authority finance approvers have never enabled multifactor authentication and one has a password found in a prior breach dump.

None of this appears in the training report, because it lives in identity and email hygiene systems the training program never touches.

0%
of organizations experienced at least one identity-related security incident in the past 12 months
Source: Identity Defined Security Alliance, 2025 Trends in Identity Security Report

Closing the Gap

A Human Risk Intelligence solution unifies training, phishing, identity, and hygiene signals into a single, per-user view of risk, so the same dashboard that reports completion also reports exposure. It surfaces the small number of people whose combination of access and vulnerability matters most, instead of a long list of disconnected activity logs.

05 · Blind Spot 02

The Compliance Evidence Gap: Passing an Audit Is Not the Same as Reducing Risk

  • ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, the UK’s Cyber Essentials scheme, Australia’s Essential Eight, and the CIS Controls each increasingly require organizations to show that security awareness and access controls are operating effectively, not just documented.
  • Many organizations can produce a signed policy and a training completion report. Far fewer can show that the people who are granted the most access, typically because of their seniority and importance to the business, are also the people managing their own risk well enough to deserve that trust.
  • Regulators and auditors are shifting from asking whether a program exists to asking whether it works, and whether that trust is actually earned.
Prediction: As auditors and regulators shift from asking whether your organization has a security awareness training program to asking whether you can demonstrate that it's effective, compliance evidence based solely on training completion will increasingly fail to satisfy examiners.

Illustrative Scenario

A regional healthcare provider completes its annual HIPAA security awareness requirement with 100% training completion across clinical staff, satisfying the letter of the Security Rule on paper.

During a routine audit, the examiner asks a different question: which clinical staff with access to patient records also show weak password hygiene and unresolved phishing failures.

The organization has no way to answer, because that evidence lives in separate identity and hygiene systems never connected to the training report.

€1.2B
record GDPR fine issued to Meta in 2023 for unlawful cross-border data transfers, the largest since GDPR took effect
Source: Irish Data Protection Commission, decision on Meta Platforms Ireland Limited, May 22, 2023

Closing the Gap

A Human Risk Intelligence solution ties access, hygiene, and training data together into continuous, audit-ready evidence at both the individual and organizational level. It enables compliance teams to demonstrate not only that training was completed, but also that employees with the highest levels of access consistently present lower measurable risk.

06 · Blind Spot 03

Toxic Combinations: Individually Tolerable Risks Become Dangerous When They Combine

  • A user without multifactor authentication is a manageable risk. A user who failed a phishing simulation is a manageable risk. An executive account is a manageable risk.
  • The same user carrying all three at once, plus breached credentials circulating on the dark web, represents a significantly greater security risk.
  • Most security tools alert on each factor separately, generating a stream of low-priority noise instead of a short list of genuine priorities.
Prediction: In 2026, security programs will increasingly move from single-signal alerting toward composite risk scoring that evaluates exposure, behavior, security hygiene, and access as interconnected risk factors rather than isolated metrics.

Illustrative Scenario

A finance manager holds broad payment approval authority (high target value), scores below average on finance-themed phishing simulations (low awareness), has no multifactor authentication and one dormant secondary account (weak hygiene), and retains standing administrative rights to the payment platform from a project two years ago (excessive access).

Individually, none of these four factors would trigger an alert in a tool that evaluates only one signal at a time. Yet, unbeknownst to the security team, those factors combine to create one of the highest-consequence accounts in the organization. The risk remains hidden until someone manually correlates data across separate systems.

0B+
stolen username and password combinations estimated to be circulating on criminal and dark web forums
Source: ReliaQuest (formerly Digital Shadows), From Exposure to Takeover

Closing the Gap

A Human Risk Intelligence solution scores exactly this kind of toxic combination automatically across four pillars, Target Value, Awareness, Hygiene, and Access, and surfaces the handful of highest-risk users instead of a long list of isolated, single-factor findings.

07 · Blind Spot 04

Identity, Access, and Shadow Admin Sprawl Outpaces Manual Review

  • Cloud applications, OAuth-connected tools, mail forwarding rules, and shadow administrative rights accumulate quietly over time.
  • Most organizations cannot answer, without a manual audit, who currently holds administrative rights, who granted a risky OAuth consent last quarter, or which departed employee still has an active forwarding rule.
  • Attackers have adapted specifically to exploit this blind spot, using OAuth consent phishing and lateral phishing to gain durable access that traditional credential resets do not remove.
Prediction: Gartner projects that by 2027, 50% of large enterprise CISOs will have adopted human-centric security design practices, up from less than 10% in 2023, in part to close exactly this kind of access visibility gap.

Illustrative Scenario

A marketing employee approved a third-party scheduling application’s OAuth request eighteen months ago to sync calendar invitations. The application was later deprecated and its domain resold to an unrelated party.

The original consent grant, including standing access to calendar and mail data, was never revoked, because no team owned continuous review of application consents.

The access remains active today, invisible to any control that only reviews accounts and passwords rather than the applications those accounts have authorized.

0
average number of days to identify and contain a breach involving stolen or compromised credentials
Source: IBM, Cost of a Data Breach Report 2026

Closing the Gap

A Human Risk Intelligence solution continuously inventories administrative roles, group memberships, application consents, and shadow admin rights as one of its core pillars, flagging dormant or excessive access automatically rather than waiting for an annual review to catch it.

08 · Blind Spot 05

The Outcome Gap: Activity Metrics Do Not Prove Reduced Risk

  • Completion rate and phishing simulation click rate are the two most common metrics in security awareness reporting, yet neither measures whether risk actually went down.
  • A user can complete every training module and still reuse a breached password. A department can score a low click rate on one simulated campaign and still be among the most exposed groups on every other measure.
  • Regulators and auditors increasingly want outcome evidence, not just activity evidence.
Prediction: Completion-only reporting will increasingly be viewed like a passed penetration test. It is necessary, but no longer sufficient, as regulators and auditors shift their focus to evidence of effectiveness.

Illustrative Scenario

An organization's security awareness dashboard shows 98% training completion, up from the year before, and a 3% phishing simulation click rate, down from the year before, both improving in the way leadership wants to see.

A closer look at identity and hygiene data tells a different story: password reuse and multifactor authentication adoption across the same population barely moved over the same period.

The metrics that look best in an executive report are not necessarily the ones that best predict the organization's next security incident.

#1
Phishing and identity-based attacks are the top initial vectors for corporate network intrusions.
Source: IBM, Cost of a Data Breach Report 2026

Closing the Gap

A Human Risk Intelligence solution tracks outcome measures, such as hygiene improvement, access reduction, and exposure trend, alongside activity measures, so training investment can be tied to measurable risk reduction rather than completion alone.

09 · Predictions for 2026 and Beyond

Predictions for 2026 and Beyond

Human Risk Scoring Becomes a Board-Level Metric

As breach costs rise and regulatory oversight intensifies, boards will increasingly expect a single, trusted measure of human risk, much like they already rely on security posture scores. Disconnected training metrics and phishing reports will no longer provide the strategic visibility executives require.

Cyber Insurance Underwriting Will Demand Human Risk Evidence

As insurers respond to rising claims and tighter underwriting standards, organizations will be expected to provide objective evidence of human risk management. Demonstrable reductions in user risk will increasingly influence both policy pricing and claims eligibility, rather than simply checking a box during the application process.

Compliance Frameworks Demand Continuous Evidence, Not Annual Snapshots

As regulations including NIS2, DORA, GDPR, HIPAA, and PCI DSS place greater emphasis on operational effectiveness, annual completion reports alone will no longer satisfy auditors. Continuous, evidence-based reporting will become the standard for demonstrating ongoing compliance.

Generative AI Will Widen the Gap Between Attacker and Defender Speed

As attackers use generative AI to rapidly personalize phishing, business email compromise, and other social engineering attacks, organizations relying on annual training programs will fall further behind. Security teams will increasingly adopt continuous, adaptive risk management to keep pace with rapidly evolving threats.

Identity and Human Risk Programs Converge

As identity-based attacks such as OAuth consent phishing, lateral phishing, and credential abuse continue to grow, organizations will increasingly unify identity, security awareness, and compliance around a shared view of human risk instead of relying on disconnected tools and reporting.

Human Risk Becomes a Standard Line in M&A Due Diligence

As acquirers become more cautious about inheriting compliance gaps, identity sprawl, and insider risk, human risk posture will become a standard component of cybersecurity due diligence. Buyers will evaluate not only an organization's technical security controls, but also its ability to measure, manage, and reduce human risk.

10 · Closing the Gap

Closing the Gap: A Human Risk Intelligence Solution

Most organizations already own the pieces: a training platform, a phishing simulation tool, an identity provider, an email or endpoint security tool. A Human Risk Intelligence solution is the layer that connects those signals into one prioritized, continuously updated view of human risk, organized around four pillars.

Target ValueWho attackers want to compromiseSeniority, escalation influence, data and system access, social presence, and company loyalty.
AwarenessWho may fail to recognize threatsTraining coverage, completion and performance, and phishing simulation results over time.
HygieneWho is easiest to compromiseMultifactor authentication and password weaknesses, breached credentials, dormant accounts, and forwarding rules.
AccessWhat damage a compromise could causeAdministrative roles, group memberships, application consents, and shadow admin rights.
11 · What an HRI Solution Delivers

What a Human Risk Intelligence Solution Delivers

For Security and Compliance Teams
Identify the specific users who carry the greatest combined risk
Focus awareness and remediation effort where it matters most
Produce audit-ready evidence for ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, and beyond
Show measurable risk reduction, not just completed activity
Report a trusted human risk trend to leadership and the board
For Managed Service Providers
Surface hidden risk across every client portfolio in one place
Support recommendations for additional services with evidence instead of assumption
Shift client conversations from activity updates to risk outcomes
Prioritize engineering and account attention across accounts
Run sharper, more effective quarterly business reviews
Glossary

Glossary

Show definitions

Glossary: Human Risk Intelligence Terms

Human Risk Intelligence (HRI) — The practice of unifying human risk signals, such as training, phishing simulation results, identity data, and access data, into a single, prioritized view of risk, rather than tracking each signal separately.

Human Risk Management (HRM) — The day-to-day activities that reduce human risk, including security awareness training, phishing simulations, policy sign-off, and activity reporting.

Target Value — The HRI pillar that measures who attackers want to compromise, based on factors such as seniority, system access, and influence within the organization.

Awareness — The HRI pillar that measures who may fail to recognize threats, based on training completion, performance, and phishing simulation results.

Hygiene — The HRI pillar that measures who is easiest to compromise, based on factors such as multifactor authentication adoption, password strength, and breached credentials.

Access — The HRI pillar that measures what damage a compromise could cause, based on administrative roles, group memberships, and application permissions.

Toxic Combination — A set of individually manageable risk factors that, when combined in a single user, create significantly greater risk than any one factor would on its own.

Shadow Admin — A user account that holds effective administrative rights, often through indirect group memberships or delegated permissions, without being formally recognized as an administrator.

OAuth Consent Phishing — An attack in which a user is tricked into granting a malicious application access to their account through a legitimate-looking permission request, rather than by stealing a password.

Lateral Phishing — An attack launched from a legitimate, already-compromised internal account to target other users within the same organization.

Multifactor Authentication (MFA) — A login method that requires more than one form of verification, such as a password plus a one-time code, to confirm a user's identity.

Glossary: Compliance Frameworks and Standards

ISO/IEC 27001 — An international standard for information security management systems, widely used as a certification benchmark across industries.

SOC 2 — An attestation framework developed by the AICPA that evaluates a service organization's controls related to security, availability, and confidentiality.

NIS2 Directive — European Union legislation that expands cybersecurity risk management and reporting obligations to a much larger population of essential and important entities across 18 sectors.

DORA — The Digital Operational Resilience Act, an EU regulation requiring financial entities and their critical technology providers to maintain digital operational resilience, including staff training.

GDPR — The General Data Protection Regulation, an EU regulation governing the protection of personal data that requires organizations to demonstrate, not just assert, that appropriate safeguards are in place.

HIPAA — The Health Insurance Portability and Accountability Act, US legislation that sets security and privacy requirements for health information, including workforce security awareness training.

PCI DSS — The Payment Card Industry Data Security Standard, a global standard for organizations that store, process, or transmit payment card data, covering both access control and awareness training.

UK Cyber Essentials — A UK government backed certification scheme covering five technical control areas, including access control and multifactor authentication.

Australia's Essential Eight — A set of baseline mitigation strategies published by the Australian Cyber Security Centre, including restricting administrative privileges and enforcing multifactor authentication.

CIS Controls — A prioritized set of safeguards published by the Center for Internet Security, covering account management, access control, and security awareness training.

About usecure

The Human Risk Intelligence platform built for the modern threat landscape.

usecure is a Human Risk Intelligence platform designed to help businesses reduce their human attack surface through continuous, intelligent, and measurable security awareness. Built with a managed service provider (MSP)-first approach, usecure equips security teams and their clients with the tools to simulate phishing attacks, deliver adaptive training, manage policy compliance, monitor dark web exposure, and — critically — bring all of these signals together into a single, unified Human Risk Intelligence view.

Where traditional security awareness programs stop at training completion, usecure goes further: quantifying individual risk, surfacing toxic combinations before attackers can exploit them, and turning human behavior into a manageable, reportable metric.

Protected
0+
organizations protected globally
Partners
0+
MSP partners worldwide
Recognition
#1
Human Risk Intelligence (HRI) platform
G2 Leader - Security Awareness Training ISO/IEC 27001 CertifiedISO/IEC 27001 AICPA SOC 2SOC 2 Type 2
Start managing your human risk today

3 ways to take action now

See the usecure platform in action

Book a 30-minute demo to see how Human Risk Intelligence works in practice, including real risk scores, dashboards, and automated interventions.

Book a demo

Browse the Help Centre

Explore guides, FAQs, and tutorials across uLearn, uPhish, uPolicy, uBreach, and more — all in one place at usecure’s self-serve Help Centre.

Learn more

Get in touch

Prefer to talk it through? Use the contact form and the usecure team will get back to you swiftly, or kick off a live chat if you need real-time help.

Talk to us

Attackers are already profiling your people. Every day without visibility is a day your human attack surface remains unmanaged.