2026 Human Risk and Compliance Outlook, in Sixty Seconds
The problem
Training records, phishing simulation results, identity data, and access data typically reside in separate systems, making it difficult to demonstrate that human risk is actually decreasing. Yet today's leading cybersecurity laws, frameworks, and standards, including ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, Cyber Essentials, and Essential Eight, increasingly expect organizations to provide evidence of measurable risk reduction
The fix: Human Risk Intelligence
5 blind spots to watch in 2026
Executive Summary
While technology accounts for the largest share of security spending in most organizations, the majority of security breaches still originate with people: a misplaced click, a compromised password, an inappropriate approval, or a simple oversight. Security and compliance teams are not short of data about their workforce, instead, they lack the ability to connect it in a meaningful way.
At the same time, the regulatory landscape has never been more explicit about the need to demonstrate that connection. Frameworks and regulations including ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, Cyber Essentials, Essential Eight, and the CIS Controls all require organizations, in different ways, to demonstrate that the individuals who present the greatest risk to the business are also those receiving the most appropriate security controls, training, and oversight.
This report outlines five human risk and compliance blind spots expected to widen in 2026 as these frameworks converge on that same underlying requirement, and how a Human Risk Intelligence solution, built to unify fragmented signals into a single prioritized view, can turn a training program into audit-ready evidence of reduced risk.
of breaches in 2025 involved a human element
EU entities now fall within the expanded scope of the NIS2 Directive
The Compliance Pressure Behind Human Risk in 2026
Ten of the cybersecurity-related laws, frameworks, and standards organizations are held to most often, spanning information security, financial services, healthcare, payments, and national cybersecurity baselines, no longer accept a signed policy as proof that human risk is under control. Each now asks, in its own language, for evidence that the program actually works.
Mapping Human Risk to Major Compliance Frameworks
Cross-Sector Laws, Frameworks & Standards
| Framework | Applies To | What It Requires on Human Risk | HRI Pillar |
|---|---|---|---|
| ISO/IEC 27001:2022 | Any organization pursuing certification, worldwide |
| Awareness, Access |
| SOC 2 (AICPA Trust Services Criteria) | Service organizations and SaaS vendors, US-driven but globally referenced |
| Awareness, Hygiene, Access |
| NIS2 Directive (EU 2022/2555) | Essential and important entities across 18 EU sectors; transposed October 17, 2024 |
| Target Value, Awareness, Hygiene |
| DORA (EU 2022/2554) | EU financial entities and critical ICT providers; applicable since January 17, 2025 | Article 13 requires digital operational resilience training for all staff and senior management, proportionate to role-based ICT risk. | Target Value, Awareness |
| UK Cyber Essentials (NCSC) | UK organizations; required for most UK government contracts | User Access Control section requires documented access control, administrative privilege restrictions, and multifactor authentication for cloud services. | Hygiene, Access |
| GDPR (EU 2016/679) | Any organization processing personal data of EU residents; fully enforceable since May 25, 2018 |
| Awareness, Access |
Sector and Technical Control Frameworks & Standards
| Framework | Applies To | What It Requires on Human Risk | HRI Pillar |
|---|---|---|---|
| PCI DSS v4.0.1 | Any organization storing, processing, or transmitting payment card data |
| Awareness, Hygiene |
| HIPAA Security Rule (45 CFR 164) | US healthcare providers, health plans, and their business associates; fully enforceable since April 20, 2005 |
| Awareness, Access |
| Australia’s Essential Eight (ACSC) | Australian government entities and increasingly regulated industry, maturity levels 0 to 3 |
| Hygiene, Access |
| CIS Controls v8.1 | Voluntary benchmark, widely adopted across sectors worldwide |
| Awareness, Access |
Ten frameworks. Four recurring requirements: awareness, hygiene, access, and, less consistently, whether the people who matter most to the business are actually the best protected. That last gap is where most human risk programs still fall short.
Every Framework Points Back to the Same Four Pillars
| Framework | Target Value | Awareness | Hygiene | Access |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | ✓ | ✓ | ||
| SOC 2 | ✓ | ✓ | ✓ | |
| NIS2 Directive | ✓ | ✓ | ✓ | |
| DORA | ✓ | ✓ | ||
| UK Cyber Essentials | ✓ | ✓ | ||
| GDPR | ✓ | ✓ | ||
| PCI DSS v4.0.1 | ✓ | ✓ | ||
| HIPAA | ✓ | ✓ | ||
| Australia’s Essential Eight | ✓ | ✓ | ||
| CIS Controls v8.1 | ✓ | ✓ |
Compliance effectively governs awareness, hygiene, and access. However, regulation has not caught up to the one blind spot attackers already exploit: which person, if targeted, would deliver the most value?
A Human Risk Intelligence solution adds Target Value as a standing pillar, so audit evidence reflects who would actually cause the most damage, not just who failed to complete a training course or pass a phishing simulation.
5 Human Risk and Compliance Blind Spots Set to Increase Enterprise Exposure in 2026
Security awareness programs, identity platforms, and compliance frameworks have each matured on their own. Attackers, however, do not respect those boundaries. They combine access, behavior, and hygiene signals into a single plan of attack faster than most organizations can connect the same signals into a single plan of defense.
The Visibility Gap: Human Risk Signals Are Scattered Across Disconnected Systems
- Security awareness tools track who completed a course. Identity tools track who has privileged access. Email security tools track who clicked a phishing link.
- None of these systems talk to each other, and none of them alone can answer the question that matters most: which specific people represent the greatest risk to the organization right now.
- Most organizations still measure human risk using activity metrics, such as training completion, rather than exposure metrics, such as who has access, who is vulnerable, and who is likely to be targeted.
Illustrative Scenario
A mid-size logistics company runs quarterly phishing simulations and completes annual security awareness training at 96% completion, a rate the security team proudly reports to the board.
What the completion dashboard does not show: the company’s three highest-authority finance approvers have never enabled multifactor authentication and one has a password found in a prior breach dump.
None of this appears in the training report, because it lives in identity and email hygiene systems the training program never touches.
Closing the Gap
A Human Risk Intelligence solution unifies training, phishing, identity, and hygiene signals into a single, per-user view of risk, so the same dashboard that reports completion also reports exposure. It surfaces the small number of people whose combination of access and vulnerability matters most, instead of a long list of disconnected activity logs.
The Compliance Evidence Gap: Passing an Audit Is Not the Same as Reducing Risk
- ISO 27001, SOC 2, NIS2, DORA, GDPR, HIPAA, PCI DSS, the UK’s Cyber Essentials scheme, Australia’s Essential Eight, and the CIS Controls each increasingly require organizations to show that security awareness and access controls are operating effectively, not just documented.
- Many organizations can produce a signed policy and a training completion report. Far fewer can show that the people who are granted the most access, typically because of their seniority and importance to the business, are also the people managing their own risk well enough to deserve that trust.
- Regulators and auditors are shifting from asking whether a program exists to asking whether it works, and whether that trust is actually earned.
Illustrative Scenario
A regional healthcare provider completes its annual HIPAA security awareness requirement with 100% training completion across clinical staff, satisfying the letter of the Security Rule on paper.
During a routine audit, the examiner asks a different question: which clinical staff with access to patient records also show weak password hygiene and unresolved phishing failures.
The organization has no way to answer, because that evidence lives in separate identity and hygiene systems never connected to the training report.
Closing the Gap
A Human Risk Intelligence solution ties access, hygiene, and training data together into continuous, audit-ready evidence at both the individual and organizational level. It enables compliance teams to demonstrate not only that training was completed, but also that employees with the highest levels of access consistently present lower measurable risk.
Toxic Combinations: Individually Tolerable Risks Become Dangerous When They Combine
- A user without multifactor authentication is a manageable risk. A user who failed a phishing simulation is a manageable risk. An executive account is a manageable risk.
- The same user carrying all three at once, plus breached credentials circulating on the dark web, represents a significantly greater security risk.
- Most security tools alert on each factor separately, generating a stream of low-priority noise instead of a short list of genuine priorities.
Illustrative Scenario
A finance manager holds broad payment approval authority (high target value), scores below average on finance-themed phishing simulations (low awareness), has no multifactor authentication and one dormant secondary account (weak hygiene), and retains standing administrative rights to the payment platform from a project two years ago (excessive access).
Individually, none of these four factors would trigger an alert in a tool that evaluates only one signal at a time. Yet, unbeknownst to the security team, those factors combine to create one of the highest-consequence accounts in the organization. The risk remains hidden until someone manually correlates data across separate systems.
Closing the Gap
A Human Risk Intelligence solution scores exactly this kind of toxic combination automatically across four pillars, Target Value, Awareness, Hygiene, and Access, and surfaces the handful of highest-risk users instead of a long list of isolated, single-factor findings.
Identity, Access, and Shadow Admin Sprawl Outpaces Manual Review
- Cloud applications, OAuth-connected tools, mail forwarding rules, and shadow administrative rights accumulate quietly over time.
- Most organizations cannot answer, without a manual audit, who currently holds administrative rights, who granted a risky OAuth consent last quarter, or which departed employee still has an active forwarding rule.
- Attackers have adapted specifically to exploit this blind spot, using OAuth consent phishing and lateral phishing to gain durable access that traditional credential resets do not remove.
Illustrative Scenario
A marketing employee approved a third-party scheduling application’s OAuth request eighteen months ago to sync calendar invitations. The application was later deprecated and its domain resold to an unrelated party.
The original consent grant, including standing access to calendar and mail data, was never revoked, because no team owned continuous review of application consents.
The access remains active today, invisible to any control that only reviews accounts and passwords rather than the applications those accounts have authorized.
Closing the Gap
A Human Risk Intelligence solution continuously inventories administrative roles, group memberships, application consents, and shadow admin rights as one of its core pillars, flagging dormant or excessive access automatically rather than waiting for an annual review to catch it.
The Outcome Gap: Activity Metrics Do Not Prove Reduced Risk
- Completion rate and phishing simulation click rate are the two most common metrics in security awareness reporting, yet neither measures whether risk actually went down.
- A user can complete every training module and still reuse a breached password. A department can score a low click rate on one simulated campaign and still be among the most exposed groups on every other measure.
- Regulators and auditors increasingly want outcome evidence, not just activity evidence.
Illustrative Scenario
An organization's security awareness dashboard shows 98% training completion, up from the year before, and a 3% phishing simulation click rate, down from the year before, both improving in the way leadership wants to see.
A closer look at identity and hygiene data tells a different story: password reuse and multifactor authentication adoption across the same population barely moved over the same period.
The metrics that look best in an executive report are not necessarily the ones that best predict the organization's next security incident.
Closing the Gap
A Human Risk Intelligence solution tracks outcome measures, such as hygiene improvement, access reduction, and exposure trend, alongside activity measures, so training investment can be tied to measurable risk reduction rather than completion alone.
Predictions for 2026 and Beyond
As breach costs rise and regulatory oversight intensifies, boards will increasingly expect a single, trusted measure of human risk, much like they already rely on security posture scores. Disconnected training metrics and phishing reports will no longer provide the strategic visibility executives require.
As insurers respond to rising claims and tighter underwriting standards, organizations will be expected to provide objective evidence of human risk management. Demonstrable reductions in user risk will increasingly influence both policy pricing and claims eligibility, rather than simply checking a box during the application process.
As regulations including NIS2, DORA, GDPR, HIPAA, and PCI DSS place greater emphasis on operational effectiveness, annual completion reports alone will no longer satisfy auditors. Continuous, evidence-based reporting will become the standard for demonstrating ongoing compliance.
As attackers use generative AI to rapidly personalize phishing, business email compromise, and other social engineering attacks, organizations relying on annual training programs will fall further behind. Security teams will increasingly adopt continuous, adaptive risk management to keep pace with rapidly evolving threats.
As identity-based attacks such as OAuth consent phishing, lateral phishing, and credential abuse continue to grow, organizations will increasingly unify identity, security awareness, and compliance around a shared view of human risk instead of relying on disconnected tools and reporting.
As acquirers become more cautious about inheriting compliance gaps, identity sprawl, and insider risk, human risk posture will become a standard component of cybersecurity due diligence. Buyers will evaluate not only an organization's technical security controls, but also its ability to measure, manage, and reduce human risk.
Closing the Gap: A Human Risk Intelligence Solution
Most organizations already own the pieces: a training platform, a phishing simulation tool, an identity provider, an email or endpoint security tool. A Human Risk Intelligence solution is the layer that connects those signals into one prioritized, continuously updated view of human risk, organized around four pillars.
What a Human Risk Intelligence Solution Delivers
Glossary
Show definitions
Glossary: Human Risk Intelligence Terms
Human Risk Intelligence (HRI) — The practice of unifying human risk signals, such as training, phishing simulation results, identity data, and access data, into a single, prioritized view of risk, rather than tracking each signal separately.
Human Risk Management (HRM) — The day-to-day activities that reduce human risk, including security awareness training, phishing simulations, policy sign-off, and activity reporting.
Target Value — The HRI pillar that measures who attackers want to compromise, based on factors such as seniority, system access, and influence within the organization.
Awareness — The HRI pillar that measures who may fail to recognize threats, based on training completion, performance, and phishing simulation results.
Hygiene — The HRI pillar that measures who is easiest to compromise, based on factors such as multifactor authentication adoption, password strength, and breached credentials.
Access — The HRI pillar that measures what damage a compromise could cause, based on administrative roles, group memberships, and application permissions.
Toxic Combination — A set of individually manageable risk factors that, when combined in a single user, create significantly greater risk than any one factor would on its own.
Shadow Admin — A user account that holds effective administrative rights, often through indirect group memberships or delegated permissions, without being formally recognized as an administrator.
OAuth Consent Phishing — An attack in which a user is tricked into granting a malicious application access to their account through a legitimate-looking permission request, rather than by stealing a password.
Lateral Phishing — An attack launched from a legitimate, already-compromised internal account to target other users within the same organization.
Multifactor Authentication (MFA) — A login method that requires more than one form of verification, such as a password plus a one-time code, to confirm a user's identity.
Glossary: Compliance Frameworks and Standards
ISO/IEC 27001 — An international standard for information security management systems, widely used as a certification benchmark across industries.
SOC 2 — An attestation framework developed by the AICPA that evaluates a service organization's controls related to security, availability, and confidentiality.
NIS2 Directive — European Union legislation that expands cybersecurity risk management and reporting obligations to a much larger population of essential and important entities across 18 sectors.
DORA — The Digital Operational Resilience Act, an EU regulation requiring financial entities and their critical technology providers to maintain digital operational resilience, including staff training.
GDPR — The General Data Protection Regulation, an EU regulation governing the protection of personal data that requires organizations to demonstrate, not just assert, that appropriate safeguards are in place.
HIPAA — The Health Insurance Portability and Accountability Act, US legislation that sets security and privacy requirements for health information, including workforce security awareness training.
PCI DSS — The Payment Card Industry Data Security Standard, a global standard for organizations that store, process, or transmit payment card data, covering both access control and awareness training.
UK Cyber Essentials — A UK government backed certification scheme covering five technical control areas, including access control and multifactor authentication.
Australia's Essential Eight — A set of baseline mitigation strategies published by the Australian Cyber Security Centre, including restricting administrative privileges and enforcing multifactor authentication.
CIS Controls — A prioritized set of safeguards published by the Center for Internet Security, covering account management, access control, and security awareness training.