ComplianceCyber SecurityHuman Risk ManagementIdentityIdentity and Access ManagementManaged Service ProvidersMSPNIS2Security Awareness

From Awareness Data to Human Risk Intelligence: Turning Scattered Client Data into a Service Worth Renewing

From Awareness Data to Human Risk Intelligence: Turning Scattered Client Data into a Service Worth Renewing

From Awareness Data to Human Risk Intelligence: Turning Scattered Client Data into a Service Worth Renewing

There is a version of this conversation happening in Irish MSPs every week. A client’s IT lead, or sometimes their CFO, forwards a questionnaire from an insurer, a supply chain partner, or a prospective customer. Somewhere in the document, usually buried in the governance section, a question asks: how do you assess human cyber risk across your organisation, and what evidence do you have that it is being actively managed?

The MSP can point to the security awareness platform. Completion rates are healthy. Phishing simulations are running. There may be credential monitoring in place and a policy management workflow ticking over. The tools are there, the data is being generated, and the answer still falls short, because the question being asked has moved on.

The question has changed

A year ago, the conversation with clients was about coverage. Had staff completed their training modules? Were phishing simulations being sent? Could the MSP show a report at the quarterly business review? Those were reasonable questions when the expectation was that awareness training would be provided and evidenced. For many MSPs, that is exactly the service they built and sold.

The regulatory and commercial environment has shifted the question. NIS2 obligations are arriving through customer questionnaires and insurer renewal packs well ahead of Irish legislation, and the European Commission has already referred Ireland to the Court of Justice over the delay in transposing it. DORA has applied to financial entities since January 2025 and pushes requirements through every ICT supplier those entities depend on. Boards are being briefed on personal liability. The NCSC published governance guidance for senior executives in July.

What those frameworks keep returning to is proportionality and evidence. An organisation is expected to have measures appropriate to its risk, and to be able to demonstrate that those measures are working. A completion rate demonstrates that training was delivered. It says nothing about whether the people who pose the greatest risk to the organisation received the right attention.

The data exists. The view does not.

Most MSPs running a human risk programme already have the raw material. Awareness training platforms track who completed what, and who struggled. Phishing simulations track who clicked, who reported, and who did neither. Credential monitoring flags exposed passwords. Policy management tracks acknowledgements and gaps. Each of those tools generates useful data in its own lane.

The difficulty is that the lanes do not connect. A user who failed a phishing simulation last month, whose credentials appeared in a breach database this quarter, and who holds privileged access to a critical system, does not show up as a single, prioritised concern. That user appears as three separate data points in three separate dashboards, and none of those dashboards knows about the other two.

For the MSP trying to answer a client’s questionnaire, this creates a credibility gap. The tools are running. The data is being collected. There is no single view that says: here is where human risk is concentrated in this organisation, here is who needs attention first, and here is what we are doing about it.

What changes when the signals connect

The MSPs who are answering that question well have started connecting those separate data streams into a single, per-user risk picture. When awareness scores, phishing behaviour, credential exposure, identity hygiene and access privileges are pulled together, the combinations that matter become visible. A user with low awareness, exposed credentials and admin-level access is a different proposition to a user who clicked one simulation link and otherwise presents no other risk signal.

That view changes several things at once. Remediation becomes targeted rather than blanket: instead of re-running the same training module for everyone, the MSP can direct attention to the users and the combinations that carry the most risk. Quarterly business reviews move from reporting activity (modules completed, simulations sent) to reporting outcomes (risk reduced, priority users addressed, exposure trends moving in the right direction). When a client’s insurer or supply chain partner asks for evidence of human risk management, the answer is specific, timestamped and tied to named actions.

There is a commercial dimension to this as well. A security awareness platform is a product the client pays for. A human risk intelligence service, where the MSP interprets connected risk signals, prioritises remediation and reports on outcomes, is a recurring advisory engagement. The distinction matters when MSPs are looking for services that carry margin and resist commoditisation.

Where this sits alongside what is already running

Connecting risk signals does not replace the tools generating them. Awareness training still needs to run. Phishing simulations still need to be sent. Credential monitoring still needs to flag exposures. The intelligence layer sits on top, pulling those outputs together and giving the MSP a view they could not assemble manually across dozens of client organisations.

For MSPs already delivering security services, this is a natural extension of what they do. The data is already being generated. The client conversations are already happening. The regulatory and commercial pressure is already arriving. The gap is the connected view, and the question is whether the MSP can provide it before someone else does.

Join us on Wednesday 14th October

usecure joins Renaissance to introduce uHealth, the Human Risk Intelligence product that connects awareness, phishing, credential, identity and access signals into a single risk score per user and surfaces the combinations that matter most.

The session will include a live walkthrough of a client workspace, showing how uHealth identifies priority users, recommends the next action, and gives MSPs the evidence to lead stronger QBRs, compliance conversations and board-level reporting. We will also cover how to position human risk intelligence as a recurring, billable service alongside the security stack you already deliver.

The session is relevant whether you are an existing usecure partner or evaluating human risk services for the first time.

Register here: https://renaissance.renaissance.ie/c/458350/