Group Purchasing
Group Purchasing
AI SKILLS

LDR433: Managing Human Risk

LDR433Cybersecurity Leadership, Artificial Intelligence
  • 3 Days (Instructor-Led)
  • 18 Hours (Self-Paced)
Course authored by:
Lance Spitzner
Lance Spitzner
LDR433: Managing Human Risk
Course authored by:
Lance Spitzner
Lance Spitzner
  • SANS Security Awareness Professional (SSAP)
  • 18 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Beginner Level

    Course content applicable to people with limited or no cyber security experience

  • 6 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

This intensive three-day course prepares you to build a mature awareness program, providing you with the roadmap, skills, and lessons learned on how to effectively manage and measure your organization’s human risk.

Course Overview

LDR433 provides security professionals with a structured roadmap to build, manage, and measure human risk by changing and securing their workforce's behaviors. The course offers a step-by-step strategy for engaging and securing your workforce, including six interactive team labs and a Digital Download Package. Students will learn how to assess and prioritize top human risks and the behaviors that manage those risks, how to engage and train their workforce, how to build a strong security culture, and how to measure the impact of these changes. This is the only SANS short course that provides the industry-recognized SANS Security Awareness Professional (SSAP) credential. The course content draws from lessons learned across hundreds of global programs, offering both instructor guidance and extensive peer interaction.

Strategic Human Risk Management for Security Professionals

Today’s cyber threat actors are focusing less on technology and more on exploiting people. Human Risk Management provides a systematic way for organizations to protect their workforce—now the primary target and greatest source of risk.

Learn the key lessons and understand the roadmap to building a mature awareness program that will truly engage your workforce, change their behavior, and ultimately support your efforts in managing human risk in cybersecurity. Apply models such as the BJ Fogg Behavior Model, AIDA Marketing funnel, the Golden Circle, and ADDIE training model, and learn about the Elephant vs. the Rider. You will learn how to assess and prioritize your top human risks and the behaviors that manage those risks, how to engage, train and secure your workforce by changing their behaviors, how to build a strong security culture, and how to measure the impact and value of all that change.

The course content is based not only on learning theory and behavior change models, but on lessons learned from hundreds of programs from around the world. You will learn not only from your instructor, but from extensive interaction with your peers. Finally, you will have the opportunity to earn the SSAP certification, the industry standard in managing human risk in cybersecurity, recognized by employers around the world.

Author Statement

"Having been actively involved in information security for more than 25 years, I have seen one constant factor: people are the number one attack vector for cyber attackers as organizations fail to properly invest in and secure them. This problem is solvable. Once engaged, trained and enabled, your workforce will become your greatest asset, ultimately driving not only secure behaviors but ultimately a strong security culture. I am extremely excited about LDR433, as it provides you with a proven roadmap and the skills, resources, and community you need to effectively manage and measure your human risk."

- Lance Spitzner

What You'll Learn

  • Benchmark and advance your program's maturity level
  • Identify and prioritize human risks
  • Understand the sciences behind adult learning theory, cognitive biases, and behavior change
  • Gain actionable strategies to engage and change security behaviors
  • Employ techniques to engage and build credibility with leadership and your security team
  • Implement approaches to measure and communicate your program's value
  • Leverage AI to accelerate and amplify your impact

Business Takeaways

  • Align security awareness with strategic security priorities
  • Identify and manage your organization's top human risks
  • Integrate human risk management with broader risk management efforts
  • Build sustainable programs that foster a strong security culture
  • Demonstrate program value to leadership in business terms
  • Implement effective learning and behavioral change models
  • Leverage AI to maximize program impact and efficiency

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR433: Managing Human Risk. .

Section 1Fundamentals and Identifying / Prioritizing Human Risk

Section 1 covers the fundamentals of human risk management, beginning with benchmarking your program's maturity and providing a roadmap for improvement. It addresses critical foundations including leadership support, program charter, and strategic partnerships, then covers risk management principles and how to identify and prioritize your top human risks.

Topics covered

  • Security Awareness Maturity Model stages
  • Risk management fundamentals
  • Cyber Threat Intelligence and attacker methods
  • Gaining leadership support and developing strategic partnerships
  • Human risk assessments and prioritization, and role-based risks

Labs

  • Benchmark your program maturity against peers
  • Case Study: Identify and prioritize top human risks

Overview

Section 1 covers the fundamentals by specifically answering the question: What is human risk, and how can organizations effectively manage it? We start with students defining the maturity of their existing program then provide a roadmap for how to improve their program maturity. We then cover critical foundations for a successful program: leadership support, a program charter, and partnerships. We then cover the fundamentals of risk management and how to assess and prioritize your top human risks.

Full Lab Details

  • Benchmarking your program's maturity against your peers
  • Developing key partnerships
  • Identifying your top human risks

Full Topic Details

  • How to map and benchmark your programs maturity
  • The five stages of the Security Awareness Maturity Model
  • How to leverage AI to accelerate and amplify your impact
  • The fundamentals of risk and risk management
  • The definition of human risk and the three variables that define it
  • Why humans are so vulnerable, and the latest methods cyber attackers use to exploit these vulnerabilities
  • Steps to gain and maintain leadership support for your program
  • How to develop and leverage effective partnerships
  • Developing a strategic plan that prioritizes your organization's human risk, the behaviors to manage those risks, and changing those behaviors.
  • A walkthrough on how to conduct a human risk assessment and how to prioritize your organization's top human risks, including leveraging the latest in Cyber Threat Intelligence (CTI)
  • How to identify and manage role-based risks

Section 2Identifying and Changing Behavior

Section 2 begins with identifying the key behaviors that most effectively manage your greatest human risks. We then cover organization level behavior change, to include engagement fundamentals motivation and training. You will develop an overall strategy for your program, to include how to adapt your program across demographics, cultures, and regions, then concluding with operationalizing specific training methods and modalities.

Topics covered

  • Behavior identification and prioritization
  • Engagement strategies using marketing models
  • Training approaches using ADDIE framework
  • Operationalize different training methods and modalities, to include how to leverage AI

Labs

  • Identify and prioritize key behaviors
  • Apply the AIDA Model to promote MFA adoption

Overview

The second section begins with how to identify the key behaviors that manage your top human risks, including defining each behavior as a learning objective. We then cover how to change behaviors at an organizational level, starting with the fundamentals of engagement and motivating change, then how to adapt your program to different demographics, cultures, and regions. Finally, we go into the many different methods and modalities to train and engage your workforce.

Full Lab Details

  • Identify and prioritize key behaviors
  • Leverage the AIDA Model to engage and promote behavior change

Full Topic Details

  • Resources for your long-term success
  • Defining learning objectives and how they apply to learning theory and risk management
  • How to identify and prioritize the top behaviors that manage your key human risks
  • Fundamentals of engaging and changing human behavior
  • Introduction of the Golden Circle and the importance of "why"
  • How you can effectively create an engagement strategy leveraging marketing models
  • Creating a training strategy leveraging the ADDIE and Kirkpatrick models
  • Top tips for effective translation and localization
  • The effective use of imagery, with a focus on diverse or international environments
  • Creating and documenting training campaigns
  • The two different training categories, primary and reinforcement, and the roles of each
  • How to effectively develop and provide instructor-led training (ILT), virtual live training (VLT) and computer-based training (CBT)
  • Different reinforcement methods, including newsletters, infographics, podcasts, micro-videos and video shorts, memes, hosted speaker events, hacking demos, scavenger hunts, virtual lunch-and-learns, and numerous other training activities
  • How to put this all together for a specific training /risk management goal

Section 3Security Culture and Measuring Change

Section 3 focuses on organizational culture, security culture and embedding security in your organization's overall culture. We then cover metrics, starting with strategic applications, then exploring how to measure behavior and culture change. Students will learn to communicate program value to leadership and finish the class by creating an actionable implementation plan.

Topics covered

  • Career development for awareness professionals
  • Define and align with organizational culture
  • Security culture indicators and development
  • Incentive programs for sustainable behavior, and ambassador program implementation
  • Metrics and create a strategic metrics framework and a final action plan

Labs

  • Analyze and align with organizational culture
  • Create a comprehensive action plan

Overview

This section begins with culture, specifically defining your organization's overall culture, what security culture is and how to embed a strong security culture into your organization's overall culture. We then cover metrics, starting with why we want metrics and how to use them at a strategic level. We then do a deep dive into how to measure behavior and culture, then strategic metrics and then finally how to communicate the value of your program to leadership in business terms. We finish the class with how to put this all together into an actionable plan with key tips for success.

Full Lab Details

  • How to understand, define and align security with your organization's overall culture
  • Creating an action plan for when you return to your organization

Full Topic Details

  • Career development: Steps you can take to grow your credibility, position and compensation
  • What organizational culture is and how to define your organization's overall culture
  • What security culture is, the value of a strong security culture, and the most common indicators of both a weak and strong security culture
  • How to align with and embed a strong security culture into your organization’s overall culture
  • How to create a strong incentive program to sustain behavior change long term
  • A deep dive into Ambassador Programs
  • Fundamentals of metrics, including why we collect them and how to leverage them strategically
  • The difference between compliance metrics and impact metrics
  • Walk through of the three types of impact metrics: knowledge, culture and behavior
  • Identifying leadership’s strategic priorities and how to align your metrics with them
  • Putting an overall project plan together and executing it
  • Resources for success moving forward

Things You Need To Know

Students are recommended to bring their own laptop for this course.

LDR433 training is recommended for a diverse range of individuals, including:

  • Security awareness, training, engagement or culture officers
  • Security management officials
  • Security Ambassadors or Champions officers
  • Security auditors, and governance, legal, privacy or compliance officers
  • Training, human resources and communications staff
  • Representatives from organizations regulated by industries such as HIPAA, GDPR, FISMA, FERPA, PCI-DSS, ISO/IEC 27001 SOX, NERC, or any other compliance-driven standard
  • Anyone involved in planning, deploying or maintaining a security education, training, influence or communications program

This course provides you with the opportunity to join the SANS Security Awareness Community Forum, a private, invitation-only community of over 2,000 security professionals passionate about the human side of cybersecurity. In addition, you will receive the following with the course:

  • Printed + Electronic course books that include slides with detailed notes for each slide
  • Printed + Electronic lab book
  • Digital Download Package containing digital copies of all the labs, supplemental materials, reports, templates and examples
  • MP3 audio files of the complete course lecture

This course is designed for both new security professionals and experienced ones looking to expand their expertise in human risk management. While an understanding of cybersecurity risk and/or a technical background can help, it is in no way required.

The course LDR433 Managing Human Risk is part of SANS Cybersecurity Leadership curriculum. This is in the category of knowledge every security manager should know. This course then prepares learners for the advanced leadership portion of the SANS leadership curriculum. Advanced leadership courses feature specializations based on management roles. 

What Comes Next?

  • LDR521: Security Culture for Leaders: This course takes LDR433 to the next level by teaching you how to leverage the principles of organizational change to develop, maintain, and measure a security-driven culture.
  • LDR512: Security Leadership Essentials for Managers: This course provides an overview of how to manage different security technologies, controls, and frameworks, and how they work together. It is an excellent way to better understand how awareness of human risk and knowing how to manage it partners with other elements of security.
  • LDR514: Security Strategic Planning, Policy, and Leadership: This is SANS' most advanced course for senior security leaders, CSOs, and CISOs. It is an excellent way to better understand how awareness of human risk and knowing how to manage it support your organization at a strategic level.

Managing human risk is a structured approach to addressing the primary enterprise vulnerability: people. It involves identifying high-risk behaviors, implementing targeted awareness programs, changing behaviors through engagement and training, building a strong security culture, and measuring the impact. Managing human risk properly transforms employees into active defenders against cyber threats.

LDR433 enhances your career by providing in-demand skills and the SSAP certification—a mark of distinction in human risk management. Participants gain practical frameworks for assessing risks, changing behaviors, and measuring program effectiveness that demonstrate strategic value to employers. As organizations increasingly recognize that people are both their greatest vulnerability and potential security asset, professionals who can effectively manage human risk become essential to security teams and are well-positioned for advancement into leadership roles.

Relevant Job Roles

Cybersecurity Curriculum Development (OPM 711)

NICE: Oversight and Governance

Responsible for developing, planning, coordinating, and evaluating cybersecurity awareness, training, or education content, methods, and techniques based on instructional needs and requirements.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 9 of 9

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources