Secure Behaviour Management

What is Secure Behaviour Management?

Secure Behaviour Management (SBM) is the practice of defining, measuring and improving the everyday behaviours that keep an organisation secure. It judges a programme by whether people act more securely than they did before, and whether that change can be shown, not by how many people completed a course.

The term is new in 2026. This page explains where it came from, how it relates to security awareness and human risk management, and why we think Security Champions are how it gets delivered through people.

Where the term came from

Gartner began using the name Secure Behavior Management during 2026. One of the first papers to carry it was Wam Voster's Implement Secure Behavior Management to Secure Your Cyber-Physical Systems, published in July 2026, which applies the idea to factories, utilities and other industrial sites. Its starting point is that the most common exposure in those environments is an ordinary human decision, such as a technician sharing credentials because changing them feels disruptive, or an engineer skipping a patching window to hit a production target.

The paper asks security leaders to treat secure behaviour management as infrastructure and to stop treating it as a compliance exercise. It sets out five components: training built around each role, local security ambassadors at each site, scenario exercises that reflect real operations, coverage of contractors and suppliers, and measures tied to operational outcomes in place of completion counts.

The second of those matters most to us. Gartner describes ambassadors as local people with operational credibility, often engineers or supervisors with no security background, who translate central policy into local terms and escalate what they see. It presents them as a layer of local champions that lets a central team reach sites it could never cover alone. So one of the earliest Gartner papers on the subject places Security Champions inside Secure Behaviour Management, and recommends piloting them at two or three priority sites and measuring the effect on reporting and escalation before going wider.

The name has since been applied more broadly. Keepnet reports that a Gartner note in September 2026 uses it for the whole market previously called security awareness training, and that Gartner had earlier argued for it over human risk management. Several vendors now describe themselves as SBM platforms, and in the UK SASIG ran a session on it in September 2026.

The idea underneath the label is older than the label. Security teams have spent years discovering that people who know the rules still break them, usually for sensible local reasons: a deadline, a habit, or the fact that nobody else on the team does it the secure way. SBM gives that problem a name that points at the thing to be changed.

One problem, four names

Each name the industry has used asks a slightly harder question than the one before. The tools overlap a great deal. What changes is what counts as success.

Name The question it asks What it tends to measure
Security awareness training SAT Has everyone been told? Course completion and phishing click rates
Security behaviour and culture programme SBCP, Gartner's earlier term Are we building a culture as well as running a course? Culture surveys and behaviour indicators
Human risk management HRM, used by Forrester and many vendors Which people carry the most risk, and how do we reduce it? Risk scores for each person
Secure Behaviour Management SBM, Gartner, 2026 Do people behave more securely than they did, and can we show it? The same behaviours, before and after

Human risk management and Secure Behaviour Management cover much the same ground, and buyers will meet both for some time. We prefer the newer name because it describes what you want more of. People are far easier to work with when they are not introduced as the risk.

What Secure Behaviour Management involves

Strip away the product language and an SBM programme does four things, in this order.

01

Name the behaviours

Choose a small number of observable actions that matter in your organisation: reporting a suspicious message, verifying a payment change on a known number, challenging an unusual request from someone senior.

02

Measure where you are

Find out how often those behaviours happen today, team by team. Without a baseline, nothing that follows can be shown to have worked.

03

Change the conditions

Make the secure action easier, more normal and better supported. That can mean redesigning a process, a prompt at the right moment, or a trusted colleague showing how it is done.

04

Show the change

Measure the same behaviours again and report the difference. This is the evidence a board, an auditor or a regulator can use.

The third step is where programmes differ most. We work from the COM-B model, which says a behaviour happens when people have the capability, the opportunity and the motivation to do it. Training mostly addresses capability. The other two depend on the environment and on other people, which is why the behavioural basics matter more than the choice of tool.

Where Security Champions fit

Most descriptions of SBM are written one employee at a time: a nudge for each person, training chosen for each person, a score for each person. That is useful, and it leaves something out. People adopt a security behaviour mainly because the people around them do it.

Research on how behaviour spreads shows that information passes on a single contact, while a behaviour that costs effort or carries social risk usually needs reinforcement from several people before it sticks. We cover the evidence in Simple and Complex Contagion and what it means for coverage in The Champion Density Problem.

A Security Champion is a trusted colleague who makes the secure action the normal one in their team. A Champions Network connects those people so the behaviour can travel across the organisation and be measured as it goes. In our view that makes Champions the delivery mechanism for Secure Behaviour Management, working alongside whatever software you use.

Behaviour seen by colleagues

Heroes measures what people observe happening around them in their team. It reports patterns, and it does not track individuals.

Coverage and connection

See which teams have a Champion, which have nobody, and how security influence moves between them.

Evidence a board can use

Before and after measures of behaviour, network strength and programme capability, in plain language.

Management is not surveillance

Adapting a programme to what each employee did means keeping a record of what each employee did. Handled carelessly, that becomes monitoring under a friendlier name, and staff notice. Once people believe their mistakes are being logged against them they stop owning up, which removes the most valuable security behaviour of all.

Our position is that secure behaviour should be measured at the level where it lives, which is the team. CyBehave measures and informs. It does not surveil.

People, and now AI agents

One advantage of the new name is that it does not say "human". AI agents now act on our behalf, reading instructions literally and repeating them at scale, so whether an agent behaves securely is becoming a practical question for every security team.

Behavioural Convergence Theory is our research into whether the behavioural science used for people can be extended to understand and govern agents. If it can, Secure Behaviour Management is one discipline covering both.

Questions about Secure Behaviour Management

What is Secure Behaviour Management?

Secure Behaviour Management (SBM) is the practice of defining, measuring and improving the everyday behaviours that keep an organisation secure. It judges a programme by whether people act more securely than they did before, and whether that change can be shown, not by how many people completed a course.

Is Secure Behaviour Management the same as human risk management?

They describe much the same market and many of the same tools. The difference is the starting point. Human risk management treats people as a risk to be measured and reduced. Secure Behaviour Management names the behaviour you want to see more of and manages towards it.

Does Secure Behaviour Management replace security awareness training?

It changes what training is for. Regulators and auditors still expect training, so it does not disappear. Under SBM, completion stops being the headline measure and training becomes one of several ways to change a specific behaviour. Our Beyond Awareness page covers the move in more detail.

How do you measure secure behaviour?

Pick a small number of observable behaviours, such as reporting a suspicious message or verifying a payment change on a known number, and measure them before and after an intervention. Useful measures include how often and how quickly people report, what colleagues observe happening in their team, and whether the behaviour is spreading from team to team.

Where do Security Champions fit in Secure Behaviour Management?

Security Champions are how secure behaviour reaches teams through people. Most security behaviours are adopted because trusted colleagues do them, so a connected network of Champions gives an SBM programme the peer reinforcement that software nudges alone cannot provide.

Is it Secure Behaviour Management or Secure Behavior Management?

Both are the same thing. Gartner and most US vendors write Secure Behavior Management. UK and Commonwealth organisations write Secure Behaviour Management. The abbreviation SBM is used for both.

Sources and further reading

Gartner's research is available to its clients only. This page summarises the July 2026 paper in our own words. Its description of Gartner's September 2026 research relies on vendor accounts and should be read with that in mind.

Secure behaviour, spread by people.

Find out which stage is holding your programme back, or start a free trial of Heroes. No credit card required.