Serving Fresno & the Central Valley since 1990 | (559) 251-7767 | support@cspnet.net

Human Risk Management

Firewalls and antivirus can't stop an employee from clicking a convincing email. Human Risk Management measures, trains, and continuously reduces the risk your people carry — powered by uSecure and fully managed by CSP.

Get a Free Risk Assessment See How It Works

Your Technology Is Locked Down. Your People Are Still the Target.

Attackers stopped breaking in years ago — they log in, or they simply ask. A convincing invoice, a spoofed vendor email, a password reused on a site that got breached: these bypass every technical control you own because a legitimate user let them through. Human Risk Management treats that risk the way you already treat patching and backups — as something you measure, work on continuously, and can prove is improving.

60%
of data breaches involve a human element — error, misuse, or social engineering
80%
of breaches begin with stolen or exposed user login credentials
3.4B
phishing emails are sent every single day worldwide
1 in 3
untrained employees fail their first simulated phishing test

Powered by uSecure

uS
uSecure Human Risk Management Platform

CSP's Human Risk Management service is built on uSecure — a platform used by more than 15,000 organizations and 2,000 managed service providers across 30+ countries. Rather than a once-a-year training video everyone clicks through, uSecure runs a continuous program: it finds each employee's specific knowledge gaps, feeds them short lessons that close those gaps, tests them with realistic phishing simulations, tracks policy sign-off, and watches the dark web for their leaked credentials.

Every one of those signals rolls up into a single Human Risk Score — per person, per department, and per organization — so you can see exactly where your exposure sits and watch it drop month over month. CSP configures the whole program, keeps it running, and delivers the reporting.

Rated 4.6/5 on G2 and 4.7/5 on Capterra
15,000+ organizations and 2,000+ MSP partners in 30+ countries
Syncs users directly from Microsoft 365 or Google Workspace
Training content maps to HIPAA, PCI DSS, ISO 27001, SOC 2, GDPR, and CIS Controls
Training available in 15+ languages and regional variants

The Five Modules

uLearnTraining
Bite-sized security awareness courses, automatically assigned to each user's weakest areas first
uPhishSimulation
400+ real-world phishing templates, scheduled automatically, with instant training the moment someone clicks
uPolicyCompliance
Distribute security policies, capture eSign acknowledgements, and export a clean audit trail
uBreachDark Web
Weekly scans of breach dumps, paste sites, and dark web markets for your users' exposed credentials
uHealthIntelligence
Connects every signal into one live Human Risk Score and flags the toxic combinations that matter most
Requires Microsoft 365 or Google Workspace.
Typical Result
60% Lower
Reported human risk reduction in year one (uSecure platform data)
Deployment
Same Day
No agent to install — users sync from your directory

A Continuous Cycle, Not an Annual Checkbox

Human Risk Management runs year-round in the background. Each stage feeds the next, and the whole loop repeats — so risk keeps going down instead of resetting every January.

The cycle repeats continuously — measured risk from stage 4 reshapes the training in stage 2.

uLearn — Adaptive Security Training

Short, interactive courses covering phishing, passwords, social engineering, remote work, data handling, and more — delivered a few minutes at a time rather than in one exhausting annual session. AutoEnrol assigns each user their weakest topics first, refreshes monthly, and handles all the reminder nudges. Content is available in 15+ languages, and CSP can load your own custom courses.

uPhish — Phishing Simulation

Over 400 templates modeled on live attack trends — brand impersonation, spoofed domains, and internal impersonation of your own executives. AutoPhish schedules campaigns automatically so testing never lapses, and message injection delivers simulations straight to the inbox for realistic results. Users who click are enrolled in targeted micro-training immediately.

uPolicy — Policy Attestation

Upload your existing policy PDFs or build them from templates, then push them to the right users or groups with a required eSign acknowledgement. Version control, automatic re-sign schedules, and new-hire auto-issue mean policies stay current, and real-time Pending / Visited / Signed status gives you an exportable audit trail when a regulator or insurer asks.

uBreach — Dark Web Monitoring

Weekly automated scans across dark web forums, paste sites, and breach marketplaces flag the moment one of your users' credentials appears in a leak. Alerts go to CSP and to you, redacted data snippets show what was exposed, and domain-wide monitoring covers every address on your domain — so you can force a reset before the password is used against you.

uHealth — Human Risk Score

The intelligence layer that ties it all together. uHealth scores every user across four dimensions — awareness, credential hygiene, access and privilege, and target value — then ranks them Critical to Low. It surfaces the toxic combinations that actually cause breaches, like a leaked password on a privileged account with MFA disabled, and puts them at the top of the fix list. uHealth draws its identity, access and password-hygiene signals from Microsoft 365 or Google Workspace. Organizations on other mail platforms receive the training, simulation, policy and dark web modules in full.

Reporting & Compliance Evidence

Scheduled reports show training completion, phishing click and report rates, policy sign-off status, breach exposures, and the trend line on your Human Risk Score. It is the documentation cyber insurers and auditors ask for — proof that a real, ongoing security awareness program exists, with names, dates, and results attached.

How CSP Runs the Program for You

Human Risk Management only works if someone actually runs it. That is the part CSP takes off your plate — you get the results and the reporting, not another console to log into.

1

Baseline Your Risk

CSP syncs your users from Microsoft 365 or Google Workspace — no software to install — then runs the initial gap analysis, an unannounced baseline phishing simulation, and a first dark web sweep of your domain. Within days you have a real number for where your organization actually stands.

2

Automate the Program

We configure AutoEnrol training paths, set the AutoPhish simulation schedule, load and distribute your security policies for eSign, and turn on continuous breach monitoring. From that point the program runs itself — your team just gets a short lesson now and then.

3

Report & Improve

CSP reviews the results, follows up on high-risk users, responds to credential exposures, and delivers reporting you can hand to your board, your auditor, or your insurance carrier. Each cycle the training retargets whatever the data says is still weak.

What's Included

A fully managed human risk program — configured, automated, monitored, and reported on by CSP.

uSecure platform licensing for every user
User sync from Microsoft 365, Google Workspace, or CSV
Initial gap analysis and baseline risk scoring
Automated, personalized security awareness training (uLearn)
Ongoing phishing simulation campaigns (uPhish)
In-the-moment training for users who click
Security policy distribution and eSign tracking (uPolicy)
Continuous dark web credential monitoring (uBreach)
Breach alerting and password reset response
Human Risk Score tracking by user and department (uHealth)
Self-service end user portal for training and policies
Reporting for cyber insurance, audits, and compliance
Evidence packs for vendor questionnaires and compliance audits
Allow-listing and mail-flow configuration on your platform

The Control Your Insurance Carrier Asks About

Cyber insurance applications and compliance audits increasingly ask one question directly: do you run ongoing security awareness training and phishing testing? Human Risk Management answers it with evidence — and closes the single largest gap in most Fresno-area businesses' security posture, for a few dollars per user per month.

Schedule a Free Risk Assessment (559) 251-7767

Per-user flat-rate pricing · No agent to install · Local Fresno support

When Your Client Sends You a Security Questionnaire

It arrives as a PDF from your largest customer, or from the compliance platform they use to vet their vendors, and somewhere in the middle of it are two questions. There is no partial credit on either one. You either have a documented program with completion records, or you put “no” in writing to the client you least want to say no to.

Law firms get them from corporate clients. Medical practices get them attached to business associate agreements. Suppliers, contractors and service providers get them from any customer large enough to run a vendor risk program. The wording changes; the two questions don’t.

The two questions, as they are actually worded:

“Does your company perform training on security awareness for all employees at least annually?”

“Does your company conduct social engineering and phishing simulations?”

Cyber insurance applications ask the same two. So do HIPAA business associate reviews, and the vendor risk assessments issued under the FTC Safeguards Rule.

A managed program answers both — and produces the completion reports, simulation results and policy attestation records to back the answer up when the client asks for evidence.

If Your Staff Has Email, You Have Human Risk

Every organization with employees, contractors, or volunteers carries human risk. These face the steepest consequences when it goes unmanaged.

Medical & Healthcare

HIPAA requires documented workforce security awareness training — uPolicy and uLearn produce the records to prove it

Legal & Financial

Wire fraud and business email compromise target the people who move money — simulations train them on the exact scenarios attackers use

Public Agencies & Schools

Public entities are heavily targeted and heavily audited — an ongoing program with exportable evidence satisfies both

Any Team with Turnover

New hires arrive untrained and unaware of your policies — auto-enrollment onboards them into training and policy sign-off on day one

Agriculture & Agribusiness

Growers, packers and processors run lean back offices with seasonal staff and payments large enough to be worth stealing. Business email compromise targets exactly that profile

Associations & Nonprofits

Rotating boards, shared inboxes and volunteer officers. Member data and dues payments are attractive, and constant turnover means training has to run continuously rather than once a year

Train the User, Then Back Them Up

Human Risk Management reduces how often someone falls for an attack. Two-Factor Authentication makes a stolen password useless when they do, and the Email Spam Filter keeps most of the attempts from reaching the inbox at all. Layered together, they cover the human attack path end to end — all managed by CSP under one agreement.

Two-Factor Authentication Email Spam Filter

Find Out Where Your People Actually Stand

CSP will run a no-obligation baseline — a phishing simulation and a dark web scan of your domain — and show you exactly what your human risk looks like today.