When a cyber security incident happens, the response from businesses is usually immediate. Security teams investigate what happened, leadership looks for explanations, HR communicates with employees, IT works to contain the issue, and compliance teams start to consider any regulatory implications.

For a brief period, everyone is focused on the same objective. Then the incident passes, priorities change, and each department returns to its own responsibilities. Security awareness becomes the security team’s problem again, HR focuses on people initiatives, IT returns to infrastructure projects, and business leaders move on to the next strategic priority.

This cycle plays out in different organisations every day, and it’s one of the biggest reasons human cyber risk remains so difficult to reduce.

Our Rethinking Human Cyber Risk report, based on a survey of 200 CISOs across the UK, France, Germany and Sweden, found that while organisations broadly recognise the importance of managing human cyber risk, responsibility for doing so is rarely shared in a meaningful way. Improving cross-functional collaboration between Security, HR, IT and Compliance emerged as a top priority for 22% of CISOs. However, making that happen isn’t straightforward. One in four (25%) said competing business priorities continue to limit the time and investment available for human risk initiatives, while 21% pointed to limited team capacity and 16% identified low board interest as an ongoing barrier to progress.

This means that human cyber risk sits in an uncomfortable position. , but no single function owns it from beginning to end. Security teams are expected to reduce human risk, yet many of the factors that shape employee behaviour, from onboarding and workplace culture to management practices and business processes, sit elsewhere across the organisation.

Until that disconnect is addressed, awareness programmes will continue to operate in isolation from how a business operates, making it much harder to achieve the long-term behavioural change organisations are looking for to mitigate cyber security risk.

Why Human Risk Falls Between the Cracks

Technical cyber security risks tend to have clear ownership. Whether it’s identity and access management, vulnerability management or patching, there’s usually a defined team responsible for managing that risk, supported by established processes, clear accountability and measurable outcomes. Everyone understands who owns the problem and how success is measured.

Human risk works differently. Security teams can deliver , but they don’t control many of the factors that influence employee behaviour every day.

Many of the factors influencing human cyber risk sit outside the security function. HR shapes how new employees are introduced to security expectations through onboarding and ongoing learning, IT designs the systems, tools and access controls people rely on every day, managers influence behaviours through regular conversations with their teams, and leadership determines which initiatives receive investment, attention and long-term support.

Each of these functions plays an important role in reducing human risk, yet they’re often working towards different objectives and measuring success in different ways. As a result, security awareness can become an isolated programme owned almost entirely by the security team, rather than part of a broader organisational strategy for influencing secure behaviour.

That disconnect was reflected throughout our research. While 22% of CISOs identified improving collaboration between Security, HR, IT and Compliance as a top priority, they also highlighted the practical barriers standing in the way. A quarter (25%) said competing business priorities continue to limit the time and investment available for human risk initiatives, a further 21% pointed to limited team capacity, and 16% cited low board interest as a significant challenge.

None of this suggests organisations aren’t investing time or effort into reducing human cyber risk. Rather, it highlights how difficult it is to make progress when the teams responsible for influencing employee behaviour aren’t sharing the same objectives or measuring success in the same way.

When Everyone Owns Human Risk, Nobody Really Owns It

You’ll often hear the phrase that cyber security is everyone’s responsibility, and on the surface, that’s hard to argue with. Every employee has a role to play in protecting the organisation, whether that’s reporting a suspicious email, handling sensitive information appropriately or following established processes when approving payments or granting access.

The difficulty is that shared responsibility doesn’t automatically create shared ownership.

If everyone has a role to play, someone still needs to coordinate how secure behaviours are developed, reinforced and measured across the organisation. Who decides whether awareness programmes are changing behaviour? Who identifies where additional support is needed? Who brings together the data to understand whether human risk is increasing or decreasing over time?

Without clear answers to those questions, responsibility can quickly become fragmented. Security teams are often expected to reduce human cyber risk and are held accountable when incidents occur, yet many of the factors that influence employee behaviour sit outside their control. They can’t shape onboarding programmes, determine management priorities or embed secure behaviours into every business process on their own.

One CISO we interviewed for our research summarised this challenge perfectly: “It’s not for the CISO to accept the risk – it’s for the business.”

That observation gets to the heart of the issue. Human cyber risk isn’t something the security function owns in isolation; it’s a business risk that spans multiple departments, processes and every stage of the employee lifecycle. Until organisations recognise it as a shared operational responsibility, security teams will continue to carry accountability without having the influence needed to drive meaningful, organisation-wide change.

Why Board Support Isn’t the Same as Board Alignment

Gaining executive support for human cyber risk initiatives isn’t usually the biggest challenge, it’s keeping that support over the long term that is.

When a security incident occurs, human cyber risk quickly moves up the board agenda. Leadership wants to understand what happened, whether it could happen again and what steps are being taken to reduce the likelihood of a repeat incident. Budgets are revisited, awareness programmes receive renewed attention and security becomes an immediate business priority.

The difficulty is that this level of engagement is often short-lived. Our research found that 79% of CISOs believe board interest in security awareness programmes fades once the immediate impact of an incident has passed. As other strategic priorities compete for attention, conversations around human cyber risk become less frequent until another incident brings them back into focus.

This stop-start approach makes it difficult to build lasting behavioural change. Changing how people think and act doesn’t happen over the course of a few weeks following an incident; it requires sustained leadership support, consistent reinforcement and a shared commitment from across the organisation.

Maintaining that momentum becomes even more challenging when security leaders struggle to demonstrate the value of their awareness programmes. that just 39% of CISOs feel completely confident explaining the value of security awareness initiatives to their board or executive team.

Part of the problem lies in the way many organisations measure success. Reporting often focuses on metrics like training completion rates or phishing simulation results because they’re easy to collect and straightforward to present. While these figures demonstrate that security awareness activity has taken place, they provide little insight into whether employees are making better security decisions or whether overall human cyber risk is reducing.

Without that evidence, it becomes much harder for CISOs to demonstrate return on investment, justify continued funding and keep human cyber risk positioned as a strategic business priority rather than an issue that only attracts attention after something has gone wrong.

What Good Alignment Looks Like

Organisations making the greatest progress don’t achieve it simply by encouraging departments to collaborate more closely. Instead, they create a shared approach to managing human cyber risk, where every function understands the role it plays in influencing employee behaviour and reducing risk.

Security teams remain responsible for identifying behavioural risks, delivering targeted interventions and providing the insight needed to understand where risk is increasing or improving. That information then informs action across the wider organisation, rather than staying within the security function.

HR reinforces those efforts by embedding security throughout the employee lifecycle, from onboarding and mandatory learning to ongoing communications and development. IT complements this by designing systems that make secure behaviour the easiest option, using secure defaults, appropriate access controls and well-designed processes to reduce unnecessary opportunities for human error.

Managers also have an important role to play because they’re often best placed to reinforce secure behaviours as part of everyday work. Whether someone is handling sensitive customer information, approving supplier payments or using AI tools, regular conversations with line managers can help employees recognise higher-risk situations, ask questions when something feels unusual and follow established processes before making important decisions.

Leadership completes the picture by providing visible and consistent support. Rather than allowing human cyber risk to become a priority only after an incident, mature organisations treat it as an ongoing business objective, ensuring investment, reporting and accountability are consistent throughout the year.

When every part of the organisation is working towards the same goal, security awareness becomes more than a standalone training programme. It becomes one element of a broader s strategy, supported by shared ownership, meaningful measurement and coordinated action across the business.

Human Risk Needs Shared Ownership

Many organisations still treat human cyber risk as something security teams need to solve alone.

The evidence suggests that’s one of the biggest reasons progress is difficult.

Human risk is created through everyday business activities, influenced by culture, reinforced by managers and shaped by the systems employees use. Reducing that risk requires the same level of coordination.

The organisations making the greatest progress aren’t necessarily delivering more awareness training than everyone else. They’re creating stronger alignment between the people responsible for influencing behaviour, measuring what matters and giving every stakeholder a clear role in reducing risk.

When human cyber risk becomes a shared responsibility rather than a security initiative, it becomes much easier to move from awareness activity to measurable risk reduction.

How MetaCompliance Helps Improve Cross-Functional Human Risk Management

Managing human cyber risk requires more than delivering security awareness training. It depends on giving Security, HR, IT, Risk and leadership a shared view of where behavioural risk exists, which interventions are having the greatest impact and where additional support is needed.

Our Human Risk Management platform helps organisations move beyond one-size-fits-all awareness programmes by combining personalised security learning, behavioural insights, phishing simulations, automated interventions and human risk reporting in a single platform. This gives security leaders the evidence they need to demonstrate progress, prioritise high-risk users and engage stakeholders across the business with meaningful, measurable outcomes.

By helping organisations understand, measure and reduce human cyber risk over time, MetaCompliance enables security awareness to become part of a coordinated business strategy, rather than a standalone security initiative.

Looking for practical guidance on reducing human cyber risk by aligning teams across your organisation? Download our playbook, Who Owns Human Cyber Risk: Five Principles for Building Shared Ownership of Human Cyber Risk Across Teams, to explore how Security, HR, IT, Risk and leadership can work together to build a more coordinated approach to managing human cyber risk.

Ready to build a more aligned approach to human cyber risk? Get a demo today to find out how MetaCompliance can help your organisation measure, manage and reduce human risk at scale.

FAQs

Why is human cyber risk considered a cross-functional challenge?

Human cyber risk is influenced by far more than security awareness training. HR shapes onboarding and learning, IT designs secure systems and access controls, managers reinforce behaviours through day-to-day conversations, and leadership sets business priorities. Reducing human risk requires these functions to work together rather than operating independently.